GOV-018 Threat Intelligence Programme
Description
Threat intelligence reports covering the organisation's technology stack, sector and operating geographies are produced at a defined cadence from at least two named sources. At least one source is a special interest group, a sector threat-sharing group or a national CERT alert service, held with a named internal owner. Each report records the internal stakeholders it was distributed to. Each finding accepted for action is traced to a risk register entry or a control change record.
Rationale
Threat-informed prioritisation is the difference between maintaining an undifferentiated control set and spending effort on the techniques an adversary is using against this stack this quarter. The test that separates a real programme from a mailing list subscription is the trace from a finding to a risk entry or a change. Contact with regulatory authorities and law enforcement is INC-010; threat hunting against the estate is not required here.
Applicability (9 profiles)
Framework Mappings (21)
| GRC-08 | Special Interest Groups | full |
| TVM-10 | Threat Response | partial |
| GRC-08 | Special Interest Groups | full |
| TVM-10 | Threat Response | partial |
| COP-S-3.1 | Model-independent information | informative |
| COP-S-6.1 | Security Goal | informative |
| HIPAA-164.308.a.5.ii.A | Security Reminders | informative |
| 5.6 | Contact with special interest groups | full |
| 5.7 | Threat intelligence | full |
| NIS2-Art.21.3 | Supplier-Specific Risk Factors in Supply Chain Measures | informative |
| NIS2-Art.22 | Union Level Coordinated Security Risk Assessments of Critical Supply Chains | informative |
| NIS2-CIR-2.1 | Risk Management Framework | informative |
| NIS2-CIR-4.3 | Crisis Management | informative |
| NIS2-CIR-6.10 | Vulnerability Handling and Disclosure | informative |
| AU-13 | Monitoring for Information Disclosure | partial |
| PM-15 | Security and Privacy Groups and Associations | partial |
| PM-16 | Threat Awareness Program | full |
| RA-10 | Threat Hunting | partial |
| MG-4.1-001 | Post-Deployment AI System Monitoring | MG-4.1-001 | partial |
| MS-3.2-001 | Risk Tracking for Measurement Gaps | MS-3.2-001 | informative |
| CC3.4 | COSO Principle 9: Identifies and Analyzes Significant Change | informative |
Evidence (3)
Evidence of active participation in or subscription to a security community or information sharing group.
Example: ISAC membership confirmation email, FS-ISAC or H-ISAC membership certificate, CISA alert subscription confirmation, or equivalent, dated within the last 12 months.
Test: Request membership or subscription confirmation for at least one threat intelligence sharing or industry group. Verify: (1) the subscription or membership is current (not expired), (2) it is relevant to the organisation's industry and technology stack, (3) a named internal contact is responsible for receiving and acting on alerts.
Threat intelligence report or briefing documenting collected intelligence, analysis, and dissemination to relevant internal stakeholders.
Example: Monthly or quarterly threat intelligence report (internal Confluence report or PDF export from threat intel platform such as Recorded Future, MISP, or equivalent), showing: sources consumed, relevant threats identified, analysis, and distribution to named internal stakeholders.
Test: Request the last two threat intelligence reports. Verify: (1) reports are produced within the defined cadence, (2) at least two threat intelligence sources are referenced, (3) findings are analysed for relevance to the organisation's technology stack, (4) the report was distributed to named security, engineering, or risk stakeholders, confirmed via email or meeting record.
Record showing threat intelligence outputs were used to update the risk assessment or triggered a control change.
Example: Risk register update record or Jira ticket (linked to a threat intel finding) showing: the threat identified, the date it was fed into the risk register or triggered a control review, and the named analyst who acted on it.
Test: Select a finding from a recent threat intelligence report. Trace it to the risk register or a change/control ticket. Verify: (1) the threat is recorded in the risk register or triggered a documented review, (2) an owner and date are recorded, (3) the response action (accept, mitigate, monitor) is documented.
Questions (3)
Does your organisation have a defined threat intelligence programme that collects, analyses, and disseminates threat intelligence to relevant internal stakeholders?
The programme should produce documented intelligence outputs (reports or briefings) on a defined cadence, referencing at least two sources and showing distribution to security, engineering, or risk stakeholders.
How does your organisation act on threat intelligence findings to update risk posture or controls?
A traceable link between an intelligence finding and a risk register entry or change ticket is the expected evidence, demonstrating closed-loop action.
Which external threat intelligence and special interest group relationships does your organisation actively maintain?
Active membership or subscription, not registration alone, with a named internal owner. Regulatory authority and law enforcement contacts are INC-010.