Social Engineering
What is Social Engineering?
The psychological manipulation of people into performing actions or divulging confidential information. Social engineering attacks exploit human trust rather than technical vulnerabilities and include phishing, pretexting, and baiting.
Terms that appear alongside social engineering
Each of these is named in at least one of the same controls as social engineering. The number is how many controls name both.
- phishing 12 shared controls
- insider threat 7 shared controls
- security awareness 5 shared controls
- penetration testing 3 shared controls
- security awareness training 3 shared controls
- vulnerability 3 shared controls
- cybersecurity 3 shared controls
- nist 2 shared controls
Frameworks that govern social engineering
What the standards actually require on social engineering
Requirements naming social engineering across 6 standards, quoted from the control text.
Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.
CIS-14.2 · Train Workforce Members to Recognize Social Engineering Attacks →Security awareness training includes threats and vulnerabilities that could impact the security of cardholder data including phishing and related attacks, and social engineering.
12.6.3.1 · Training on phishing and social engineering →Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.
ISM-2071 · Personnel dealing with user account details are advised of what social engineering attacks →Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...
NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering →Social engineering and phishing attacks targeting space operations personnel must be monitored and reported.
GT-4 · Social Engineering Attacks →Types of cyber threats. The company should identify the types of cyber threats (untargeted and targeted, including malware, phishing, social engineering and OT-specific threats) that could affect ship systems.
BIMCO-2.2 · Types of cyber threats →Questions people ask about social engineering
What is Social Engineering?
Why is Social Engineering important for compliance?
Which compliance frameworks address Social Engineering?
Where can I learn more about Social Engineering?
See how Social Engineering applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.