Infringement
Abuse of Decision-Making Authority
Codebase Integrity Compromise
Data Integrity Manipulation
Data Loss
Delegated Execution via Artificial Intelligence Agents
Deliberate Safety Control Defeat
Denial of Service
Digital Defacement
Disruption of Business Operations
Excessive Personal Use
Exfiltration via Automated Transcription
Exfiltration via Email
Exfiltration via Media Capture
Exfiltration via Messaging Applications
Exfiltration via Other Network Medium
Exfiltration via Physical Medium
- Exfiltration via Bring Your Own Device (BYOD)
- Exfiltration via Disk Media
- Exfiltration via Floppy Disk
- Exfiltration via New Internal Drive
- Exfiltration via Physical Access to System Drive
- Exfiltration via Physical Documents
- Exfiltration via Target Disk Mode
- Exfiltration via USB Mass Storage Device
- Exfiltration via USB to Mobile Device
- Exfiltration via USB to USB Data Transfer
Exfiltration via Screen Sharing
Exfiltration via SMS/MMS
Exfiltration via Web Service
External Credential Sharing
Harassment and Discrimination
Inappropriate Web Browsing
Installing Malicious Software
Installing Unapproved Software
Internal Credential Sharing
Misappropriation of Funds
- Creation of Fictitious Invoices
- Creation of Fictitious Work Orders
- Excessive Overtime
- Expense Reimbursement Fraud
- Fraudulent Refund Issuance
- Insider Trading
- Manipulation of Performance-Based Compensation
- Misappropriation of Redeemable Value
- Misuse of a Corporate Card
- Modification of Invoices
- Prepaid Debit Cards
- Unauthorized Bank Transfers
Misuse of Corporate Communication Channels
Non-Corporate Device
Organizational Resource Diversion
Physical Sabotage
Providing Access to a Unauthorized Third Party
Public Statements Resulting in Brand Damage
Regulatory Non-Compliance
Sharing on AI Chatbot Platforms
Theft
Unauthorized Account Access
Unauthorized Changes to IT Systems
Unauthorized Organizational Representation
Unauthorized Presence in Restricted Physical Areas
- Remaining in a Restricted Area Outside Authorized Hours
- Unauthorized Presence in Data Center or Communications Areas
- Unauthorized Presence in Executive or Board Areas
- Unauthorized Presence in Records or Evidence Storage Areas
- Unauthorized Presence in Research, Laboratory, or Production Areas
- Unauthorized Presence in Security Operations Areas
Unauthorized Printing of Documents
Unauthorized VPN Client
Unauthorized Work Location
Undisclosed Concurrent Employment
Unlawfully Accessing Copyrighted Material
- ID: IF031
- Created: 09th April 2026
- Updated: 01st August 2026
- Contributor: The ITM Team
Unauthorized Presence in Restricted Physical Areas
A subject deliberately enters or remains within a physical area as a trespasser, knowing they are not authorized to be present, where that presence alone creates a credible risk of harm to the organization.
This infringement applies where the subject bypasses, ignores, or circumvents defined physical access restrictions, and where mere presence within the environment exposes sensitive assets, information, or operational context. In these cases, harm does not depend on further action; the subject's unauthorized proximity is sufficient.
Qualifying environments include areas where sensitive material is inherently exposed through observation or presence, such as:
- Product development labs containing unreleased intellectual property
- Executive or legal meeting spaces handling confidential matters
- Security operations environments during active incidents
- Locations where credentials, systems, or regulated data are visible without additional access steps
The defining characteristic is that the subject is present as a trespasser, not through error, misassignment, or legitimate overlap of duties. The subject understands the boundary and crosses it regardless.
Subsections (6)
| ID | Name | Description |
|---|---|---|
| IF031.006 | Remaining in a Restricted Area Outside Authorized Hours | A subject knowingly remains within a restricted physical area after their authorized access period has ended, or enters the area during a time when their role, assignment, escort approval, or access authorization does not permit their presence.
The subject may have legitimate daytime or task-based access to the location, but that authority does not extend to the time at which the presence occurs. Relevant behaviors include remaining after a shift or escorted visit, entering during a closed period, concealing continued presence after other personnel depart, or returning outside an approved access window.
The infringement is distinguished from accidental overstay by evidence that the subject understood the temporal restriction and deliberately remained or entered regardless. |
| IF031.001 | Unauthorized Presence in Data Center or Communications Areas | A subject deliberately enters or remains within a data center, server room, network operations area, telecommunications room, cable distribution area, or other restricted environment containing critical information technology or communications infrastructure without authorization to be present.
The subject’s proximity may provide direct access to servers, storage systems, network appliances, cabling, console interfaces, removable media, environmental controls, or out-of-band management equipment. The infringement applies where the subject knowingly crosses an established physical boundary, regardless of whether they subsequently interact with the equipment. |
| IF031.003 | Unauthorized Presence in Executive or Board Areas | A subject deliberately enters or remains within an executive office, boardroom, senior leadership meeting space, executive support area, or other restricted location used for confidential organizational decision-making without authorization.
The subject’s presence may expose strategic discussions, merger or acquisition information, financial results, legal advice, personnel decisions, security matters, executive schedules, authentication material, or confidential documents. The infringement applies even where the subject does not remove information or interrupt the meeting, because unauthorized observation or proximity may compromise sensitive organizational matters. |
| IF031.005 | Unauthorized Presence in Records or Evidence Storage Areas | A subject deliberately enters or remains within an area used to store physical records, legal files, personnel documents, investigative material, evidential items, archived media, regulated records, or chain-of-custody material without authorization.
Unauthorized presence may expose confidential information or provide an opportunity to inspect, remove, substitute, contaminate, damage, or interfere with stored material. The infringement applies where the subject knowingly enters the controlled area, even where subsequent access to a specific record or evidential item cannot be established. |
| IF031.004 | Unauthorized Presence in Research, Laboratory, or Production Areas | A subject deliberately enters or remains within a restricted research facility, laboratory, prototype area, test environment, manufacturing floor, production line, formulation area, engineering workspace, or other location containing sensitive development or operational activity without authorization.
The area may expose unreleased intellectual property, prototypes, formulas, samples, research data, specialized equipment, manufacturing methods, safety-critical processes, or regulated materials. The subject’s presence may create risks to confidentiality, product integrity, safety, regulatory compliance, or operational continuity even where no additional action is observed. |
| IF031.002 | Unauthorized Presence in Security Operations Areas | A subject deliberately enters or remains within a Security Operations Center, incident response room, insider threat investigation area, physical security control room, crisis-management room, or other restricted security operations environment without authorization.
Presence in these areas may expose active alerts, investigative information, subject identities, security architecture, surveillance feeds, response plans, detection capabilities, access credentials, or operational discussions. The subject does not need to interact with a security system or obtain a copy of information; unauthorized proximity to visible or audible security operations is sufficient for the infringement. |