Zum Hauptinhalt springen
Glossary

Angriffsvektor

Updated on 1 min Reviewed by: Cenedril Editorial

An attack vector is the path or method through which an attacker gains access to a target system. Examples include phishing emails, exposed network services, compromised supply chains, or physical access to devices.

Identifying attack vectors is a central step in risk identification under ISO 27005 and ISO 27001 Clause 6.1.2. Each attack vector links a threat to a vulnerability and the affected asset. In BSI IT-Grundschutz, this corresponds to the threat analysis. For prioritization, what matters is how exposed a vector is (e.g., reachable from the internet vs. internal only) and what preconditions an attacker must meet. A complete picture of attack vectors is the foundation for targeted protective measures.

No Cookies!

This wiki collects nothing, bakes nothing and leaves nothing behind. There's nothing to consent to. Privacy doesn't get better than this.