Shadow IT
Shadow IT: IT systems, applications, and cloud services that are not officially approved or managed. This term is relevant to the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.
How it works and where it fits
Shadow IT denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.
Practical security relevance
Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.
Related concepts
- Cloud-Native Application Protection PlatformCloud-Native Application Protection PlatformIntegrated platform for securing cloud applications across development and operations.: Integrated platform for securing cloud applications across development and operations.
- Cloud Security Posture ManagementCloud Security Posture ManagementDetects misconfigurations and compliance deviations in cloud environments.: Detects misconfigurations and compliance deviations in cloud environments.
- Security TestingSecurity TestingExamines systems, applications, and controls for weaknesses and malfunctions.: Examines systems, applications, and controls for weaknesses and malfunctions.
- Shared Responsibility ModelShared Responsibility ModelDivision of security tasks between the cloud provider and the customer.: Division of security tasks between the cloud provider and the customer.