The Problem With Security Monitoring
Most SaaS companies do one of two things: they read nothing and get caught off guard, or they subscribe to everything and read nothing because the volume is overwhelming. Neither helps your ISO 27001 programme.
The goal is a lightweight, sustainable routine where the output is always the same: an action or a documented non-action (i.e. "we reviewed this and it doesn't affect us"). Both are valid ISMS outputs. The habit of reviewing is the evidence.
The Suggested Routine
Weekly — Threat & Vulnerability Feed
Time required: 20–30 minutes
Read and triage current threat and vulnerability news. Capture anything relevant to your risk register, vulnerability management process, supplier management, or security awareness training.
Sources to check:
Weekly output: A short note (even just a Slack message or a row in a spreadsheet) logging what you reviewed and whether anything required action. This becomes evidence for A.5.7 (threat intelligence) and A.8.8 (vulnerability management).
Monthly — Standards, Frameworks & Regulatory Watch
Time required: 30–60 minutes
Review guidance from standards bodies and regulators. The cadence here is slower because these sources publish less frequently, but the content has direct ISMS implications.
Sources to check:
Monthly output: Translate anything relevant into ISMS actions — a policy update, a control review, a risk treatment update, an internal audit topic, or a management review input. Log the review even when no action results.
Quarterly — Landscape & Strategic Review
Time required: 1–2 hours
Review broader threat landscape reports, cloud and SaaS security trends, and major regulatory developments. Use this to inform your periodic risk assessment update and as evidence of continual improvement under ISO 27001 Clause 10.
Topics to cover:
Quarterly output: A paragraph or bullet list summarising what changed and how (if at all) it affects your ISMS. Feed this directly into your quarterly risk assessment update or management review inputs.
The Must-Follow Shortlist
If you only want a single bookmark folder to check regularly, start here:
| Source | Cadence | Why |
|---|---|---|
| ISO (iso.org) | Monthly | Standard updates and new publications |
| BSI (bsigroup.com) | Monthly | UK national body; good ISO 27001 commentary |
| ISO27k Forum | Monthly | Practitioner community; real-world interpretation |
| CISA | Weekly | Actionable advisories and KEV catalogue |
| ENISA | Monthly | EU regulatory and threat landscape |
| NIST CSRC | Monthly | SP 800-series, CVEs, framework updates |
| ISACA | Monthly | Audit and governance guidance |
| SANS ISC | Weekly | Active threat and vulnerability triage |
| BleepingComputer | Weekly | Fast, accurate breach and vuln news |
| Infosecurity Magazine | Weekly | Awareness content and security news |
| Microsoft Security Blog | Monthly | Cloud and enterprise threat research |
| Mandiant | Quarterly | Adversarial research and incident analysis |
Connecting the Routine to ISO 27001
Every review session, however brief, maps to explicit ISMS obligations:
| Activity | ISO 27001 clause / control |
|---|---|
| Weekly threat triage | A.5.7 Threat intelligence; A.8.8 Vulnerability management |
| Capturing relevant items | 6.1.2 Information security risk assessment |
| Monthly regulatory watch | 4.2 Interested parties; 4.1 Context of the organisation |
| Quarterly landscape review | 9.1 Monitoring; 10.2 Continual improvement |
| Logging reviews even with no action | 7.5 Documented information (evidence of operation) |
| Sharing findings with the team | A.6.3 Information security awareness |
| Using findings in management review | 9.3 Management review inputs |
The single most important habit: log every review session, even if all you write is "reviewed CISA this week — nothing relevant". The absence of an action is itself a documented decision. Auditors look for evidence of a functioning monitoring process, not for a certain number of findings.