unified

UC-RISK-17 — Operate threat intelligence and threat hunting

Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Risk Assessment & Management
type
detective
category
technical

Details

unified_id
UC-RISK-17
title
Operate threat intelligence and threat hunting
statement
Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.
domain
Risk Assessment & Management
control_type
detective
control_category
technical
members
  • framework
    iso-27001
    control_id
    A.5.7
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    RA-10
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections