An IT administrator at a manufacturing company discovers that an employee installed an unauthorized third-party cloud storage application on a corporate desktop to transfer large file packages, bypassing corporate security policy. Which threat vector or security risk category best describes this situation?
- Shadow ITAnswer
- BNation-state threat actor
- CHacktivist collective
- DSupply chain attack vector
Answer
Shadow IT
Shadow IT encompasses any IT resources, cloud applications, or hardware introduced into an enterprise infrastructure without official security authorization. The employee's installation of unvetted cloud software to circumvent file transfer restrictions is a classic example of Shadow IT.
Step-by-Step Solution
Key Concept
Shadow IT as an Internal Threat Vector