Definition
A technology offense involving unauthorized access, interference, deception, or unlawful interception using electronic systems. It is defined by authorization status, protected system or data, and the required intent or harm elements where applicable. It does not include authorized access or communications conduct that satisfies applicable consent requirements. It safeguards system and data integrity and commonly supports restitution and forfeiture remedies. The concept is generally stable, though coverage expands as technical methods evolve over time.
Principle
Principle
Access control and authentication govern lawful use; unauthorized access occurs when those controls are bypassed, defeated, or absent and no lawful consent exists.
Demonstration
Demonstration
An external actor exploits a vulnerable remote management port to join an enterprise LAN and enumerate internal hosts; alternatively, a person uses stolen VPN credentials to access a corporate network.
Misapplication
Misapplication
Labeling every failed login attempt or benign network scan as unauthorized access; treating publicly reachable services that advertise guest access as automatically protected.
Consequence
Consequence
When correctly identified, it triggers incident response, potential criminal investigation, and mitigation measures to restore confidentiality and availability of networked resources.
Reversal
Reversal
Authorized access: connection and use permitted by policy, explicit consent, or credentialed authentication that the owner recognizes as lawful.
Boundary
Boundary
Covers network-level intrusion and use of network services; excludes lawful remote access, purely physical presence outside network equipment, and interaction with genuinely public resources disclosed for open use.
Semantic Tension
Semantic Tension
Differs from 'Unauthorized Access to Data' by focusing on network entry and resource use rather than the act of obtaining specific data; overlaps with trespass and tampering when access is used to modify systems.
Synthesis
Synthesis
Unauthorized access to a computer network is the technical and legal characterization of connecting to or using networked infrastructure without the permission required by the network’s access controls, producing risks to confidentiality, integrity, and availability.