Annex 8.1.1
Mapped SPARTA techniques (3)
Techniques referencing this article
Cyber-hygiene awareness across collaborator organizations limits the social-engineering footprint of cross-org repositories and shared portals where collaborator accounts are most often the entry point.
Mapping the human and institutional terrain to enable phishing, credential theft and invoice fraud is precisely the threat surface the cyber-hygiene awareness obligation addresses; the implementing regulation requires the entity to ensure employees understand the risks they expose through public profiles and routine communication.
Cyber-hygiene awareness is the human-side defence against social engineering against the well-connected nodes a relationship-recon adversary identifies as weakest.