Social Engineering

From Open Risk Manual

Definition

Social Engineering. A general term for trying to deceive people into revealing information or performing certain actions. In the context of Cyber Risk in particular, social tactics employ deception, manipulation, intimidation, etc to exploit the human element, or users, of information assets. Includes pretexting, phishing, blackmail, threats, scams, etc.

Reference

  • Adapted from FFIEC
  • VERIS