GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-018 Threat Intelligence Programme

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Threat intelligence reports covering the organisation's technology stack, sector and operating geographies are produced at a defined cadence from at least two named sources. At least one source is a special interest group, a sector threat-sharing group or a national CERT alert service, held with a named internal owner. Each report records the internal stakeholders it was distributed to. Each finding accepted for action is traced to a risk register entry or a control change record.

Rationale

Threat-informed prioritisation is the difference between maintaining an undifferentiated control set and spending effort on the techniques an adversary is using against this stack this quarter. The test that separates a real programme from a mailing list subscription is the trace from a finding to a risk entry or a change. Contact with regulatory authorities and law enforcement is INC-010; threat hunting against the estate is not required here.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (21)

GRC-08Special Interest Groupsfull
TVM-10Threat Responsepartial
GRC-08Special Interest Groupsfull
TVM-10Threat Responsepartial
COP-S-3.1Model-independent informationinformative
COP-S-6.1Security Goalinformative
HIPAA-164.308.a.5.ii.ASecurity Remindersinformative
5.6Contact with special interest groupsfull
5.7Threat intelligencefull
NIS2-Art.21.3Supplier-Specific Risk Factors in Supply Chain Measuresinformative
NIS2-Art.22Union Level Coordinated Security Risk Assessments of Critical Supply Chainsinformative
NIS2-CIR-2.1Risk Management Frameworkinformative
NIS2-CIR-4.3Crisis Managementinformative
NIS2-CIR-6.10Vulnerability Handling and Disclosureinformative
AU-13Monitoring for Information Disclosurepartial
PM-15Security and Privacy Groups and Associationspartial
PM-16Threat Awareness Programfull
RA-10Threat Huntingpartial
MG-4.1-001Post-Deployment AI System Monitoring | MG-4.1-001partial
MS-3.2-001Risk Tracking for Measurement Gaps | MS-3.2-001informative
CC3.4COSO Principle 9: Identifies and Analyzes Significant Changeinformative

Evidence (3)

recorddocumentmanual

Evidence of active participation in or subscription to a security community or information sharing group.

Example: ISAC membership confirmation email, FS-ISAC or H-ISAC membership certificate, CISA alert subscription confirmation, or equivalent, dated within the last 12 months.

Test: Request membership or subscription confirmation for at least one threat intelligence sharing or industry group. Verify: (1) the subscription or membership is current (not expired), (2) it is relevant to the organisation's industry and technology stack, (3) a named internal contact is responsible for receiving and acting on alerts.

reportdocumentmanual

Threat intelligence report or briefing documenting collected intelligence, analysis, and dissemination to relevant internal stakeholders.

Example: Monthly or quarterly threat intelligence report (internal Confluence report or PDF export from threat intel platform such as Recorded Future, MISP, or equivalent), showing: sources consumed, relevant threats identified, analysis, and distribution to named internal stakeholders.

Test: Request the last two threat intelligence reports. Verify: (1) reports are produced within the defined cadence, (2) at least two threat intelligence sources are referenced, (3) findings are analysed for relevance to the organisation's technology stack, (4) the report was distributed to named security, engineering, or risk stakeholders, confirmed via email or meeting record.

recorddocumentmanual

Record showing threat intelligence outputs were used to update the risk assessment or triggered a control change.

Example: Risk register update record or Jira ticket (linked to a threat intel finding) showing: the threat identified, the date it was fed into the risk register or triggered a control review, and the named analyst who acted on it.

Test: Select a finding from a recent threat intelligence report. Trace it to the risk register or a change/control ticket. Verify: (1) the threat is recorded in the risk register or triggered a documented review, (2) an owner and date are recorded, (3) the response action (accept, mitigate, monitor) is documented.

Questions (3)

boolean

Does your organisation have a defined threat intelligence programme that collects, analyses, and disseminates threat intelligence to relevant internal stakeholders?

The programme should produce documented intelligence outputs (reports or briefings) on a defined cadence, referencing at least two sources and showing distribution to security, engineering, or risk stakeholders.

select

How does your organisation act on threat intelligence findings to update risk posture or controls?

Threat intelligence findings are systematically traced to risk register updates or control change ticketsFindings are reviewed and discussed in security meetings but not formally tracked to the risk registerIntelligence is collected but dissemination and action are ad hocNo formal process for acting on threat intelligence exists

A traceable link between an intelligence finding and a risk register entry or change ticket is the expected evidence, demonstrating closed-loop action.

multi

Which external threat intelligence and special interest group relationships does your organisation actively maintain?

ISAC or sector-specific threat sharing group membershipNational CERT or CISA alert subscriptionVendor or MSSP threat intelligence feedSecurity industry association or professional forum membershipNone of the above

Active membership or subscription, not registration alone, with a named internal owner. Regulatory authority and law enforcement contacts are INC-010.