Phishing
What is Phishing?
A social engineering attack that uses fraudulent emails, text messages, or websites to trick users into revealing sensitive information such as passwords, credit card numbers, or personal data. Phishing remains the most common initial attack vector.
Terms that appear alongside phishing
Each of these is named in at least one of the same controls as phishing. The number is how many controls name both.
- authentication 27 shared controls
- nist 19 shared controls
- multi factor authentication 16 shared controls
- cybersecurity 15 shared controls
- social engineering 12 shared controls
- phishing simulation 11 shared controls
- audit 11 shared controls
- insider threat 10 shared controls
Frameworks that govern phishing
What the standards actually require on phishing
Requirements naming phishing across 6 standards, quoted from the control text.
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
ISM-1682 · Multi-factor authentication used for authenticating users of systems is phishing-resistant →FIDO2 PHISHING RESISTANCE properties + the channel binding + anti-replay + privacy mechanisms. PHISHING RESISTANCE: WebAuthn ceremonies bind the authentication to the ORIGIN (cryptographically verified by the client + RP server);
FIDO2-Phishing-Resistance · Phishing Resistance, Channel Binding, Anti-Replay and Privacy →Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...
NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance →Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks
5.4.1 · Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks →Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...
LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12 →Implement authentication per NIST SP 800-63-4 Volume B (Authentication and Authenticator Lifecycle). Approve authenticator types per Section 4 covering (a) memorised secrets (Section 4.1), (b) look-up secrets (Section 4.2), (c) out-of-band devices (Section 4.3...
NISTSP63R4-3 · Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators →Questions people ask about phishing
What is Phishing?
Why is Phishing important for compliance?
Which compliance frameworks address Phishing?
Where can I learn more about Phishing?
See how Phishing applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.