risk
Unauthorized use of equipment and unauthorized access escalation
Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Access Control & Identity Management
- taxonomy
- iso-27005-threat
- nist-800-30-threat-event
- inherent_rating
- medium
Details
- risk_id
- access-unauthorized-use-equipment
- category
- cyber_security
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- iso-27005-threat
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Changing vendor defaults before use closes the default-credential path to unauthorized system use.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- primary
- rationale
- Mediating every access attempt against approved authorizations directly blocks users reaching resources exceeding their authorization.
- UC-ACCESS-13 — Notify users of system terms and previous logon activity mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Last-logon and failed-attempt display is a soft detective aid: it helps users notice unauthorized account use after the fact but depends on user vigilance and does not itself prevent or reduce unauthorized use.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Prohibiting shared/group IDs and no-reuse rules close shared-account vectors for unauthorized use.
- UC-ACCESS-10 — Authenticate devices and services before granting connections mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- primary
- rationale
- Mutually authenticating devices and services before any connection directly blocks rogue or unauthorized devices from connecting.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Least privilege constrains authorized users from reaching resources beyond their authorization.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Pattern-hiding lock of unattended sessions prevents unauthorized use of an authenticated workstation.
- UC-ACCESS-14 — Authorize public content and external information sharing mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- primary
- rationale
- Explicitly defining and limiting actions permitted without authentication to designated public functions prevents anonymous unauthorized use of system functions.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Application allowlisting blocks unauthorized software and utility restriction prevents control-override escalation.