Shadow IT

Hardware, software or cloud services used for organisational work without the knowledge or approval of IT or security, and therefore missing from the inventory and its controls.

Shadow IT is hardware, software or cloud services used for organisational work without the knowledge or approval of the IT or security function. Typical examples are personal file-sharing accounts used to move work documents, software-as-a-service tools bought by a department on a company card, and unapproved devices connected to the network. It usually arises from convenience rather than malice.

The security problem is visibility. An asset missing from the asset inventory has no recorded asset owner, has not been through asset classification, and receives none of the controls its data would require: no patching, no access reviews, and no contract terms covering where the data is stored. Discovery helps close the gap. A cloud access security broker can identify unsanctioned cloud services from network traffic, while IT asset management, network scanning and network access control can surface unmanaged devices.

Exam relevance: questions in this area tend to describe company data found in an unapproved service, or an unknown device on the network, and ask for the first or best step. Candidates are expected to see that discovery and inventory come before protection, and that bringing a useful tool under management can be a better answer than a blanket ban, which tends to push usage further out of sight.