A risk practitioner finds that the enterprise threat landscape is described in a single document that was written two years ago and has not changed since. The board wants the landscape to reflect adversary activity as it evolves. Which practice would MOST reliably keep the threat landscape current?
- ASchedule a single annual penetration test of the external estate and update the landscape only from its findings.
- BAsk each system owner to confirm in writing every year that no new threats now apply to their own system.
- CAdopt a recognised control framework and map each existing control to its relevant clause, section and owner.
- DFeed continuously updated threat intelligence on relevant actors and campaigns into a regular review of the landscape. Correct
Why A is wrong: Annual penetration testing reveals exploitable weaknesses at a point in time, but it is too infrequent and vulnerability-focused to track how adversary behaviour shifts between tests.
Why B is wrong: Periodic owner attestations are easy to collect yet rely on local opinion rather than external evidence, so emerging threat actors and campaigns go unnoticed between cycles.
Why C is wrong: Mapping controls to a framework documents the defensive posture, but it describes what the organisation does and not how the surrounding threat environment is evolving.
Why D is correct: Ongoing threat intelligence about active adversaries, their targets and their methods is the input that lets the landscape be revised as the external environment changes rather than at a fixed date.