Cyber Risk Compendium

Unauthorized use or administration of devices and systems

BSI ID: G 0.30

Without suitable mechanisms for access control, unauthorised use of devices and systems cannot be prevented or detected in practice. In IT systems, the basic mechanism is user identification and authentication. However, even in IT systems with strong identification and authentication functions, unauthorised use is conceivable if the relevant security features (passwords, chip cards, tokens, etc.) fall into the wrong hands. Many mistakes can also be made when assigning and maintaining authorisations, for example if authorisations are too broad, granted to unauthorised persons or not updated in a timely manner. Unauthorised persons can gain access to confidential information, manipulate data or cause disruptions through the unauthorised use of devices and systems. A particularly important special case of unauthorised use is unauthorised administration. If unauthorised persons change the configuration or operating parameters of hardware or software components, this can result in serious damage.

Example:

  • While checking log data, a network administrator encountered initially unexplained events that occurred on various days, but frequently in the early morning and afternoon. Upon closer inspection, it turned out that a Wi-Fi router was configured insecurely. People waiting at the bus stop in front of the company building used this access to surf the Internet on their mobile devices while waiting.