Cybersecurity GRC 16 items
Cyber Threat Intelligence Program Assessment
Assesses the maturity of a cyber threat intelligence program across the intelligence lifecycle, from requirements and collection through analysis, dissemination, and operational integration.
NIST 800-53MITRE ATT&CKISO 27001
Free PDF · enter your email to download.
Requirements & Direction
- Are Priority Intelligence Requirements (PIRs) documented and approved by stakeholders? *
- Is the organization's threat model and relevant threat actors documented? *
- Are intelligence consumers (SOC, IR, leadership, vulnerability mgmt) identified with defined needs? *
- Are PIRs reviewed and updated on a defined cadence?
Collection & Sources
- Are diverse sources used (commercial feeds, OSINT, ISAC/ISAO, government advisories)? *
- Is the organization a member of a relevant ISAC or information-sharing community?
- Are indicators of compromise ingested into detection and blocking controls? *
- Is source reliability and confidence tracked for collected intelligence?
Analysis & Production
- Is a structured analytic model (e.g., Diamond Model, Cyber Kill Chain) used for analysis? *
- Are adversary TTPs mapped to MITRE ATT&CK and tracked over time? *
- Are finished intelligence products tailored to the needs of each consumer? *
- Is a confidence and estimative-language standard applied to assessments?
Dissemination & Integration
- Is intelligence disseminated through defined channels with appropriate TLP markings? *
- Does threat intelligence inform detection engineering and threat hunting? *
- Is intelligence used to prioritize vulnerability remediation (threat-informed)?
- Is consumer feedback collected to refine future intelligence products?
Download the full Cyber Threat Intelligence Program Assessment checklist
Get it as a clean, printable PDF — free.
