risk
Abuse of rights, forged rights, and repudiation of actions
Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Access Control & Identity Management
- Logging, Monitoring & Detection
- taxonomy
- iso-27005-threat
- nist-800-30-threat-event
- nist-800-30-threat-source
- inherent_rating
- high
Details
- risk_id
- access-privilege-abuse-repudiation
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-threat
- nist-800-30-threat-event
- nist-800-30-threat-source
Source
No record-specific source URL is provided.
Connections
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Protecting logs from modification/deletion and alerting on tampering preserves audit-trail integrity so privileged users cannot cover tracks or repudiate.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Never embedding keys in code and protecting authenticators prevents credential/key forgery used to gain privileges.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Unique, non-shared identifiers mapped to accountable owners are the attribution foundation that defeats repudiation of actions.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Always-invoked, tamper-resistant authorization enforcement blocks access beyond permitted scope and resists forged rights.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Capturing and reviewing privileged/admin session activity detects authorized users exploiting access beyond permitted scope.
- UC-ACCESS-07 — Proof identities before binding credentials mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Proofing and binding identity to credentials prevents fraudulent enrollment and forged-identity credential issuance.
- UC-LOG-01 — Log security-relevant events across all systems mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Logging authentication and privileged actions creates the accountability record that detects rights abuse and defeats repudiation of actions.
- UC-LOG-02 — Record complete audit content with synchronized clocks mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Recording identity, source, and outcome with clocks synced to an authoritative source delivers reliable attribution that defeats repudiation.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Need-to-know least privilege directly limits the scope available for abuse of rights and privilege escalation.
- UC-ACCESS-02 — Review user access rights periodically mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Removing standing/excess privilege found in reviews shrinks the rights available to be abused.
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Restricting and logging privileged and utility-program use on separate admin identities directly limits and attributes abuse of rights.