⚓ Running on beta — hold tight, things may still shake.

ISO 27001:2022 Annex A

ISO 27001 A.5.7 evidence, without the week-before-audit scramble

Control 5.7, Threat intelligence, asks that information relating to security threats be collected and analysed to produce threat intelligence — and that it feeds back into how your organization actually responds. An auditor testing this control wants to see that happening on a schedule, with a record, not a one-off exercise done right before the certification visit.

What auditors typically ask for

For an A.5.7 test, an auditor generally wants to see the full loop, not just a subscription to a mailing list:

  • • Which sources of threat intelligence are collected, and how they're matched against what you actually run.
  • • Evidence that collection is continuous — timestamped findings spanning the certification period, not a single snapshot.
  • • Analysis of each item — a recorded disposition showing someone evaluated it, not just that it arrived.
  • • A clear sign-off closing each review period, demonstrating the intelligence was actually acted on.

Forwarding CVE emails to a shared inbox technically satisfies "collection," but it doesn't produce anything an auditor can point to as analysis or evidence of action.

How TrawlSec generates this evidence

TrawlSec continuously collects from NVD, EUVD, and any custom feeds you add, matches findings against the assets you tell it you run, and routes anything relevant into a review queue for analysis. Every disposition — confirmed, ignored, false positive — is logged automatically with who, when, and why.

Closing a review period locks that record in, and exports into a report scoped to the exact window an auditor is asking about — collection and analysis, in one auditable trail.

See it before you sign up

The live demo has sample findings, a review queue, and a real generated PDF report — no account required.

View live demo