Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does authorised access mean the activity was legitimate?

No. Technical permission to enter a system can exceed the organisational authority to use particular data or functions. Access may be limited by role, purpose, time, case, customer, approval or instruction.

Compare capability with authority

Identify what the system allowed, what the person's role and business process permitted, the applicable purpose and approval, and the exact action performed. Poor access control can expose far more than a role legitimately requires.

Where policy is relied upon, confirm it applied to the person, system and period and was communicated. Policy breach alone does not prove malicious or criminal intent.

Respect changes over time

Temporary assignments, emergency roles, suspension and revocation can make the same action authorised at one time and not another. Preserve role activation, instructions and approval timing.

Assess necessity and context as well as formal permission. Separate technical capability, policy authority and personal purpose in the final conclusion.

Key takeaway

Test each action against the authority and purpose existing at that time; system permission alone does not establish legitimacy.

Reference: CIM-232Cyber Incidents & Offender Methods