A.5.7 A.5 · Organisational Controls New in 2022

A.5.7 — Threat intelligence

Collect, analyse and act on information about threats to information security to make risk management decisions.

Also written as A5.7, Annex A 5.7, ISO 27001:2022 A.5.7, ISO27001 A.5.7.

What ISO 27001 A.5.7 requires

Threat intelligence is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Collect, analyse and act on information about threats to information security to make risk management decisions. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.5.7, gather artefacts such as:

  • Threat intelligence feed subscriptions (commercial or open-source)
  • Threat bulletin / advisory distribution records
  • Documented process for collecting and acting on threat intel
  • Evidence of controls updated or alerts triggered in response to threat intel

How to implement A.5.7

  1. Define what you actually need to knowThreat intelligence is only useful against a defined scope. Start from your technology stack, sector and geography, and write down the intelligence requirements that follow — which vendors, which threat actors, which vulnerability classes. Without this, teams subscribe to feeds and then drown in irrelevance.
  2. Use free sources properly before buying anythingNational CERT advisories, your cloud provider security bulletins, vendor security advisories and CISA KEV cover most of what a mid-sized organisation needs. A paid feed is not required to satisfy A.5.7 and buying one does not satisfy it either — the control is about acting on intelligence, not receiving it.
  3. Route intelligence to a decision, not an inboxThe evidence auditors want is the link between an advisory and something that changed: a patch prioritised, a detection rule written, a firewall rule added, a risk accepted. Build that handoff explicitly — advisory received, assessed for relevance, action recorded, closed.
  4. Feed it into vulnerability management and risk assessmentA.5.7 exists to inform decisions taken elsewhere. Connect it to A.8.8 so exploited-in-the-wild vulnerabilities jump the remediation queue, and to your risk assessment so the threat landscape you assess against is current rather than inherited from last year.
  5. Record the negative cases tooMost advisories will not apply to you. An assessment log showing "reviewed, not applicable because we do not run that product" is strong evidence of an operating process, and it is the record most organisations forget to keep.

Common audit findings for A.5.7

What actually gets raised against A.5.7, in rough order of how often it comes up:

Scoping A.5.7

A.5.7 is new in ISO 27001:2022 and has no 2013 equivalent, so a transitioning ISMS has no prior evidence to re-point. It is rarely excludable — every organisation faces threats — but the depth expected scales with your size and risk profile. A 20-person company demonstrating that it reads and acts on vendor advisories is meeting the control.

How A.5.7 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.5.7 aligns with:

SOC 2: CC3.2 Risk identification and analysis, CC7.1 Vulnerability and configuration monitoring

NIST CSF 2.0: ID.RA-02 Threat intelligence received, ID.RA-03 Internal and external threats identified, DE.AE-07 Threat intel enrichment of analysis

ISO 27001:2013 mapping

A.5.7 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.

Map A.5.7 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.5.7 in the Risk Register.

Related Annex A controls

A.5.6 Contact with special interest groups A.5.9 Inventory of information and other associated assets A.8.8 Management of technical vulnerabilities A.8.9 Configuration management

See all 37 Organisational Controls →

Frequently asked questions

Is ISO 27001 A.5.7 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.7 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.5.7?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.5.7 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.5.7 map to in SOC 2 and NIST CSF?

A.5.7 aligns with SOC 2 CC3.2, CC7.1 and NIST CSF ID.RA-02, ID.RA-03, DE.AE-07. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

Is A.5.7 a new control in ISO 27001:2022?

Yes. A.5.7 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.

What are the most common audit findings for A.5.7?

Subscriptions in place with no record of anything ever being actioned, which evidences receipt rather than the control. Threat intelligence handled entirely by one individual with no documented process, so the control fails the moment they are on leave.