Social engineering describes targeted manipulation techniques that induce people to disclose sensitive information or perform unintended actions. It relies on psychological tactics, contextual knowledge and trust-building. Effective prevention combines technical controls, organizational policies and regular awareness training and testing to reduce human-targ…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Social engineering comprises attacks that use deception, pressure, or trust to make people perform a security-relevant action.
The term comes from security research and describes exploiting human communication as an attack path. Phishing, pretexting, and impersonation are common forms.
Treat a message or request as a possible attack: who requests which action, through which channel, and under what time pressure? Protection combines independent verification, least privilege, safe processes, and training. Technology can detect patterns but cannot replace clear accountability.
An attacker uses psychological or social signals to trigger a desired action.
An invented role or situation gives a request apparent credibility.
An independent check through a known channel interrupts the attack.
Social engineering connects security controls with roles, approvals, and communication paths. Robust verification rules and a blame-free reporting environment are especially important.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.