Skip to content

Social Engineering

What is Social Engineering?

The psychological manipulation of people into performing actions or divulging confidential information. Social engineering attacks exploit human trust rather than technical vulnerabilities and include phishing, pretexting, and baiting.

Information Security

Each of these is named in at least one of the same controls as social engineering. The number is how many controls name both.

What the standards actually require on social engineering

Requirements naming social engineering across 6 standards, quoted from the control text.

CIS Controls v82 controls

Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.

CIS-14.2 · Train Workforce Members to Recognize Social Engineering Attacks
PCI DSS 4.02 controls

Security awareness training includes threats and vulnerabilities that could impact the security of cardholder data including phishing and related attacks, and social engineering.

12.6.3.1 · Training on phishing and social engineering

Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.

ISM-2071 · Personnel dealing with user account details are advised of what social engineering attacks

Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...

NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering

Social engineering and phishing attacks targeting space operations personnel must be monitored and reported.

GT-4 · Social Engineering Attacks

Types of cyber threats. The company should identify the types of cyber threats (untargeted and targeted, including malware, phishing, social engineering and OT-specific threats) that could affect ship systems.

BIMCO-2.2 · Types of cyber threats

Questions people ask about social engineering

What is Social Engineering?
The psychological manipulation of people into performing actions or divulging confidential information. Social engineering attacks exploit human trust rather than technical vulnerabilities and include phishing, pretexting, and baiting.
Why is Social Engineering important for compliance?
Social Engineering is a key concept in Information Security. Understanding social engineering helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Social Engineering?
Social Engineering appears in the requirement text of CIS Controls v8, PCI DSS 4.0, Australian Information Security Manual, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), Space ISAC (Information Sharing and Analysis Center) - Threat Framework. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Social Engineering?
Explore our compliance framework pages to see how social engineering applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Social Engineering applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.