Browse Definitions :
Definition

dark infrastructure

Contributor(s): Matthew Haughn

Dark infrastructure is undocumented but active software or services whose existence and function is unknown to system administrators -- despite the fact that it may be integral to the continued operation of documented infrastructure.

Dark infrastructure’s undocumented code may tie together pieces of known infrastructure, filling in needed functions.  Without inspection of how software is operating, an administrator might never discover that dark infrastructure exists. Often dark infrastructure may not be noticed until something stops working.

An administrator may discover dark infrastructure when they look for the source of a problem and may learn where the unknown service is and how it functions while they attempt to correct the issue. Dark infrastructure can cause additional difficulties in troubleshooting, especially while it remains undetected.

There are any number of situations that can lead to undocumented infrastructure. For example, a vendor may add software services at the last minute and not take the time to document the changes. In other cases, changes may be made by individual administrators to correct issues after deployment. Either way, this quick, quiet work may correct the immediate issues but result in dark infrastructure that causes problems down the road.

This was last updated in November 2015

Continue Reading About dark infrastructure

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

  • compliance framework

    A compliance framework is a structured set of guidelines that details an organization's processes for maintaining accordance with...

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

SearchSecurity

  • DNS over HTTPS (DoH)

    DNS over HTTPS (DoH) is a relatively new protocol that encrypts domain name system traffic by passing DNS queries through a ...

  • integrated risk management (IRM)

    Integrated risk management (IRM) is an approach to risk management that uses a set of practices and processes to improve an ...

  • MITRE ATT&CK framework

    The MITRE ATT&CK (pronounced 'miter attack') framework is a free, globally accessible service that provides comprehensive and ...

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

SearchStorage

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification and is used in internally mounted ...

  • kilobyte (KB or Kbyte)

    A kilobyte (KB or Kbyte) is a unit of measurement for computer memory or data storage used by mathematics and computer science ...

  • virtual memory

    Virtual memory is a memory management capability of an operating system (OS) that uses hardware and software to allow a computer ...

Close