Art. 21(2)(g)
Mapped SPARTA techniques (6)
Techniques referencing this article
Spear-phishing of operators and contractors is one of the named initial-access vectors; Art. 21(2)(g)'s basic cyber hygiene practices and cybersecurity training raise human resilience to that path.
Removable-media discipline and peripheral hygiene are core elements of basic cyber hygiene practices under Art. 21(2)(g) — particularly during hurried I&T or contingency maintenance when auto-ingest workflows are most exploitable.
Spear-phishing of operators and vendors is one of the named initial-access routes; Art. 21(2)(g)'s basic cyber hygiene practices and cybersecurity training raise the floor of human resilience to that vector.
Org-chart enumeration feeds spear-phishing, invoice-fraud, and credential-theft pretexts; basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) are the obligation that builds resistance in operators, finance, and engineering staff.
Spear-phishing, credential reuse, and exposure of secrets in scripts/CI runners are addressed by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) that build human resilience to the most common credential-theft vectors.
Tailored phishing, invoice fraud, and credential reuse leveraged off business-relationship recon are countered by basic cyber hygiene practices and cybersecurity training under Art. 21(2)(g) covering operators, finance, and engineering staff.