{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Risk Assessment & Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-17","description":"Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.","details":{"control_category":"technical","control_type":"detective","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"A.5.7","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"RA-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Information relating to threats is collected from internal and external sources and analyzed to produce actionable strategic, tactical, and operational threat intelligence that informs risk assessments and defensive measures. A threat hunting capability proactively searches organizational systems for indicators of compromise that evade existing detection controls. Intelligence products and hunt reports are produced on a defined cadence and drive response actions.","title":"Operate threat intelligence and threat hunting","unified_id":"UC-RISK-17"},"id":"uc:UC-RISK-17","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-17","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-RISK-17 — Operate threat intelligence and threat hunting","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:833eaa526020986f864a71bd92b2d97be764d0f1f6238b3c49eab79320e46215","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","targetId":"uc:UC-RISK-17","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a298d20beb96fc664a4303769fbb08b723e4c7e231bce73d8a3bdbad4036e729","properties":{"rationale":"Threat intel on fraud campaigns and hunting for indicators of account compromise help surface credential-theft account takeover, alongside auth/monitoring defenses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","sourceId":"uc:UC-RISK-17","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d07b8d4ff9f3bb16068b3bf85756957731ab8d0a0683e2c7e53d3320d980e07c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c20-5b99e185.json","sourceId":"wf:C20","targetDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","targetId":"uc:UC-RISK-17","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d16f10ed1a0c7529a9cb3f843113b2246df77c34d6c0e5cdc78c5c436dd87122","properties":{"control_id":"A.5.7","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","sourceId":"uc:UC-RISK-17","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-7-0328fe6b.json","targetId":"ctrl:iso-27001:A.5.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dec5b00cdde31ce06893dd667e3c0484986998830d51ec0ae7f72dca2ea50ec7","properties":{"rationale":"Threat intelligence and proactive threat hunting for IOCs directly detect and counter attacks by motivated threat actors, including activity that evades existing detection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","sourceId":"uc:UC-RISK-17","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e03f81fa6ac0785ed4f98e5bfb1399af39461766bb3a8c1d2e1cd6befc263fe1","properties":{"control_id":"RA-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-17-4ea73b39.json","sourceId":"uc:UC-RISK-17","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-10-30932a94.json","targetId":"ctrl:nist-800-53:RA-10","type":"maps_to"}],"schemaVersion":1}
