A parks department quietly adopts an unsanctioned public SaaS form tool for event registrations without IT review. How should security classify this situation?
Select an answer to reveal the explanation.
Short Explanation
Shadow IT is the 'helpful' side door—someone spins up a handy SaaS form without asking security. Intent can be innocent, but the attack surface still went unmanaged, like adding a unlocked annex to city hall.
Full Explanation
Shadow IT refers to systems or services adopted without organizational approval or security oversight, creating unmanaged risk and attack surface. Malicious nation-state activity, completed authorized change control, and deliberate insider theft describe different situations. Treating unsanctioned SaaS as shadow IT focuses remediation on discovery, risk assessment, and governance rather than assuming hostile intent.