Skip to content

Vishing

What is Vishing?

Voice phishing, a social engineering attack that uses phone calls or voice messages to trick victims into revealing sensitive information. Vishing attacks often impersonate banks, government agencies, or technical support.

Information Security

What the standards actually require on vishing

Requirements naming vishing across this standard, quoted from the control text.

Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + a...

NISTSP115-4 · Target Vulnerability Validation - Password Cracking, Pen Testing, Social Engineering

Questions people ask about vishing

What is Vishing?
Voice phishing, a social engineering attack that uses phone calls or voice messages to trick victims into revealing sensitive information. Vishing attacks often impersonate banks, government agencies, or technical support.
Why is Vishing important for compliance?
Vishing is a key concept in Information Security. Understanding vishing helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Vishing?
Vishing appears in the requirement text of NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment). Across these standards we have identified 1 control that names it directly, each linked to the control text on the compliance platform.
Where can I learn more about Vishing?
Explore our compliance framework pages to see how vishing applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Vishing applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.