Skip to content

Phishing

What is Phishing?

A social engineering attack that uses fraudulent emails, text messages, or websites to trick users into revealing sensitive information such as passwords, credit card numbers, or personal data. Phishing remains the most common initial attack vector.

Information Security

Each of these is named in at least one of the same controls as phishing. The number is how many controls name both.

What the standards actually require on phishing

Requirements naming phishing across 6 standards, quoted from the control text.

Multi-factor authentication used for authenticating users of systems is phishing-resistant.

ISM-1682 · Multi-factor authentication used for authenticating users of systems is phishing-resistant

FIDO2 PHISHING RESISTANCE properties + the channel binding + anti-replay + privacy mechanisms. PHISHING RESISTANCE: WebAuthn ceremonies bind the authentication to the ORIGIN (cryptographically verified by the client + RP server);

FIDO2-Phishing-Resistance · Phishing Resistance, Channel Binding, Anti-Replay and Privacy

Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...

NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance
PCI DSS 4.03 controls

Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks

5.4.1 · Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Implement authentication per NIST SP 800-63-4 Volume B (Authentication and Authenticator Lifecycle). Approve authenticator types per Section 4 covering (a) memorised secrets (Section 4.1), (b) look-up secrets (Section 4.2), (c) out-of-band devices (Section 4.3...

NISTSP63R4-3 · Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

Questions people ask about phishing

What is Phishing?
A social engineering attack that uses fraudulent emails, text messages, or websites to trick users into revealing sensitive information such as passwords, credit card numbers, or personal data. Phishing remains the most common initial attack vector.
Why is Phishing important for compliance?
Phishing is a key concept in Information Security. Understanding phishing helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Phishing?
Phishing appears in the requirement text of Australian Information Security Manual, FIDO2 / WebAuthn, NIST SP 800-63 Digital Identity Guidelines, PCI DSS 4.0, Lloyd's Minimum Standards - Cyber Security. Across these standards we have identified 19 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Phishing?
Explore our compliance framework pages to see how phishing applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Phishing applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.