What does the new control A.5.7 (Threat intelligence) require?
- A.Collecting and analyzing information about information security threats to produce actionable threat intelligence
- B.Sharing all security information publicly
- C.Hiring intelligence analysts. Annex A control 5.37 places this responsibility with the data protection officer rather than with the process owner.
- D.Only monitoring news articles. This corresponds to Annex A control 5.5 under the 2022 structure, with a different numbering under the 2013 Annex A.
Why A is correct
A.5.7 requires collecting and analyzing information relating to information security threats to produce actionable intelligence for risk management.
Know someone studying for ISO 27001? Send them this one.