NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)
Threat Intelligence

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) NATO-NCIRC-4: Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure

Participate in NATO cyber threat intelligence sharing via Malware Information Sharing Platform (MISP) instances operated by NCIRC + Cyber Threat Assessment Cell (CTAC) at SHAPE + bilateral channels with NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn Estonia. Apply STIX/TAXII formats per CCDCOE recommendations. Operate Coordinated Vulnerability Disclosure programme per CCDCOE Tallinn Manual 3.0 guidance + ISO/IEC 29147. Share indicators of compromise (IOCs) + tactics techniques and procedures (TTPs) with allied nations within 24-48 hours.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 19 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CAT-D2-1 Threat intelligence
  • CAT-D2-2 Monitoring and analyzing
  • CAT-IRP-5 External threats

BSI IT-Grundschutz · 1 control

  • BSI-16 Threat intelligence integration

ISO/IEC 27011:2024 · 1 control

  • 27011-5.4 Threat intelligence for telecom

ISO/IEC 27400:2022 · 1 control

  • 27400-5.1 IoT Security and Privacy Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

OWASP Top 10:2025 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.