Skip to main content
Category: Logging and Monitoring

Threat Intelligence Control (5.7)

Also known as: Annex A 5.7, ISO 27001 Control 5.7, Threat Intelligence (Annex A 5.7)
Simply put

Threat Intelligence (Control 5.7) is a reference control in ISO/IEC 27001 that asks an organization to gather and make sense of information about the security threats it faces. The idea is to use that information to take informed action that reduces risk, rather than just collecting data for its own sake. It was introduced as a new control in the 2022 revision of the standard.

Formal definition

Annex A Control 5.7 is a reference control introduced in the ISO/IEC 27001:2022 revision that directs organizations to collect and analyze information relating to information security threats and to act on it in an informed manner to minimize risk. In practice it typically involves systematically gathering threat information relevant to the organization's business, systems, and environment, evaluating that information, and feeding the resulting analysis into security decision-making. As an Annex A control, 5.7 is a reference control selected via the Statement of Applicability and informed by the risk assessment; its applicability, scope, and depth of implementation depend on the organization's context rather than being universally mandated. The certifiable ISMS requirements themselves reside in clauses 4 through 10, while Annex A (including 5.7) provides the reference control set from which controls are drawn.

Why it matters

Threat Intelligence (Control 5.7) matters because information security threats evolve continuously, and controls designed against yesterday's threat landscape can become less effective over time. By directing organizations to systematically collect and analyze threat information relevant to their business, systems, and environment, the control helps ensure that security decisions are informed by current understanding of what adversaries are actually doing, rather than by assumption alone. The emphasis in the standard is on taking informed action to minimize risk, not on accumulating threat data for its own sake.

As a new addition in the ISO/IEC 27001:2022 revision, Control 5.7 formalizes a practice that many mature security teams already performed informally. Threat intelligence, understood broadly, combines data, context, and analysis to help security teams identify, assess, and prioritize the threats they face. When this analysis feeds back into an organization's risk assessment and control selection, it can strengthen the overall management system and help organizations allocate limited resources toward the threats most relevant to their context.

It is important to keep the boundaries of this control in view. As an Annex A reference control, 5.7 is selected via the Statement of Applicability and informed by the risk assessment; its applicability, scope, and depth of implementation depend on the organization's context rather than being universally mandated. Implementing it does not guarantee freedom from incidents, and its presence in Annex A does not make it a certifiable requirement in itself, the certifiable ISMS requirements reside in clauses 4 through 10.

Who it's relevant to

Compliance and GRC managers pursuing ISO 27001:2022
Because Control 5.7 was introduced in the 2022 revision, organizations transitioning from or certifying against the current edition should consider whether it applies to them and document that decision in the Statement of Applicability. Where it is applicable, they should be prepared to show how threat information is gathered, analyzed, and used to inform security decisions, with the specific scope and depth reflecting their organizational context.
Security engineers and threat analysts
Teams responsible for identifying, assessing, and prioritizing cyber threats are typically the practitioners who operationalize this control. Their work in collecting and evaluating threat information, combining data, context, and analysis, provides the substance that Control 5.7 expects, and connecting that analysis to concrete risk-reduction actions is central to the control's intent.
Auditors and certification body assessors
When Control 5.7 is included in an organization's Statement of Applicability, assessors evaluating an ISMS against ISO/IEC 27001:2022 will typically look for evidence that threat information is collected, analyzed, and acted upon in an informed way. The assessment focuses on whether the organization's approach is appropriate to its context rather than on any single universally mandated method.
Smaller organizations and SMEs
Organizations without a dedicated threat intelligence function still need to determine whether Control 5.7 is applicable and, if so, implement a proportionate approach. The control's context-dependent nature means a lighter-weight, risk-informed process can be appropriate, provided it demonstrably supports informed action to minimize risk.

Inside Threat Intelligence Control (5.7)

Annex A Reference Control 5.7
Threat Intelligence is a reference control introduced in the ISO/IEC 27001:2022 revision of Annex A, which restructured controls into four themes (organizational, people, physical, and technological). As an Annex A control, it is selected for applicability via the Statement of Applicability and informed by the organization's risk assessment, rather than being an ISMS requirement in clauses 4 through 10.
Collection and Analysis of Threat Information
The control concerns gathering and analyzing information about existing or emerging threats so that the organization can understand its threat landscape. The specific sources, tooling, and depth of analysis typically depend on the organization's scope, risk profile, and available resources.
Levels of Threat Intelligence
Threat intelligence is commonly considered across strategic, tactical, and operational perspectives, addressing high-level trends, attacker techniques, and specific indicators respectively. How an organization applies these levels varies based on its needs and the scope of its ISMS.
Integration with Risk-Driven Controls
Where selected as applicable, threat intelligence is intended to inform other security activities and decisions. Its output can feed into risk assessment and the selection or tuning of other Annex A controls, though the exact integration depends on organizational scope and design decisions.

Common questions

Answers to the questions practitioners most commonly ask about Threat Intelligence Control (5.7).

Is Threat Intelligence a control that exists in ISO/IEC 27001:2013?
No. Threat intelligence appears as Annex A control 5.7 in the 2022 revision of the reference controls, which restructured the Annex from the earlier edition. When citing this control number, specify the 2022 version, since control numbering and structure differ between editions.
Does implementing a threat intelligence control satisfy the equivalent requirement in a SOC 2 examination?
Not automatically. SOC 2 is an attestation examination against the Trust Services Criteria, while Annex A control 5.7 is a reference control selected via the Statement of Applicability in an ISO 27001 ISMS. Mapping between the two frameworks is possible but partial, and satisfying one does not automatically satisfy the other. How this control relates to any SOC 2 criteria depends on scope and the assessing party.
Is Annex A control 5.7 mandatory for ISO 27001 certification?
Annex A controls are reference controls selected based on risk assessment and documented in the Statement of Applicability. Whether this control is included, excluded, or tailored depends on the organization's risk treatment decisions. The certifiable requirements themselves reside in clauses 4 through 10, and inclusion of any specific Annex A control is informed by the organization's scoping and risk decisions rather than being universally mandatory.
What kinds of activities might an organization use to demonstrate this control?
Depending on scope, organizations typically document how threat information is collected, analyzed, and communicated to relevant functions. Evidence and specific activities vary by organization, certification body expectations, and the risk assessment; there is no single prescribed approach, so implementation should be aligned to the documented Statement of Applicability and risk treatment.
How is this control usually integrated with the broader ISMS?
In most implementations, threat intelligence activities feed into risk assessment and treatment processes and inform other operational controls. Because the certifiable ISMS requirements sit in clauses 4 through 10, organizations generally connect this reference control to their risk management and continual improvement processes rather than treating it in isolation. The exact integration depends on scope and organizational context.
What are the boundaries of what this control covers within a certified ISMS?
An ISO 27001 certificate covers only the defined scope of the ISMS, and any single Annex A control operates within that boundary. This control addresses how threat information is handled as described in the Statement of Applicability; it does not by itself guarantee freedom from incidents or breaches, and its coverage is limited to what the organization has defined within its ISMS scope.

Common misconceptions

Threat Intelligence (5.7) is a mandatory control that every ISO 27001-certified organization must implement.
Annex A controls, including 5.7, are reference controls selected via the Statement of Applicability and informed by risk assessment. An organization may justify excluding a control based on its risk assessment and scope. The mandatory certifiable requirements reside in clauses 4 through 10, not in Annex A itself.
Because SOC 2 covers security, satisfying the SOC 2 Common Criteria automatically covers ISO 27001's threat intelligence expectations.
SOC 2 and ISO 27001 are distinct frameworks. SOC 2 is an attestation examination performed by a licensed CPA firm under SSAE 18, resulting in a report against the Trust Services Criteria; ISO 27001 is a certification against a management system standard. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
Control 5.7 has always existed and its number or grouping is consistent across ISO 27001 editions.
Threat Intelligence was introduced in the 2022 revision of Annex A, which restructured the controls into four themes and reduced the overall count from 114 in the 2013 version to 93. Control counts and identifiers depend on the edition, so the version should be specified when citing them.

Best practices

Document the applicability decision for control 5.7 in the Statement of Applicability, referencing the risk assessment that justifies its inclusion or exclusion within your defined ISMS scope.
Where applicable, consider threat intelligence across strategic, tactical, and operational levels, tailoring the depth to your organization's risk profile and available resources rather than assuming a single fixed approach.
Feed threat intelligence outputs back into your risk assessment process so that emerging threats can inform the selection and tuning of other Annex A controls.
Specify the ISO/IEC 27001 edition (for example, the 2022 revision) whenever referencing control 5.7 or Annex A control counts, since numbering and grouping differ between versions.
If your organization also pursues a SOC 2 report, treat any mapping between 5.7 and the Trust Services Criteria as partial, and validate that each framework's requirements are addressed on their own terms.
Review and update threat intelligence activities periodically so that the control continues to reflect the current threat landscape and the boundaries of your certified ISMS scope.