Space ISAC (Information Sharing and Analysis Center) - Threat Framework
Ground Segment Threats

Space ISAC (Information Sharing and Analysis Center) - Threat Framework GT-4: Social Engineering Attacks

Social engineering and phishing attacks targeting space operations personnel must be monitored and reported.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 32 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • ASD37-37 Personnel management (Very Good)
  • CJIS-2 Security Awareness Training
  • CAT-D1-4 Training and culture
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

ISO 27799:2025 · 1 control

  • ISO27799-09 Security awareness and training program
  • ISO28001-PI-02 Security Awareness and Training

ISO/IEC 27011:2024 · 1 control

  • 27011-6.3 Awareness and Training

MARS-E · 1 control

  • MDS2-Roadmap-Third-Party-RDMP-Security-Guidance-SGUD-SBOM-Vulnerability-Disclosure-Programme MDS2 Roadmap + RDMP + Third Party + Security Guidance + SGUD + SBOM + Vulnerability Disclosure + Coordinated
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-66 · 1 control

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • OMANCS-8 Third-Party + Supply Chain Risk, Awareness Training, Physical Security, Compliance Audit
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • UKGAMBLE-4 Resilience and Incident Response

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Ground Segment Threats

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.