Skip to content

Attack Vector

What is Attack Vector?

The method or pathway used by a threat actor to gain unauthorised access to a target system. Common attack vectors include phishing emails, unpatched software vulnerabilities, and compromised credentials.

Information Security

What the standards actually require on attack vector

Requirements naming attack vector across 6 standards, quoted from the control text.

FAA AC 120-76D (latest revision) addresses Electronic Flight Bag (EFB) operational authorisation including cybersecurity considerations: (a) EFB classification (Class 1 / Class 2 / Class 3 - portable + installed + integrated) with different cybersecurity basel...

FAA-CSA-EFB · Electronic Flight Bag (EFB) Operational Authorisation Cybersecurity

FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Inte...

FIRST-CVSS-v4 · FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination

Identify is the first of five functional elements per MSC-FAL.1/Circ.3/Rev.2 (aligned with NIST CSF Identify). Activities include: (1) Asset Inventory of vulnerable systems organisationally + onboard ship - Operational Technology (OT) systems including Bridge...

IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities · IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

Operate detection and analysis per NIST SP 800-61 Rev 2 Section 3.2 (Detection and Analysis). Tasks include (a) Attack vectors as taxonomy (External/Removable Media + Attrition + Web + Email + Improper Usage + Loss or Theft of Equipment + Other) for categorisa...

NISTSP61-4 · Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

Operate security test + certification + conformance per O-RAN WG11 Security Test Specifications and WG11 Test Specifications including Open Test and Integration Center (OTIC) testing.

ORANWG11-6 · Security Test Specifications, Certification, and Conformance

Questions people ask about attack vector

What is Attack Vector?
The method or pathway used by a threat actor to gain unauthorised access to a target system. Common attack vectors include phishing emails, unpatched software vulnerabilities, and compromised credentials.
Why is Attack Vector important for compliance?
Attack Vector is a key concept in Information Security. Understanding attack vector helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Attack Vector?
Attack Vector appears in the requirement text of FAA Cybersecurity Framework for Aviation, FIRST CSIRT Services Framework and Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), NIST SP 800-61. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Attack Vector?
Explore our compliance framework pages to see how attack vector applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Attack Vector applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.