T 2.7 Unauthorised use of rights

Rights such as physical, system, and data access authorisations are used as organisational safeguards to ensure the information, business processes, and IT systems are protected against unauthorised access. If such rights are granted to the wrong person or such a right is exercised without authorisation, then a number of threats may be posed that place the confidentiality and integrity of data or the availability of computing power at risk.
