{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Awareness & Training","Access Control & Identity Management"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-phishing-social-engineering","description":"Adversary counterfeits trustworthy communications (email, phone, spoofed websites) to trick individuals — including high-value executives — into revealing credentials or sensitive information, or into enabling wire-transfer/BEC fraud.","details":{"category":"cyber_security","impact":"high","inherent_rating":"critical","likelihood":"very_high","risk_id":"aware-phishing-social-engineering","taxonomies":["nist-800-30-threat-event","basel-operational-risk"],"treatment":"mitigate"},"id":"risk:aware-phishing-social-engineering","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-phishing-social-engineering","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Phishing, spear-phishing and social engineering","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04a6d208fc62e199456b186b546a117766f45f54a64aeed4d2363ae94b8f1298","properties":{"rationale":"Control explicitly runs phishing simulations and social-engineering awareness, directly lowering susceptibility to deception/credential theft.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-01-5f513831.json","sourceId":"uc:UC-TRAIN-01","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:23043fe161d8a3824846ebf453d44150b2ff499f0c7c1afc949b74f290d2361a","properties":{"rationale":"Pre-publication review preventing exposure of nonpublic information reduces reconnaissance data available for spear-phishing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c6dc8c856463292032e32bf0a63fe9ef585c7f0adc0383287070634517e5ca7","properties":{"rationale":"Re-proofing on credential recovery defends against social-engineering of help-desk account-recovery takeover.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0ccdb2eee56a902f62515a1cee4335fa6d18466bbea94354557bcbe8503b9a9","properties":{"rationale":"Adaptive step-up or denial catches use of phished credentials from anomalous location/device contexts.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8436cf942803f6684548623379ec24ed1adf724f2ef38897a2c22b83c5b428f","properties":{"rationale":"MFA blocks account takeover even when a password is phished, the canonical defense against credential-harvesting social engineering.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1b3abcf8c9c8952565d3ca576ef903596bcfcfab69cd74413d18d7b96a78797","properties":{"rationale":"Collecting phishing-simulation/assessment results and improving content raises anti-phishing effectiveness indirectly.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-train-03-7125ac3e.json","sourceId":"uc:UC-TRAIN-03","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f03995f9ce07a0711c5ff0a5bddd73b8ff642f1d17b626a734053d230f07e39b","properties":{"rationale":"Role-based training for senior leaders and privileged staff directly defends against executive-targeted spear-phishing/BEC.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-train-02-88898a0b.json","sourceId":"uc:UC-TRAIN-02","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"}],"schemaVersion":1}
