Threat intelligence arrived in ISO 27001 with the 2022 edition as Annex A control 5.7, and it is the control organizations most often satisfy with a subscription nobody reads. The requirement is not to buy a feed. It is to collect and analyse information about information security threats and produce intelligence — something that changes a decision.
This guide covers what control 5.7 asks for, the three levels of threat intelligence and who consumes each, and what an auditor looks for when the evidence is a vendor invoice.

What ISO 27001 control 5.7 requires
Annex A 5.7 sits in the organizational theme of the 2022 control set — the 93 controls split 37 organizational, 8 people, 14 physical and 34 technological. It is one of the controls introduced in that edition, which is why organizations transitioning from the 2013 Annex A frequently have no evidence for it at all.
The obligation has two halves that a subscription alone does not meet:
- Collect. Information about existing and emerging threats relevant to your organization — from external feeds, sector bodies, vendors, national authorities, and your own incidents and detections.
- Analyse. Turn that into intelligence: relevant, contextual, actionable. A feed of indicators is data. “This actor targets our sector through our remote access vendor, and here is what we changed” is intelligence.
The test an auditor applies is whether anything downstream moved because of it. If the risk assessment, the detection rules, the patch priorities and the awareness training all look identical before and after the feed was bought, the control is not implemented.
The three levels of threat intelligence
| Level | Question it answers | Who acts on it |
|---|---|---|
| Strategic | How is the threat landscape for our sector and geography changing? | Leadership and risk owners — it feeds the risk assessment and the security budget |
| Tactical | What techniques are being used against organizations like us? | Security architecture and engineering — it drives control selection and hardening |
| Operational | What should we block, hunt for or patch this week? | Detection, response and vulnerability management |
Most programmes buy operational threat intelligence, because indicators are the easiest thing to sell and the easiest to ingest. That is the level with the shortest shelf life and the least influence on the management system. Strategic intelligence is what makes the annual risk assessment reflect this year rather than last.
Making the threat intelligence control auditable
Five artefacts carry the evidence, and none of them requires a large budget:
- Named sources with an owner. A short list: your national cyber authority, your sector’s information sharing body, your major vendors’ advisories, and whatever paid feed you use. Written down, with who monitors each.
- A cadence. Daily for operational, monthly for tactical, at least annually for strategic — and evidence that it ran when nothing was on fire.
- A relevance filter. What makes an item relevant to you: your technologies, your sector, your geographies, your suppliers. Without it, every feed is noise and analysts learn to skim.
- A decision record. The single most valuable artefact: a short log of what changed as a result — a rule deployed, a patch expedited, a supplier questioned, a risk re-scored.
- A route into the risk assessment. Threat intelligence that never reaches the risk register has no effect on the management system, and that is where an auditor will look for it.
Where small organizations get stuck
The common objection is that threat intelligence is a large-team capability. It is not, at the level ISO 27001 asks for. A small organization can satisfy control 5.7 with free national-authority advisories, its vendors’ security bulletins, one sector mailing list, a monthly half-hour review and a decision log. What it cannot do is claim the control on the strength of an unread subscription.
How it connects to the rest of the ISMS
Control 5.7 is deliberately upstream of several others. It feeds the risk assessment, informs technical vulnerability management, sharpens supplier assurance, and gives incident response the context to recognize what it is seeing. It also pairs with monitoring: intelligence tells you what to look for, and monitoring tells you whether it is here.
If you are documenting the 2022 control set, our guides to the 93 Annex A controls and the Statement of Applicability cover where 5.7 sits and how to justify its scope.
Frequently asked questions
Is threat intelligence new in ISO 27001:2022?
Yes. Control 5.7 is one of the controls introduced in the 2022 edition, which is why organizations that transitioned from the 2013 Annex A often have no evidence for it.
Do we have to buy a commercial feed?
No. The control requires collection and analysis producing relevant, actionable intelligence. National authority advisories, vendor bulletins and sector sharing groups can satisfy it if they are actually reviewed and acted on.
What evidence will an auditor ask for?
Named sources, a review cadence that ran, a relevance filter, and a record of decisions the intelligence changed. The last one is the hardest to fake and the easiest to produce if the control is real.
Where does it belong organizationally?
Wherever the analysis will actually happen — often security operations, sometimes risk. What matters is that outputs reach both the technical teams and the risk register.
How does it relate to threat modelling?
Threat intelligence tells you what is happening in the world; threat modelling applies it to a specific system. The second is much more useful when fed by the first.
Where this leaves you
Implement control 5.7 as a small, running process rather than a purchase. Name your sources and their owner, set a cadence you will keep, write down what makes an item relevant to you, and above all keep a log of what changed because of it. Then make sure the strategic layer reaches the annual risk assessment — that route is what turns threat intelligence from an operational feed into part of the management system.
References
- ISO/IEC 27001 — the information security management system standard and its Annex A control set.
- NCSC — advice and guidance — an example of a free, authoritative source that satisfies the collection half.
More on ISO 27001 controls
- Threat intelligence and control 5.7 — you are here
- The 93 Annex A controls
- The ISO 27001 risk assessment
- The incident response plan
Procedures, source registers and review records are in the ISO 27001 Toolkit, or start with the free ISO templates.