Does your organization have a process to identify and manage unauthorized or unapproved technology solutions (shadow IT) being used to meet business objectives?
Explanation
Shadow IT refers to technology systems, software, devices, or services used within an organization without explicit IT department approval or knowledge. These unofficial solutions often emerge when employees seek to improve productivity or overcome limitations in approved tools. Examples include using personal cloud storage accounts for work files, unauthorized collaboration tools, or employee-developed applications.
Evidence of compliance could include documentation of shadow IT discovery processes, such as network scanning reports, application inventory tools, cloud access security broker (CASB) logs, or formal shadow IT assessment reports that identify unauthorized systems in use across the organization.
Implementation Example
Identify unofficial uses of technology to meet mission objectives (i.e., shadow IT)
ID: ID.AM-08.140
Context
- Function
- ID: IDENTIFY
- Category
- ID.AM: Asset Management
- Sub-Category
- Systems, hardware, software, services, and data are managed throughout their life cycles
Related questions
- Does your organization maintain comprehensive inventories of all hardware assets, including IT equipment, IoT devices, operational technology (OT), and mobile devices?
- Does your organization implement automated network monitoring to detect new hardware and update inventory records in real-time?
- Does your organization maintain a comprehensive inventory of all software and services, including commercial, open-source, custom, API, and cloud-based applications?
- Does your organization implement continuous monitoring for software and service inventory changes across all platforms, including containers and virtual machines?
- Does your organization maintain a comprehensive inventory of all systems within your environment?
- Does your organization maintain documented baselines of expected network communication patterns and data flows for both wired and wireless networks?

