home/dictionary/unauthorized access

unauthorized access

nounverified·updated May 9, 2026

Access to information or system components that ( a ) has not been approved by a person designated to do so by management and ( b ) compromises segregation of duties, confidentiality commitments, or otherwise increases risks to the information or system components beyond the levels approved by management (that is, access is inappropriate).

Framework senses

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
Any access that violates the stated security policy.
NIST Cybersecurity Framework1 senseview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
FFIEC Cybersecurity Assessment Tool, Baseline, May 20171 senseview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)1 senseview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
NERC CIP-006-6 (Physical Security of BES Cyber Systems) v61 senseview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
§2 · sense_2_pending_review
Any access that violates the stated security policy.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Any access that violates the stated security policy.
FIPS PUB 1911 senseview framework →
§1
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
TSP Section 1001 senseview framework →
§1 · glossary
Access to information or system components that ( a ) has not been approved by a person designated to do so by management and ( b ) compromises segregation of duties, confidentiality commitments, or otherwise increases risks to the information or system components beyond the levels approved by management (that is, access is inappropriate).
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
DR-088 backfill from the noun definition column