Information about security threats is to be gathered and examined so that it yields threat intelligence. Purpose: make the organization aware of the threats around it so that fitting mitigations can be chosen. Guidance: knowledge of current and emerging threats is analysed so the organization can act to stop them doing harm and lessen their effect. All three layers should be considered: strategic (the broad picture of how the threat landscape is shifting, such as kinds of attacker or attack), tactical (how attackers operate, their tools and technologies) and operational (detail of particular attacks, including technical indicators). Good intelligence is relevant to protecting the organization, gives accurate and detailed insight, carries context (timing, location, past experience, how common it is among similar organizations) and can be acted on quickly. The activities are: set objectives for producing intelligence; identify, vet and choose internal and external sources; collect from them; process the material for analysis (translating, formatting, corroborating); analyse what it means for the organization; and pass it in understandable form to the people who need it. The results feed information security risk management, serve as extra input to technical preventive and detective tools such as firewalls, intrusion detection and anti-malware, and inform security testing. Intelligence should be shared with other organizations on a reciprocal basis. Other information: most organizations consume intelligence from independent providers, government agencies or collaborative groups rather than producing it, and controls 5.25, 8.7, 8.16 and 8.23 depend on its quality.
This control maps to 77 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.