Skip to content

Cyber Threat Intelligence

What is Cyber Threat Intelligence?

Evidence-based knowledge about existing or emerging cyber threats that can be used to inform decisions regarding the organisation's response to those threats. CTI includes indicators of compromise, threat actor profiles, and attack patterns.

Information Security

Each of these is named in at least one of the same controls as cyber threat intelligence. The number is how many controls name both.

What the standards actually require on cyber threat intelligence

Requirements naming cyber threat intelligence across 6 standards, quoted from the control text.

Participate in NATO cyber threat intelligence sharing via Malware Information Sharing Platform (MISP) instances operated by NCIRC + Cyber Threat Assessment Cell (CTAC) at SHAPE + bilateral channels with NATO Cooperative Cyber Defence Centre of Excellence (CCDC...

NATO-NCIRC-4 · Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure

Article 3 establishes the European Cybersecurity Alert System: a pan-EU interconnected network of National Cyber Hubs (Article 4) and Cross-Border Cyber Hubs (Article 5) operating as advanced security operations centres for detection of significant cyber threa...

CSA-Art.3 · Establishment of the European Cybersecurity Alert System (Article 3)

Threat intelligence integration. Implements CyFun ID.RA-2: cyber threat intelligence is received from information-sharing forums and sources and integrated into risk processes.

BE-CF-16 · Threat intelligence integration

Article 32 establishes the ADVANCED CYBERSECURITY CONTROLS that critical-impact entities must implement IN ADDITION TO the Article 30 minimum controls.

NCCS-Art.32_33_34 · Advanced cybersecurity controls (NCCS Articles 32-34) - for critical-impact entities

FAA + NTSB cyber-incident reporting requirements + processes: (a) cybersecurity incidents affecting aircraft + air traffic control + safety of flight must be reported to the FAA per AC 119-1 + the operator OpsSpec + per FAA Order 1370.123A for FAA systems;

FAA-CSA-Operator-Cyber-IR · Aviation Cyber Incident Response and Reporting to FAA and NTSB

Questions people ask about cyber threat intelligence

What is Cyber Threat Intelligence?
Evidence-based knowledge about existing or emerging cyber threats that can be used to inform decisions regarding the organisation's response to those threats. CTI includes indicators of compromise, threat actor profiles, and attack patterns.
Why is Cyber Threat Intelligence important for compliance?
Cyber Threat Intelligence is a key concept in Information Security. Understanding cyber threat intelligence helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cyber Threat Intelligence?
Cyber Threat Intelligence appears in the requirement text of NIST Cybersecurity Framework 2.0, NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC), EU Cyber Solidarity Act (Regulation (EU) 2025/38), Belgium CyberFundamentals, EU Network Code on Cybersecurity for the Electricity Sector. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cyber Threat Intelligence?
Explore our compliance framework pages to see how cyber threat intelligence applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cyber Threat Intelligence applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.