Information Assurance: Managing Organizational IT Security Risks

Significant IA threats can be divided into the following categories.
Unauthorized use by an authorized user of system resources for which he or she lacks formal approval
Unauthorized access by former users whose accounts were not deleted on departure
Unauthorized use of system resources by individuals who have physical access to the resources but who are not authorized users of the resources
Hacker penetrations of system resources
Undetected or uncorrected vulnerabilities that, when exploited, allow unauthorized access
Masquerading, which involves posing as an authorized user or program to gain access to system resources for example, a program such as a Trojan horse may act like another program to gain information (e.g., logon passwords or information files), or an unauthorized user may impersonate a network control center user to request router passwords and filter definitions
Replay, which involves recording a stream of previously transmitted encrypted text, such as an encrypted logon sequence, and retransmitting the stream at a later time in...