Segregation of duties
Purpose
Lower the risk of fraud, mistakes and circumvention of security controls by splitting conflicting duties.
How to meet this control
In short: Separate conflicting duties and areas of responsibility to reduce fraud and error.
- Step 01Run a duty-conflict analysis that lists toxic combinations (request plus approve access, develop plus deploy to production, create plus pay a vendor) and document the required separations
- Step 02Configure role-based access in core systems (ERP, identity provider, cloud consoles) so conflicting permissions cannot sit in one account
- Step 03Where headcount is too small to separate duties, document compensating controls such as mandatory peer review, four-eyes approval and management oversight
- Step 04Use access governance tooling or periodic SoD reports to detect and flag conflicting role combinations as they arise
- Step 05Record any approved exceptions with the compensating control and an expiry date
Tip: Watch for one person who can both make and approve a change; split or add compensating review.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Identify which duties and areas of responsibility conflict and should be kept separate
- ›Separate activities like requesting, approving and granting access rights
- ›Separate development of software from administration of production systems
- ›Separate use of applications from administration of the underlying databases
- ›Keep the design, audit and assurance of controls in different hands
- ›Account for the possibility of collusion when designing the separations
- ›Where full separation is impractical, add compensating controls like monitoring, audit trails and supervision
- ›Use automated tools to spot and remove conflicting role combinations when many roles exist
Audit evidence to keep
- - Segregation-of-duties matrix identifying conflicting duties and required separations
- - System role configuration or access reports demonstrating conflicting rights are not combined
- - Records of compensating controls (peer review, dual approval) where full separation is impractical
- - Exception register entries with compensating controls and review dates
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.3. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.