A.5.7 Organizational
Threat intelligence
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RA-10mostlyaligns with — Both controls establish a dedicated threat-hunting/intelligence capability that feeds risk decisions and defensive controls with timely, contextual adversary information.
- RA-3mostlyaligns with — Threat-intelligence outputs are explicitly required as an input to the organization’s risk-assessment process, improving the accuracy and relevance of risk determinations.
- IR-4partialaligns with — Threat-intelligence products are used to inform and improve incident-handling decisions and response actions.
- PM-16partialaligns with — Both emphasize an enterprise-level program that gathers, analyzes, and disseminates threat information to raise organizational awareness and preparedness.
- SI-4partialaligns with — Operational threat intelligence is consumed by monitoring and detection mechanisms to enhance situational awareness and response tuning.
- SI-5partialaligns with — The control requires the collection and internal dissemination of threat-related alerts and directives, mirroring the ISO threat-intelligence sharing and communication activities.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.RA-02fullcovers — The ISO control's systematic collection, analysis, and integration of threat intelligence directly fulfills the CSF outcome of receiving cyber threat intelligence from external and internal sources.
- DE.AE-07mostlyaligns with — By requiring threat intelligence to be contextualized and integrated into analysis, the control supports the CSF outcome of incorporating threat intelligence and contextual data into adverse-event analysis.
- ID.RA-05mostlyaligns with — Feeding threat-intelligence insights into risk-management processes helps the organization understand inherent risk and prioritize responses, matching the CSF outcome.
- GV.SC-03partialaligns with — Sharing threat intelligence with peer organizations and integrating it into risk processes aligns with the CSF outcome of embedding supply-chain risk management into broader enterprise risk activities.
- ID.RA-03partialaligns with — The control's focus on external and internal threat information contributes to the identification and recording of threats, though it does not itself mandate the initial threat-identification step.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.2.4partialaligns with — Operational threat intelligence supplies the vetted external indicators used to maintain the allow-list of permitted external resources and systems.
- V15.2.1partialaligns with — Threat intelligence on emerging vulnerabilities in third-party components is used to enforce documented remediation time-frames and keep the application within acceptable risk posture.
- V16.3.3partialaligns with — Threat intelligence feeds provide the documented security events and bypass attempts that the application must log to maintain situational awareness of relevant threats.
- V2.4.1partialaligns with — Tactical threat intelligence on attacker methodologies informs the design and tuning of anti-automation controls that protect against excessive or malicious calls.
- V6.3.1partialaligns with — Strategic and tactical threat intelligence on credential-stuffing and brute-force campaigns drives the implementation of rate-limiting and adaptive authentication defenses.
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1039partialmitigates — Threat intelligence can surface adversarial ML attack patterns but does not implement technical controls.
- CWE-200partialmitigates — By feeding tactical and operational threat intelligence into firewalls, IDS and anti-malware, the control reduces the window during which sensitive data can be exfiltrated by known attacker TTPs.
- CWE-507partialfinds — Threat intelligence helps anticipate Trojan Horse threats but does not directly prevent them.
- CWE-509partialprevents — Threat intelligence helps anticipate and prepare for virus/worm campaigns.
- CWE-79partialprevents — Operational indicators of compromise for web-application attacks can be incorporated into WAF or input-filtering rules, lowering the likelihood that unsanitized data reaches the browser.
- CWE-89partialprevents — Threat-intelligence feeds that surface new SQL-injection campaigns enable rapid updates to query-construction defenses and detection signatures before exploitation occurs.
- CWE-918partialprevents — Operational threat data describing SSRF campaigns can be used to tighten outbound-request allow-lists and detection rules before attackers exploit them.
- CWE-284nonenone — Strategic and tactical intelligence about attacker methodologies allows the organization to adjust access-control rules and privilege boundaries before those techniques are used against it.
- CWE-352nonenone — Contextual intelligence about emerging CSRF toolkits can be translated into updated anti-CSRF token or same-site policy configurations across applications.
Mitigated MITRE ATT&CK techniques (7)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1027partialmitigates — Operational intelligence on obfuscation and packing techniques used by malware improves anti-malware signatures and sandbox analysis, decreasing the adversary's ability to hide payloads.
- T1059partialmitigates — Tactical intelligence on prevalent scripting languages and command-line abuse helps configure application allow-listing and behavioral detection, constraining the adversary's post-compromise execution options.
- T1078partialmitigates — Threat intelligence on credential-based attacks and compromised account indicators supports account monitoring and conditional access policies, reducing the effectiveness of valid account abuse.
- T1105partialmitigates — Threat intelligence on common download URLs, file hashes, and C2 infrastructure allows blocking of ingress tool transfers at network and endpoint layers, limiting the adversary's ability to stage additional tools.
- T1190partialprevents — Operational threat intelligence on public-facing application exploits enables timely patching and WAF rule updates, limiting the adversary's success in exploiting those applications for initial access.
- T1566partialprevents — Strategic and tactical threat intelligence on phishing campaigns and lures informs user awareness programs and email filtering, lowering the likelihood that users will execute malicious attachments or links.
- T1595partialmitigates — Threat intelligence on active scanning campaigns and tooling allows the organization to tune network defenses and detection rules, reducing the adversary's ability to discover exposed services and vulnerabilities.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09partialmitigates — Strategic and tactical threat intelligence informs the selection and prioritization of log sources and alerting rules, ensuring that security monitoring focuses on the attack techniques most relevant to the organization.
- A02nonemitigates — Feeding tactical and operational threat intelligence into firewalls, IDS and anti-malware solutions keeps security configurations aligned with current attacker tools and techniques, reducing the window during which misconfigurations can be exploited.
- A05nonemitigates — Operational threat intelligence supplies up-to-date indicators of compromise and attack patterns that can be used to tune input-validation rules and WAF policies, lowering the likelihood that injection payloads will reach vulnerable code paths.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.