Impersonation
What is Impersonation?
A social engineering technique where an attacker pretends to be a trusted individual or authority figure to manipulate victims into revealing information.
Terms that appear alongside impersonation
Each of these is named in at least one of the same controls as impersonation. The number is how many controls name both.
- phishing 8 shared controls
- authentication 6 shared controls
- nist 5 shared controls
- identity proofing 4 shared controls
- insider threat 3 shared controls
- cybersecurity 3 shared controls
- consent 3 shared controls
- ransomware 2 shared controls
Frameworks that govern impersonation
What the standards actually require on impersonation
Requirements naming impersonation across 6 standards, quoted from the control text.
Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...
NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance →Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.
ISM-2046 · Where software allows user impersonation, sensitive data is not logged and appropriate per →Phishing-resistant MFA for all users; verifier impersonation resistant; central authentication event logs.
E8-MFA-ML3 · Multi-Factor Authentication - Maturity Level 3 →Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;
FAA-CSA-Personnel · Personnel Security Training and Insider Threat →Ghana CSA Cybercrime + Lawful Access + Preservation (Parts VII + VIII of Act 1038). CYBERCRIME OFFENCES (Sec.80-104): coordinated with Budapest Cybercrime Convention (which Ghana acceded to 2018) + Malabo Convention;
GhCSA-Cybercrime-Lawful-Access-Preservation · Cybercrime Offences, Lawful Access and Electronic Evidence Preservation →Threats during the enrollment and identity proofing phase including impersonation and forgery
29115-9.2 · Enrollment and identity proofing threats →Questions people ask about impersonation
What is Impersonation?
Why is Impersonation important for compliance?
Which compliance frameworks address Impersonation?
Where can I learn more about Impersonation?
See how Impersonation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.