SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.7Threat intelligence

Collect and analyze information about threats relevant to your organization, then use it to inform your defenses. Turn raw alerts and reports into decisions about what to prioritize.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0007Risk assessment · PolicyenablesThis policy control documents a repeatable method for identifying and recording risks, the structure threat intelligence needs to feed into for A.5.7 to matter.RCF-0008Risk assessment · ProcesssupportsThis process control runs risk assessments on a regular cycle and uses the results to steer spend, the channel through which threat intelligence should change decisions.RCF-0009Risk assessment · TechnicalsupportsThis technical control feeds risk assessments with real technical data instead of opinion, which is what a working threat intelligence practice supplies.RCF-0021Metrics & reporting · TechnicalrelatedThis technical control automates a metrics dashboard for security posture, a different data feed than threat intelligence but the same discipline of turning raw signal into visibility.RCF-0212Detection engineering · ProcesssupportsThis process control develops and refines detection rules using threat intelligence and past incidents, the direct downstream use of the intelligence A.5.7 requires.RCF-0231Patch prioritization · TechnicalsupportsThis technical control merges scanner severity with live threat intelligence so the patch queue reorders around active exploitation, a concrete use of the intelligence this control collects.RCF-0323Ongoing monitoring · ProcesssupportsThis process control runs periodic supplier reviews and watches breach signals for critical providers, extending threat intelligence to the supply chain A.5.7 also covers.RCF-0324Ongoing monitoring · TechnicalsupportsThis technical control continuously scores supplier external security posture and alerts on drops, an automated form of the threat intelligence this control expects for suppliers.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Threat intelligence sources
The threat-intelligence sources you follow (vendor advisories, CERT/CSIRT bulletins, feeds) and your participation in security forums, associations or threat-sharing groups, plus how you use that information to watch your systems and prioritize your defenses.
From the Sekit evidence catalog

In practice

In practice, a small company's threat intelligence is rarely a dedicated feed budget; it is someone subscribed to a CERT bulletin, a vendor advisory list, and maybe an ISAC for their sector, then reading and acting on what arrives. Auditors ask which sources are followed and want to see a case where an advisory changed a decision, such as reprioritizing a patch or tightening detection rules. The common failure mode is subscribing to sources nobody reads, so intelligence sits in an inbox instead of feeding risk assessments, patch queues or detection engineering.

Common gaps

Threat intelligence sources are listed on paper but nobody can point to a decision, such as a reprioritized patch or a new detection rule, that came from them.
Supplier security monitoring relies entirely on the periodic questionnaire, with no real-time signal for a breach or rating drop between review cycles.
Detection rules were written once and never updated to reflect current threat intelligence or lessons from the company's own past incidents.

Questions your auditor will ask

What threat intelligence sources does the company follow?
A named list of CERT bulletins, vendor advisories, or sector ISAC feeds the team monitors, documented in the threat intelligence sources evidence.
Can you show intelligence changing a real decision, not merely being received?
A patch got reprioritized or a detection rule was updated because of a specific advisory, with the change dated against the advisory.
How is supplier security monitored between periodic reviews?
An automated rating service or breach-monitoring feed flags critical suppliers between the scheduled assessment cycles.

Where regulation demands it

NIS2 3.2 requires ongoing monitoring and logging that threat intelligence feeds directly, turning external signals into internal detection priorities.
ENS op.mon.3 covers vigilancia, the same continuous watching this control expects over threats relevant to the organisation.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.7?”
Also via MCP, free with account