BSI ID: G 0.23
In principle, every interface to an IT system not only allows authorised users to use certain services of the IT system, but also carries the risk of unauthorised access to the IT system.
Examples:
If a user ID and the associated password are spied out, unauthorised use of the applications or IT systems protected by them is conceivable.
Hackers could gain unauthorised access to IT systems via inadequately secured remote maintenance access points.
If the interfaces of active network components are inadequately secured, it is conceivable that attackers could gain unauthorised access to the network component. If they also manage to overcome the local security mechanisms, e.g. by obtaining administrative authorisations, they could perform all administrative tasks.
Many IT systems have interfaces for the use of removable data storage devices, such as additional memory cards or USB storage media. In an unattended IT system with the appropriate hardware and software, there is a risk that large amounts of data could be read without authorisation or that malware could be introduced.