Skip to content

feat(iso27001-gap): add threat intelligence to risk register evidence gates#2761

Closed
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:improve/iso27001-gap-threat-intel-gates
Closed

feat(iso27001-gap): add threat intelligence to risk register evidence gates#2761
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:improve/iso27001-gap-threat-intel-gates

Conversation

@zeroknowledge0x

Copy link
Copy Markdown

Automated PR from bounty executor shipper.

  • Branch: improve/iso27001-gap-threat-intel-gates
  • Last commit: feat(iso27001-gap): add threat intelligence to risk register evidence gates

… gates

Add structured threat intelligence evidence flow framework to A.5.7:
- Intelligence Source: documented source of threat intelligence
- Relevance Decision: documented assessment of applicability
- Risk Register Link: traceable connection to register item
- Treatment Owner: named individual/role for risk response
- Residual Score Update: score updated when threat changes
- Review Timestamp: when intelligence was reviewed

Add false positive guidance for advisory-only feeds.
Add missed variant detection for supplier-specific advisories.
Add edge case handling for duplicate feeds, regional advisories.
Add remediation quality checklist for intelligence improvements.

Closes UnitOneAI#2704

Signed-off-by: ZKA SUPER <zeroknowledge0x@users.noreply.github.com>
@github-actions github-actions Bot added the needs-approved-issue PR has no linked maintainer-approved issue label Jun 22, 2026
@github-actions

Copy link
Copy Markdown

Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened.

Please open an issue describing the skill, wait for the approved label, then reopen this PR with Closes #<issue> in the description. The PR template lists everything we'll look for (including an independently runnable reproduction).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-approved-issue PR has no linked maintainer-approved issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant