GAISSF / D7 / D7-CTL-H01

Ai-Generated Phishing Simulation

Objective

Reduce human vulnerability (primary attack vector).

Control / requirement

Simulation campaigns + click tracking + remedial training.

Business impact

Human error remains the leading attack vector (74% of breaches, Verizon DBIR). AI-generated phishing increases click rates 15x, with average breach cost $4.44M.

Validation approach

Test ID: D7-CTL-H01-VTS-001 Test Type: Manual Test Design: Quarterly AI-generated phishing emails, voice deepfakes, SMS lures against employee population Execution Steps: 1. Generate AI-phishing campaign 2. Deploy to employees 3. Track clicks & reporting 4. Deliver remedial training 5. Measure click rate Pass Criteria: click_rate < 5%; employee_coverage >= 90%; remedial_training_completed_within_7_days = True Independent Verification: Auditor reviews simulation results and training records.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.