Skip to content

feat(iso27001-gap): add threat intelligence to risk register evidence gates#2770

Closed
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:improve/iso27001-gap-threat-intel-gates
Closed

feat(iso27001-gap): add threat intelligence to risk register evidence gates#2770
zeroknowledge0x wants to merge 1 commit into
UnitOneAI:mainfrom
zeroknowledge0x:improve/iso27001-gap-threat-intel-gates

Conversation

@zeroknowledge0x

Copy link
Copy Markdown

Closes #2768

Follows the issue-first policy. Issue #2768 documents this skill.

Previous PRs (#2761, #2763, #2765) were auto-closed by needs-approved-issue policy. Re-raised now that #2768 exists.

… gates

Add structured threat intelligence evidence flow framework to A.5.7:
- Intelligence Source: documented source of threat intelligence
- Relevance Decision: documented assessment of applicability
- Risk Register Link: traceable connection to register item
- Treatment Owner: named individual/role for risk response
- Residual Score Update: score updated when threat changes
- Review Timestamp: when intelligence was reviewed

Add false positive guidance for advisory-only feeds.
Add missed variant detection for supplier-specific advisories.
Add edge case handling for duplicate feeds, regional advisories.
Add remediation quality checklist for intelligence improvements.

Closes UnitOneAI#2704

Signed-off-by: ZKA SUPER <zeroknowledge0x@users.noreply.github.com>
@github-actions github-actions Bot added the one-open-pr Contributor already has an open PR; only one allowed at a time label Jun 22, 2026
@github-actions

Copy link
Copy Markdown

Thanks for contributing! 🙏 To keep the queue reviewable, we allow one open PR per contributor at a time. You already have #2769 open, so we're closing this one — please reopen it after that PR is resolved.

@github-actions github-actions Bot closed this Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

one-open-pr Contributor already has an open PR; only one allowed at a time

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add threat intelligence evidence gates to ISO27001 A.5.7 risk register

1 participant