Skip to content

Pretexting

What is Pretexting?

A social engineering technique where an attacker creates a fabricated scenario to engage a victim and trick them into divulging information or taking action.

Information Security

What the standards actually require on pretexting

Requirements naming pretexting across 3 standards, quoted from the control text.

GLBA1 control

GLBA Subchapter II - Fraudulent Access to Financial Information (Sections 6821-6827). SECTION 6821 PROHIBITION ON OBTAINING CUSTOMER INFORMATION BY FALSE PRETENSES (PRETEXTING): it shall be a violation of this subchapter for any person to obtain or attempt to...

GLBA-Sec6821-Pretexting-Prohibition-Criminal · GLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties

FCC CPNI rules + Section 222 of the Communications Act are the principal US federal telecommunications-privacy framework. Status: REGULATIONS IN FORCE since 1996 (Section 222) + 1998 (initial FCC CPNI Order) + 2007 + 2009 + 2011 + 2017 amendments.

CPNI-Status · FCC CPNI - corpus status, enforcement landscape, broadband privacy

Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...

NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering

Questions people ask about pretexting

What is Pretexting?
A social engineering technique where an attacker creates a fabricated scenario to engage a victim and trick them into divulging information or taking action.
Why is Pretexting important for compliance?
Pretexting is a key concept in Information Security. Understanding pretexting helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Pretexting?
Pretexting appears in the requirement text of GLBA, FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011), NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment). Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Pretexting?
Explore our compliance framework pages to see how pretexting applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Pretexting applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.