unauthorized access
nounverified·updated May 9, 2026
Access to information or system components that ( a ) has not been approved by a person designated to do so by management and ( b ) compromises segregation of duties, confidentiality commitments, or otherwise increases risks to the information or system components beyond the levels approved by management (that is, access is inappropriate).
Framework senses
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
- §1
- Any access that violates the stated security policy.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §2 · sense_2_pending_review
- Any access that violates the stated security policy.
- §1
- Any access that violates the stated security policy.
- §1
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.
- §1 · attested_usage_pack_match
- No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · glossary
- Access to information or system components that ( a ) has not been approved by a person designated to do so by management and ( b ) compromises segregation of duties, confidentiality commitments, or otherwise increases risks to the information or system components beyond the levels approved by management (that is, access is inappropriate).Attribution from the CKI glossary mapping stage (glossary)
- §1 · legacy_primary
- Occurs when a user, legitimate or unauthorized, accesses a resource that the user is not permitted to use.DR-088 backfill from the noun definition column