unified
UC-RISK-17 — Operate threat intelligence and threat hunting
Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- detective
- category
- technical
Details
- unified_id
- UC-RISK-17
- title
- Operate threat intelligence and threat hunting
- statement
- Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.
- domain
- Risk Assessment & Management
- control_type
- detective
- control_category
- technical
- members
- framework
- iso-27001
- control_id
- A.5.7
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- RA-10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-RISK-17 — Operate threat intelligence and threat hunting
- UC-RISK-17 — Operate threat intelligence and threat hunting mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- related
- rationale
- Threat intel on fraud campaigns and hunting for indicators of account compromise help surface credential-theft account takeover, alongside auth/monitoring defenses.
- Threat Intelligence & Insider Threat Program operates UC-RISK-17 — Operate threat intelligence and threat hunting
- UC-RISK-17 — Operate threat intelligence and threat hunting maps_to A.5.7 — Threat intelligence
- framework
- iso-27001
- control_id
- A.5.7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-17 — Operate threat intelligence and threat hunting mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Threat intelligence and proactive threat hunting for IOCs directly detect and counter attacks by motivated threat actors, including activity that evades existing detection.
- UC-RISK-17 — Operate threat intelligence and threat hunting maps_to RA-10 — Threat Hunting
- framework
- nist-800-53
- control_id
- RA-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.