ISO 27001
Annex A
Threat Intelligence
Segregation of Duties

How to Audit Threat Intelligence, Information Security Roles, and Segregation of Duties in ISO 27001

A practical ISO 27001 threat intelligence audit guide for testing security responsibilities, control ownership, approval independence, privileged access, segregation of duties, and real operational evidence.

Quick Answer

What should internal audit test?

An ISO 27001 threat intelligence audit should test whether relevant threat information is reviewed and converted into action.

Internal audit should also confirm that security responsibilities are clearly assigned and understood.

Finally, auditors should verify that sensitive activities are separated or independently reviewed when full segregation is not possible.

Some of the Most Important Controls Live Inside the Organization

Not every important ISO 27001 control sits inside a firewall.

Many controls depend on people, ownership, approvals, and oversight.

Who watches emerging threats? Who owns the control? Who approves access? Who implements changes?

These questions show whether organizational controls actually work in daily operations.

Practical rule: internal audit should test real workflows, not only policy statements.

Internal Audit Snapshot

Control Area What Internal Audit Should Test
Threat Intelligence Is relevant threat information reviewed and turned into action?
Threat Sources Are sources relevant to systems, vendors, sector, and risk?
Security Roles Are responsibilities clearly assigned and understood?
Control Ownership Does each important control have an accountable owner?
Segregation of Duties Are incompatible activities separated?
Approval Independence Can one person request, approve, and implement a high-risk action?

Why These Controls Matter Together

Threat intelligence, security roles, and segregation of duties may look separate.

In practice, they support the same security workflow.

Threat intelligence tells the organization what to watch. Security roles determine who acts. Segregation of duties ensures sensitive actions receive independent oversight.

Example: Critical Cloud Advisory

A cloud provider publishes a critical security advisory.

The organization should show that someone reviewed it, assessed risk, assigned action, approved any change, implemented the fix, independently reviewed it where needed, and retained evidence.

Practical rule: good organizational security depends on the right information reaching the right owner through the right controlled workflow.

The Main Internal Audit Question

The strongest question is not, “Do you have policies for these controls?”

A better question is:

Can you prove that threats are reviewed, responsibilities are understood, and sensitive activities are independently controlled?

1. Start With Threat Intelligence Sources

Threat intelligence should be relevant to the organization.

Collecting threat feeds without reviewing them adds little value.

Cloud provider security advisories.
Vendor security notifications.
Industry threat reports.
Software vulnerability advisories.
CERT or sector alerts.
Identity provider alerts.

Audit Questions

  • Which threat sources are monitored?
  • Who selected them?
  • Who reviews new alerts?
  • How often are sources reviewed?
  • What happens when a relevant threat is identified?

Common finding: multiple threat sources exist, but nobody can prove who reviews them or how relevant threats are escalated.

2. Test Whether Threat Intelligence Creates Action

The strongest threat intelligence evidence is not the advisory itself.

The strongest evidence is what happened because of the advisory.

Weak Evidence Strong Evidence
Threat report stored in a folder. Advisory linked to an internal assessment and action.
Security alert saved in email. Ticket, change, patch, or monitoring update created.
No owner identified. Named assessment and remediation owners.
Ticket marked closed. Implementation and validation evidence retained.

Practical rule: internal audit should test whether threat information changed security behavior.

3. Sample Threat Decisions Instead of Reviewing Everything

There is no need to collect every alert received during the year.

Use focused samples.

Suggested Sample

  • One critical vulnerability advisory.
  • One vendor security advisory.
  • One cloud-related threat.
  • One threat that triggered no action.
  • One threat that resulted in remediation.

Practical rule: sample threat decisions, not inbox volume.

Need to Test Organizational Controls Before Certification?

Canadian Cyber helps organizations audit ISO 27001 Annex A controls for threat intelligence, security responsibilities, control ownership, segregation of duties, and approval independence.

We focus on operational evidence, not policy-only assurance.

4. Test Information Security Roles and Responsibilities

Security responsibility should be clear.

It should not be assumed.

Audit Questions

  • Which roles have security responsibilities?
  • Are control owners assigned?
  • Are risk owners assigned?
  • Are evidence owners assigned?
  • Do employees understand their responsibilities?
  • Are responsibilities updated when roles change?

Common finding: responsibilities are documented centrally, but sampled control owners cannot explain what they are accountable for.

5. Separate Control Owner, Evidence Owner, and Approver

These roles may be different.

Internal audit should confirm that ownership reflects the actual operating model.

Control Owner

Ensures the control operates effectively.

Evidence Owner

Produces or maintains supporting evidence.

Approver

Provides independent authorization where required.

Example: IT Manager owns the access review control. An Identity Administrator produces evidence. The Head of Technology provides independent approval.

Practical rule: central ISMS coordination should not replace real operational ownership.

6. Test Security Responsibilities Through Interviews

Documents show what responsibility should look like.

Interviews show whether people actually understand it.

Question What It Tests
Which controls do you own? Ownership awareness.
What evidence do they produce? Evidence responsibility.
What happens if the control fails? Escalation knowledge.
Who reviews your work? Independent oversight.

Red flag: “I think Security handles that.”

7. Audit Segregation of Duties by Looking for Conflicts

Segregation of duties reduces the risk that one person can complete a sensitive activity without oversight.

Internal audit should look for incompatible responsibilities.

Requesting and approving access.
Creating and approving users.
Developing and deploying production changes.
Granting and reviewing privileged access.
Creating and closing audit findings.
Performing and approving vendor security reviews.

Practical rule: segregation of duties should be tested through transactions, not only policy wording.

8. Sample Real Approval Workflows

Internal audit should inspect real activity.

The evidence trail should show who requested, approved, implemented, and reviewed each action.

Suggested Sample

  • One user access request.
  • One privileged role assignment.
  • One production change.
  • One vendor approval.
  • One corrective action closure.

Common finding: a documented workflow requires independent approval, but sampled records show the same administrator requested and approved access.

9. Test Privileged Access Segregation

Privileged access creates higher risk.

Therefore, stronger independence should apply.

Audit Questions

  • Who creates privileged users?
  • Who approves privileged access?
  • Can administrators approve their own access?
  • Are emergency accounts controlled?
  • Are service accounts reviewed?
  • Are cloud admin roles independently reviewed?

Practical rule: the more powerful the access, the stronger the independence should be.

10. Test Change Management Segregation

Change management is another high-risk segregation area.

The auditor should test the sequence of request, approval, implementation, and validation.

Audit Step What to Verify
Request Who requested the change?
Approval Was approval recorded before implementation?
Implementation Who deployed the change?
Validation Who independently verified the result?

11. Test Segregation of Duties in Small Teams

Small organizations may not have enough staff to separate every activity fully.

That does not automatically mean the control fails.

Manager approval.
Independent retrospective review.
Activity logging.
Peer review.
External reviewer.
Enhanced monitoring.

Practical rule: when separation is impossible, independent oversight becomes more important.

12. Test Segregation Exceptions

Exceptions should not become the normal operating model.

They should be documented, approved, risk-assessed, and reviewed.

Evidence to Review

  • Segregation of duties exception register.
  • Risk acceptance record.
  • Manager approval.
  • Privileged activity logs.
  • Periodic review records.

Practical rule: an unmanaged exception becomes an uncontrolled process.

13. Link Segregation to Joiner-Mover-Leaver Processes

Role changes can create hidden conflicts.

An employee may receive new responsibilities while retaining access from the previous role.

Audit Questions

  • Are role changes reviewed?
  • Does access change when responsibilities change?
  • Are conflicting roles identified?
  • Are old privileges removed?
  • Do HR and IT communicate role changes?

14. Give Threat Intelligence Clear Ownership

Threat intelligence often fails because everyone assumes the security team owns everything.

Internal audit should verify specific accountability.

Responsibility Example Owner
Threat Monitoring Security Analyst
Risk Assessment Security Manager
Remediation IT or DevOps
Change Approval Technology Lead
Management Escalation CISO or vCISO

Practical rule: threat intelligence should move through defined ownership, not a shared inbox with no accountability.

15. Test Threat Intelligence Awareness

Some threats require communication beyond the security team.

Technical action alone may not be enough.

Sector phishing campaign.
Credential theft technique.
AI-related data leakage warning.
Cloud account compromise pattern.
Vendor breach notification.
New ransomware technique.

Practical rule: some threats require both technical action and human awareness.

Threat Intelligence Evidence Matrix

Evidence Area Weak Evidence Strong Evidence
Threat Sources Subscriptions only. Relevant sources with assigned owner.
Review Alerts stored in mailbox. Documented review and relevance decision.
Action Advisory downloaded. Ticket, patch, change, or monitoring update.
Awareness No communication. Targeted communication where human action is needed.

Roles and Responsibilities Evidence Matrix

Evidence Area Weak Evidence Strong Evidence
Roles Generic policy. Named responsibilities.
Control Ownership ISMS Manager owns everything. Operational owners assigned.
Understanding Name appears in a spreadsheet. Owner explains the control during interview.

Segregation of Duties Evidence Matrix

Evidence Area Weak Evidence Strong Evidence
Access Approval Same person requests and approves. Independent approval recorded.
Privileged Access Admins grant their own access. Independent privileged access approval.
Change Control Developer deploys directly. Approval and deployment are separated.
Small Team No separation or review. Compensating review and logging.

Common Internal Audit Findings

Threat intelligence is passive.
Threat ownership is unclear.
Security roles exist only on paper.
Too many controls are assigned to the ISMS Manager.
Segregation of duties is defined but not enforced.
Privileged access approval is weak.
Small-team conflicts have no compensating control.
Role changes create access conflicts.

Sample Internal Audit Finding

Weak Finding

Segregation of duties requires improvement.

Stronger Finding

The internal audit sampled five privileged access requests and found that two cloud administrator role assignments were requested and implemented by the same administrator. No independent approval was recorded before access was granted. Because the current workflow does not consistently enforce independent approval, the organization cannot demonstrate effective segregation between privileged access authorization and implementation.

Internal Audit Interview Questions

Interview Group Questions to Ask
Security Team Which threat sources do you monitor? How do you decide what matters? How is remediation assigned?
Control Owners Which controls do you own? What evidence do you produce? Who approves your work?
IT Administrators Can you approve your own access? Who reviews administrative activity?
Developers and DevOps Who approves production changes? Can developers deploy directly?
Leadership Which segregation conflicts remain open? Which threats required management action?

Internal Audit Checklist

Checklist Area What to Confirm
Threat Intelligence Sources are relevant, owned, reviewed, assessed, escalated, actioned, and verified.
Security Roles Control owners, evidence owners, risk owners, training, and escalation paths are clear.
Segregation of Duties Incompatible duties are identified, approvals are independent, exceptions are documented, and real samples prove separation.

How SharePoint Can Support These Controls

A SharePoint ISMS workspace can make ownership, threat tracking, segregation exceptions, and audit evidence easier to manage.

It can also make responsibility and independence visible to internal auditors and leadership.

Threat Intelligence Register
Track sources, assessments, owners, risk, and action.
Control Owner Matrix
Track operational and evidence ownership.
Security Roles Register
Track responsibilities and review status.
SoD Exception Register
Track conflicts, approvals, risk, and compensating controls.
Privileged Access Tracker
Track approval and independent review.
Certification Dashboard
Show ownership gaps, exceptions, overdue actions, and readiness risks.

Practical rule: SharePoint should make responsibility and independence visible, not bury them in policies.

High-Intent Buyer Signals

We receive threat alerts but do not track what happens next.
Our security responsibilities are unclear.
Our ISMS Manager owns too many controls.
Our admins can approve their own access.
We cannot fully separate duties because our team is small.
Our certification audit is approaching.

How Canadian Cyber Helps

Canadian Cyber helps organizations audit ISO 27001 Annex A organizational controls for threat intelligence, security responsibilities, and segregation of duties.

We help teams move from policy-based assurance to operational testing.

Our support includes threat intelligence reviews, control owner mapping, evidence owner mapping, segregation of duties testing, privileged access workflow reviews, change approval testing, SoD exception reviews, compensating control reviews, risk-based sampling, SharePoint ISMS dashboard setup, corrective action tracking, management review preparation, certification readiness reporting, vCISO services, SOC 2 readiness alignment, ISO 42001 AI governance readiness, ISO 27017, ISO 27018, and cybersecurity assessments.

Frequently Asked Questions

What is threat intelligence in ISO 27001?

Threat intelligence involves collecting and analyzing relevant security threat information so the organization can make informed decisions and take action where needed.

What evidence proves threat intelligence is working?

Strong evidence can include threat sources, relevance assessments, remediation tickets, risk updates, patches, monitoring changes, configuration changes, and awareness communication.

How should information security roles be audited?

Review role documentation, control owner matrices, evidence ownership, escalation paths, employee interviews, and actual control operation.

What is segregation of duties?

Segregation of duties separates conflicting responsibilities so one person cannot complete a sensitive activity without appropriate approval or independent oversight.

What if a small organization cannot fully segregate duties?

The organization can use risk-based compensating controls such as management approval, independent review, activity logging, periodic monitoring, peer review, or external oversight.

Should segregation of duties be tested through real samples?

Yes. Review real access requests, privileged role assignments, change tickets, exception records, and approvals to confirm segregation operates in practice.

Can SharePoint help manage these controls?

Yes. SharePoint can track threat assessments, security responsibilities, control owners, segregation conflicts, exceptions, compensating controls, corrective actions, and management review actions.

Takeaway

Threat intelligence, security roles, and segregation of duties are not paperwork controls.

They determine how security decisions move through the organization.

Threat intelligence without action is only information.

Security roles without understanding are only names on a matrix.

Segregation of duties without real workflow testing is only policy language.

Audit Organizational Controls Before Certification

Canadian Cyber can help your organization review threat intelligence, information security roles, control ownership, and segregation of duties before an ISO 27001 internal audit or certification audit.

We provide Annex A internal audits, threat intelligence reviews, responsibility mapping, segregation testing, privileged access reviews, change approval testing, SharePoint ISMS dashboards, corrective action tracking, management review preparation, vCISO support, SOC 2 readiness alignment, ISO 42001 AI governance readiness, ISO 27017, ISO 27018, and cybersecurity assessments.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, Annex A controls, threat intelligence, security responsibilities, segregation of duties, privileged access, certification readiness, SharePoint ISMS, SOC 2 readiness, AI governance, vCISO services, ISO 42001, ISO 27017, ISO 27018, and cybersecurity maturity.