Attack Vector
What is Attack Vector?
The method or pathway used by a threat actor to gain unauthorised access to a target system. Common attack vectors include phishing emails, unpatched software vulnerabilities, and compromised credentials.
Frameworks that govern attack vector
What the standards actually require on attack vector
Requirements naming attack vector across 6 standards, quoted from the control text.
FAA AC 120-76D (latest revision) addresses Electronic Flight Bag (EFB) operational authorisation including cybersecurity considerations: (a) EFB classification (Class 1 / Class 2 / Class 3 - portable + installed + integrated) with different cybersecurity basel...
FAA-CSA-EFB · Electronic Flight Bag (EFB) Operational Authorisation Cybersecurity →FIRST Common Vulnerability Scoring System (CVSS) v4.0 published November 2023 + CVSS v3.1 (2019) maintained for legacy advisories. CVSS v4.0 STRUCTURE: (a) BASE METRICS - Attack Vector + Attack Complexity + Attack Requirements + Privileges Required + User Inte...
FIRST-CVSS-v4 · FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy →HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination →Identify is the first of five functional elements per MSC-FAL.1/Circ.3/Rev.2 (aligned with NIST CSF Identify). Activities include: (1) Asset Inventory of vulnerable systems organisationally + onboard ship - Operational Technology (OT) systems including Bridge...
IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities · IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA →Operate detection and analysis per NIST SP 800-61 Rev 2 Section 3.2 (Detection and Analysis). Tasks include (a) Attack vectors as taxonomy (External/Removable Media + Attrition + Web + Email + Improper Usage + Loss or Theft of Equipment + Other) for categorisa...
NISTSP61-4 · Detection and Analysis: Sources, Triage, Categorisation, Prioritisation →Operate security test + certification + conformance per O-RAN WG11 Security Test Specifications and WG11 Test Specifications including Open Test and Integration Center (OTIC) testing.
ORANWG11-6 · Security Test Specifications, Certification, and Conformance →Questions people ask about attack vector
What is Attack Vector?
Why is Attack Vector important for compliance?
Which compliance frameworks address Attack Vector?
Where can I learn more about Attack Vector?
See how Attack Vector applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.