Identities (users) cannot be individually identified and attributed to a person
Context and Guidance: Organisations need to be able to uniquely identify individuals who use assets (such as networks, systems, and applications) relevant to the function. This involves consideration of the principles of attribution and non-repudiation.
Without the ability to distinguish identities (users) between individuals, anonymous users can perform malicious or illegal activity without their actions being linked back to them.
For the context of this Anti-Pattern: