Unknown or unauthorised identities (users) and assets can connect to known assets
Context and Guidance: Each identity (user) should be authorised before being provisioned with access to assets (such as networks, systems, and applications).
This excludes Guest wireless network access, which provides Internet access only, and does not allow access to other organisational assets.
An example of an unauthorised asset is an employee’s personal computer that is not managed by the function. Remote desktop access from an unauthorised asset should be considered when assessing this Anti-Pattern.