A.5.3A.5 Organizational controls

Segregation of duties

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.3 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Lower the risk of fraud, mistakes and circumvention of security controls by splitting conflicting duties.

How to meet this control

In short: Separate conflicting duties and areas of responsibility to reduce fraud and error.

  1. Step 01Run a duty-conflict analysis that lists toxic combinations (request plus approve access, develop plus deploy to production, create plus pay a vendor) and document the required separations
  2. Step 02Configure role-based access in core systems (ERP, identity provider, cloud consoles) so conflicting permissions cannot sit in one account
  3. Step 03Where headcount is too small to separate duties, document compensating controls such as mandatory peer review, four-eyes approval and management oversight
  4. Step 04Use access governance tooling or periodic SoD reports to detect and flag conflicting role combinations as they arise
  5. Step 05Record any approved exceptions with the compensating control and an expiry date

Tip: Watch for one person who can both make and approve a change; split or add compensating review.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Identify which duties and areas of responsibility conflict and should be kept separate
  • ›Separate activities like requesting, approving and granting access rights
  • ›Separate development of software from administration of production systems
  • ›Separate use of applications from administration of the underlying databases
  • ›Keep the design, audit and assurance of controls in different hands
  • ›Account for the possibility of collusion when designing the separations
  • ›Where full separation is impractical, add compensating controls like monitoring, audit trails and supervision
  • ›Use automated tools to spot and remove conflicting role combinations when many roles exist

Audit evidence to keep

  • - Segregation-of-duties matrix identifying conflicting duties and required separations
  • - System role configuration or access reports demonstrating conflicting rights are not combined
  • - Records of compensating controls (peer review, dual approval) where full separation is impractical
  • - Exception register entries with compensating controls and review dates

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.3. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.