Skip to content

Reconnaissance

What is Reconnaissance?

The initial phase of a cyberattack where threat actors gather information about target systems, networks, and organizations to plan their attack strategy.

Information Security

Each of these is named in at least one of the same controls as reconnaissance. The number is how many controls name both.

What the standards actually require on reconnaissance

Requirements naming reconnaissance across 6 standards, quoted from the control text.

MITRE ATT&CK1 control

Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations.

MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact · MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact
PTES2 controls

Active reconnaissance including port scans, service identification, and banner grabbing must enumerate live hosts and exposed services within the agreed scope.

PTES-INT-2 · Active Information Gathering

Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information.

CIS-18.2 · Perform Periodic External Penetration Tests

Quantify attempted attacks against the institution including phishing, DDoS, and reconnaissance traffic.

FFIEC-CAT-IRP-5 · External Threats

HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.

HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs
MITRE D3FEND1 control

Apply D3FEND MODEL tactic - establishing the digital domain that the defender intends to defend. D3-AM Asset Inventory + D3-NM Network Mapping + D3-ID Identity Discovery + D3-NM-AM Asset Mapping + D3-SI System Inventory + D3-UA User Account Inventory + D3-SWI...

MITRE-D3FEND-Model-Tactic-System-Inventory-Network-Mapping-Identity-Discovery-Asset-Identification · MITRE D3FEND Model Tactic + System Inventory + Network Mapping + Identity Discovery + Asset Identification

Questions people ask about reconnaissance

What is Reconnaissance?
The initial phase of a cyberattack where threat actors gather information about target systems, networks, and organizations to plan their attack strategy.
Why is Reconnaissance important for compliance?
Reconnaissance is a key concept in Information Security. Understanding reconnaissance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Reconnaissance?
Reconnaissance appears in the requirement text of MITRE ATT&CK, PTES, CIS Controls v8, FFIEC Cybersecurity Assessment Tool (CAT), HKMA Cyber Resilience Assessment Framework (C-RAF). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Reconnaissance?
Explore our compliance framework pages to see how reconnaissance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Reconnaissance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.