Skip to content

Impersonation

What is Impersonation?

A social engineering technique where an attacker pretends to be a trusted individual or authority figure to manipulate victims into revealing information.

Information Security

Each of these is named in at least one of the same controls as impersonation. The number is how many controls name both.

What the standards actually require on impersonation

Requirements naming impersonation across 6 standards, quoted from the control text.

Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...

NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance

Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.

ISM-2046 · Where software allows user impersonation, sensitive data is not logged and appropriate per

Phishing-resistant MFA for all users; verifier impersonation resistant; central authentication event logs.

E8-MFA-ML3 · Multi-Factor Authentication - Maturity Level 3

Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;

FAA-CSA-Personnel · Personnel Security Training and Insider Threat

Ghana CSA Cybercrime + Lawful Access + Preservation (Parts VII + VIII of Act 1038). CYBERCRIME OFFENCES (Sec.80-104): coordinated with Budapest Cybercrime Convention (which Ghana acceded to 2018) + Malabo Convention;

GhCSA-Cybercrime-Lawful-Access-Preservation · Cybercrime Offences, Lawful Access and Electronic Evidence Preservation

Threats during the enrollment and identity proofing phase including impersonation and forgery

29115-9.2 · Enrollment and identity proofing threats

Questions people ask about impersonation

What is Impersonation?
A social engineering technique where an attacker pretends to be a trusted individual or authority figure to manipulate victims into revealing information.
Why is Impersonation important for compliance?
Impersonation is a key concept in Information Security. Understanding impersonation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Impersonation?
Impersonation appears in the requirement text of NIST SP 800-63 Digital Identity Guidelines, Australian Information Security Manual, ACSC Essential Eight, FAA Cybersecurity Framework for Aviation, Ghana Cybersecurity Act. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Impersonation?
Explore our compliance framework pages to see how impersonation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Impersonation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.