Browse Definitions :
Definition

shadow app

A shadow app is a software program that is not supported by an employee's information technology (IT) department.

In the past, shadow apps were often installed locally by impatient employees who wanted immediate access to software without going through normal corporate channels. With the growth of software-as-a-service (SaaS) and cloud computing, however, the meaning has expanded to include third-party consumer software that is accessed over the Internet.

Skype, Lucidchart, Dropbox, Google Spreadsheets, Docusign and CloudOn are all popular shadow apps. Although many shadow apps can improve productivity and collaboration with little or no financial cost to the company, their use comes with risks. If an employee accesses a cloud app with his personal account, for example, corporate data may be put at risk or even lost if the employee leaves the company. Shadow apps can also cause bandwidth issues on the corporate network, slowing things down and impacting everyone's productivity.

To prevent problems, an IT department should have a service audit process in place to inspect outbound packets and verify ownership of company-owned services in the cloud. The organization should also have policy in place that requires employees to use corporate accounts for web-based applications and restrict network privileges so end users cannot install software locally. If a large group of employees is using a particular cloud app, the IT department should consider providing the service in house and finally, the IT department should educate employees about the value of corporate data and the risks that shadow apps present.

See also: shadow IT, rogue IT

This was last updated in August 2014

Continue Reading About shadow app

SearchCompliance
  • OPSEC (operations security)

    OPSEC (operations security) is a security and risk management process and strategy that classifies information, then determines ...

  • smart contract

    A smart contract is a decentralized application that executes business logic in response to events.

  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

SearchSecurity
  • private key

    A private key, also known as a secret key, is a variable in cryptography that is used with an algorithm to encrypt and decrypt ...

  • DOS (disk operating system)

    A DOS, or disk operating system, is an operating system that runs from a disk drive. The term can also refer to a particular ...

  • security token

    A security token is a physical or digital device that provides two-factor authentication for a user to prove their identity in a ...

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • change control

    Change control is a systematic approach to managing all changes made to a product or system.

  • disaster recovery (DR)

    Disaster recovery (DR) is an organization's ability to respond to and recover from an event that affects business operations.

SearchStorage
  • What is RAID 6?

    RAID 6, also known as double-parity RAID, uses two parity stripes on each disk. It allows for two disk failures within the RAID ...

  • PCIe SSD (PCIe solid-state drive)

    A PCIe SSD (PCIe solid-state drive) is a high-speed expansion card that attaches a computer to its peripherals.

  • VRAM (video RAM)

    VRAM (video RAM) refers to any type of random access memory (RAM) specifically used to store image data for a computer display.

Close