ISO 27001 A.5.7 — Threat intelligence

A.5.7 is one of the eleven controls added in ISO 27001:2022. It asks you to collect and analyse information about threats so you can act on it — not to buy an expensive intelligence feed.

Michael McCarroll 6 min read Updated August 2026

What the control says

Information relating to information security threats shall be collected and analysed to produce threat intelligence. The standard splits this into strategic (who is targeting your sector and why), tactical (attacker tooling and methods) and operational (specific, actionable indicators) intelligence.

Theme: Organisational · New in ISO 27001:2022

Why it matters

Without threat intelligence your risk assessment is a snapshot of last year's thinking. Auditors look for a feedback loop: intelligence in, risk register updated, controls adjusted. It is also the control that most cheaply demonstrates the continual improvement the standard demands under clause 10.

You do not need a threat intelligence platform. A small business can satisfy A.5.7 with free national sources, your existing security tooling's alerts, and a fifteen-minute monthly review that is minuted and linked to the risk register.

How to implement it

  1. Pick three or four sources you will actually read: your national cyber agency advisories (in the UK, the NCSC), your sector's information sharing group, your main vendors' security bulletins (Microsoft, your cloud provider) and one industry newsletter.
  2. Name an owner and a cadence. Monthly review is the practical default for an SME; move to weekly only if you operate in a high-threat sector.
  3. Define what triggers action: a threat affecting a technology in your asset inventory, a threat targeting your sector, or an actively exploited vulnerability in something internet-facing.
  4. Record the review — even when nothing needs action. A short dated note per review is the evidence.
  5. Feed the output into the risk register: raise a new risk, re-score an existing one, or record that no change was required.
  6. Review the intelligence process itself at management review under clause 9.3, and note whether it produced anything useful.

Evidence auditors ask for

  • A documented list of intelligence sources with the named owner and review frequency
  • Dated review notes for the last 12 months, including the 'no action required' ones
  • Risk register entries or re-scores traceable back to a specific advisory
  • Any resulting actions with owner, due date and completion evidence
  • Management review minutes referencing threat intelligence as an input

Common findings

  • A subscription exists but nobody can show a single decision that came from it — the classic 'shelf-ware' finding.
  • Reviews happened for two months after certification and then stopped; the gap is visible in the dates.
  • Intelligence is collected but never connected to the risk register, so there is no traceable outcome.
  • The control is marked applicable in the Statement of Applicability with no owner assigned.

Related controls

  • A.5.5 Contact with authorities
  • A.5.6 Contact with special interest groups
  • A.8.8 Management of technical vulnerabilities
  • A.8.16 Monitoring activities

See the full list of all 93 Annex A controls or start from the Statement of Applicability template.

FAQ

Do we need a paid threat intelligence feed for A.5.7?
No. The control requires that threat information is collected and analysed, not that it is purchased. Free national advisories, vendor security bulletins and sector groups are accepted by auditors provided you can show analysis and a documented outcome.
How often should threat intelligence be reviewed?
Set a cadence proportionate to your risk and then stick to it. Monthly suits most SMEs. Auditors care far more about consistent, evidenced reviews than about frequency.
Can A.5.7 be excluded from the Statement of Applicability?
In practice, no. Every organisation faces information security threats, so excluding A.5.7 is very hard to justify. Scale the implementation down instead of excluding the control.

Evidence A.5.7 without the spreadsheet

ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →