BSI ID: G 0.32
Depending on their roles and tasks, individuals are granted appropriate access and access authorisations. This is intended to control and monitor access to information on the one hand, and to enable individuals to perform certain tasks on the other.
For example, individuals or groups require certain authorisations to run applications or process information or edit information.
Authorisation is misused when rights or privileges are intentionally used unlawfully or improperly opportunities acquired are used outside the intended scope. The aim is often to gain personal advantage or to harm an institution or specific individuals.
In many cases, individuals have higher or more extensive access rights than they need for their work for historical, technical or other reasons. These rights may be misused for attacks under certain circumstances.
Examples:
The more granular the access rights to information are, the greater the maintenance effort required to keep these authorisations up to date. There is therefore a risk that when access rights are assigned, too little distinction is made between the different roles, thereby facilitating the misuse of authorisations.
In various applications, access authorisations or passwords are stored in system areas that can also be accessed by other users. This could allow attackers to change authorisations or read passwords.
People with overly generous authorisations may be tempted to access other people's files, for example to view someone else's email, because they urgently need certain information.
ย