Pretexting
What is Pretexting?
A social engineering technique where an attacker creates a fabricated scenario to engage a victim and trick them into divulging information or taking action.
Frameworks that govern pretexting
What the standards actually require on pretexting
Requirements naming pretexting across 3 standards, quoted from the control text.
GLBA Subchapter II - Fraudulent Access to Financial Information (Sections 6821-6827). SECTION 6821 PROHIBITION ON OBTAINING CUSTOMER INFORMATION BY FALSE PRETENSES (PRETEXTING): it shall be a violation of this subchapter for any person to obtain or attempt to...
GLBA-Sec6821-Pretexting-Prohibition-Criminal · GLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties →FCC CPNI rules + Section 222 of the Communications Act are the principal US federal telecommunications-privacy framework. Status: REGULATIONS IN FORCE since 1996 (Section 222) + 1998 (initial FCC CPNI Order) + 2007 + 2009 + 2011 + 2017 amendments.
CPNI-Status · FCC CPNI - corpus status, enforcement landscape, broadband privacy →Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...
NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering →Questions people ask about pretexting
What is Pretexting?
Why is Pretexting important for compliance?
Which compliance frameworks address Pretexting?
Where can I learn more about Pretexting?
See how Pretexting applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.