CCAK

 View Only
  • 1.  Shadow IT Examples?

    Posted Jun 10, 2021 10:39:00 AM

    Hello :)

    In the CCAK training, Shadow IT comes up quite frequently as an example of a risk, especially when talking about auditing compliance and governance programs. 

    I was wondering if someone could provide some examples of Shadow IT that commonly occur within companies?



    ------------------------------
    Jenna Morrison
    Training Department Intern
    Cloud Security Alliance
    ------------------------------


  • 2.  RE: Shadow IT Examples?

    Posted Jun 11, 2021 08:09:00 AM
    Hi Jenna, 

    Marketing department need a new web site. They work with an external PR agency to create one. PR agency creates a basic hosted web site, but a new domain on behalf of the customer and the site starts working. (Already shadow)

    Later on, the marketing department decides to connect the web site to some other company system for better user experience. They are using their own users without notifying IT department. Now company data is integrated to uncontrolled external system which is legally owned by the company. IT has no idea about this. (Hence very shadow)

    They will most probably learn about it after the site is hacked. (Horror story)

    ------------------------------
    Murat L
    President
    Lostar
    ------------------------------



  • 3.  RE: Shadow IT Examples?

    Posted Jun 11, 2021 01:37:00 PM
    Thank you, this is helpful!

    ------------------------------
    Jenna Morrison
    Training Department Intern
    Cloud Security Alliance
    ------------------------------



  • 4.  RE: Shadow IT Examples?

    Posted Jun 14, 2021 07:05:00 AM
    Edited by Ilia Tivin Jun 14, 2021 07:06:50 AM

    Shadow IT would mean anything that is done "procuring IT services" without the explicit knowledge of the IT organization in the company.

    Dropbox, OneDrive and any other model of delivery (SaaS/PasS/IaaS) that is used by other departments without a formal approval or oversight of the IT organization.



    ------------------------------
    Ilia Tivin CISSP-ISSMP, CCSP, CCSK, ITIL
    ------------------------------