GAISSF / D7 / D7-CTL-H02

Deepfake Detection Training

Objective

Prevent CEO/executive impersonation fraud.

Control / requirement

Training modules + quiz + simulated attacks.

Business impact

Deepfake impersonation featured in 35% of breaches where attackers used AI (IBM Cost of a Data Breach Report, 2025); individual deepfake-enabled fraud incidents have exceeded $25M (2024 multinational CFO video-deepfake case).

Validation approach

Test ID: D7-CTL-H02-VTS-001 Test Type: Manual Test Design: Annual training on voice/video deepfake indicators for high-risk roles Execution Steps: 1. Deploy training module 2. Target high-risk roles 3. Administer quiz 4. Track completion & pass rates Pass Criteria: high_risk_role_completion_rate >= 95%; quiz_pass_rate >= 90%; annual_training_completed = True Independent Verification: Auditor reviews training records and quiz results.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.