Browse Definitions :
Definition

shadow app

A shadow app is a software program that is not supported by an employee's information technology (IT) department.

In the past, shadow apps were often installed locally by impatient employees who wanted immediate access to software without going through normal corporate channels. With the growth of software-as-a-service (SaaS) and cloud computing, however, the meaning has expanded to include third-party consumer software that is accessed over the Internet.

Skype, Lucidchart, Dropbox, Google Spreadsheets, Docusign and CloudOn are all popular shadow apps. Although many shadow apps can improve productivity and collaboration with little or no financial cost to the company, their use comes with risks. If an employee accesses a cloud app with his personal account, for example, corporate data may be put at risk or even lost if the employee leaves the company. Shadow apps can also cause bandwidth issues on the corporate network, slowing things down and impacting everyone's productivity.

To prevent problems, an IT department should have a service audit process in place to inspect outbound packets and verify ownership of company-owned services in the cloud. The organization should also have policy in place that requires employees to use corporate accounts for web-based applications and restrict network privileges so end users cannot install software locally. If a large group of employees is using a particular cloud app, the IT department should consider providing the service in house and finally, the IT department should educate employees about the value of corporate data and the risks that shadow apps present.

See also: shadow IT, rogue IT

This was last updated in August 2014

Continue Reading About shadow app

SearchCompliance
  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

  • risk exposure

    Risk exposure is the quantified potential loss from business activities currently underway or planned.

SearchSecurity
  • script kiddie

    Script kiddie is a derogative term that computer hackers coined to refer to immature, but often just as dangerous, exploiters of ...

  • cipher

    In cryptography, a cipher is an algorithm for encrypting and decrypting data.

  • What is risk analysis?

    Risk analysis is the process of identifying and analyzing potential issues that could negatively impact key business initiatives ...

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • gigabyte (GB)

    A gigabyte (GB) -- pronounced with two hard Gs -- is a unit of data storage capacity that is roughly equivalent to 1 billion ...

  • MRAM (magnetoresistive random access memory)

    MRAM (magnetoresistive random access memory) is a method of storing data bits using magnetic states instead of the electrical ...

  • storage volume

    A storage volume is an identifiable unit of data storage. It can be a removable hard disk, but it does not have to be a unit that...

Close