Collect and analyze information about threats relevant to your organization, then use it to inform your defenses. Turn raw alerts and reports into decisions about what to prioritize.
What an auditor, or Sekit's evidence engine, asks for.
Threat intelligence sources
The threat-intelligence sources you follow (vendor advisories, CERT/CSIRT bulletins, feeds) and your participation in security forums, associations or threat-sharing groups, plus how you use that information to watch your systems and prioritize your defenses.
From the Sekit evidence catalog
In practice
In practice, a small company's threat intelligence is rarely a dedicated feed budget; it is someone subscribed to a CERT bulletin, a vendor advisory list, and maybe an ISAC for their sector, then reading and acting on what arrives. Auditors ask which sources are followed and want to see a case where an advisory changed a decision, such as reprioritizing a patch or tightening detection rules. The common failure mode is subscribing to sources nobody reads, so intelligence sits in an inbox instead of feeding risk assessments, patch queues or detection engineering.
Common gaps
Threat intelligence sources are listed on paper but nobody can point to a decision, such as a reprioritized patch or a new detection rule, that came from them.
Supplier security monitoring relies entirely on the periodic questionnaire, with no real-time signal for a breach or rating drop between review cycles.
Detection rules were written once and never updated to reflect current threat intelligence or lessons from the company's own past incidents.
Questions your auditor will ask
What threat intelligence sources does the company follow?
A named list of CERT bulletins, vendor advisories, or sector ISAC feeds the team monitors, documented in the threat intelligence sources evidence.
Can you show intelligence changing a real decision, not merely being received?
A patch got reprioritized or a detection rule was updated because of a specific advisory, with the change dated against the advisory.
How is supplier security monitored between periodic reviews?
An automated rating service or breach-monitoring feed flags critical suppliers between the scheduled assessment cycles.
Where regulation demands it
NIS2 3.2 requires ongoing monitoring and logging that threat intelligence feeds directly, turning external signals into internal detection priorities.
ENS op.mon.3 covers vigilancia, the same continuous watching this control expects over threats relevant to the organisation.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.