Skip to content

Eavesdropping

What is Eavesdropping?

The interception of private communications or data transmissions without the knowledge or consent of the parties involved, a form of passive attack.

Information Security

What the standards actually require on eavesdropping

Requirements naming eavesdropping across 6 standards, quoted from the control text.

Adversary-operated base stations and air-interface eavesdropping that can intercept, redirect, or degrade subscriber traffic.

SP800-187-THR-ROGUE-BS · Threat: Rogue Base Stations and Eavesdropping

350.0-G-3 sec.2.3: characterisation of threats against space missions (e.g. eavesdropping, jamming, spoofing, replay, denial of service, unauthorised access, software threats).

CCSDS350-2.3 · Types of Threat

Requirements for protecting the quantum channel against side-channel attacks and eavesdropping

23837-1.6.3 · Quantum channel security

Use authentication protocols resistant to relevant threats including replay, eavesdropping, and man in the middle.

ISO29115-7.1 · Authentication Protocol Requirements

Protect information in networks through segmentation, secure transmission protocols, firewall and intrusion detection, secure remote access, and protection against eavesdropping and tampering.

TISAX-COMMS-01 · Communications and Network Security

Questions people ask about eavesdropping

What is Eavesdropping?
The interception of private communications or data transmissions without the knowledge or consent of the parties involved, a form of passive attack.
Why is Eavesdropping important for compliance?
Eavesdropping is a key concept in Information Security. Understanding eavesdropping helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Eavesdropping?
Eavesdropping appears in the requirement text of NIST SP 800-187, CCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems), ISO/IEC 23837 - Security Requirements for Quantum Key Distribution, ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, ITU-T X.805 - Security Architecture for End-to-End Communications. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Eavesdropping?
Explore our compliance framework pages to see how eavesdropping applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Eavesdropping applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.