# Standards — Social Engineering Penetration Testing ## Frameworks - PTES Social Engineering Section: http://www.pentest-standard.org/index.php/Social_Engineering - NIST SP 800-50: Building an Information Technology Security Awareness and Training Program - SANS Security Awareness Maturity Model - MITRE ATT&CK Initial Access: https://attack.mitre.org/tactics/TA0001/ ## MITRE ATT&CK Techniques | Technique | ID | Vector | |-----------|----|--------| | Phishing: Spear Phishing Link | T1566.002 | Email with malicious URL | | Phishing: Spear Phishing Attachment | T1566.001 | Email with payload | | Phishing: Spear Phishing via Service | T1566.003 | Social media / messaging | ## Legal Considerations - Must have explicit written authorization - Cannot target personal email or devices without consent - GDPR compliance for EU employees - Cannot use real malware or destructive payloads - Results must be anonymized in reporting to protect individuals