AC.L2-3.1.4Separation of Duties
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
[a]
the duties of individuals requiring separation are defined;[b]
responsibilities for duties that require separation are assigned to separate individuals; and[c]
access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals.
No single person both approves and provisions enclave access
Implementation
AO coverage. Addresses all Separation of Duties objectives for enclave IAM and privileged IT functions.
Conflicting duties. Documented pairs that must not be held by one person: (1) access approver vs provisioner for enclave groups, (2) code deploy vs production break-glass for enclave apps, (3) security policy edit vs audit-log admin on the IdP.
Technical enforcement. ServiceNow workflows require distinct users for approve and fulfill. Okta admin roles that can change Conditional Access are eligible via PIM-equivalent and cannot be the same standing role as the log-retention admin.
Maintenance. Quarterly SoD report: export who held both sides of each pair in the last 90 days; exceptions need CISO sign-off.
Accepted gap. Company of this size cannot fully separate backup-operator from restore-operator overnight. Dual control is enforced by a witnessed restore checklist until a second trained operator is hired.
What the evidence looks like
- SoD policy listing conflicting duty pairs
- ServiceNow workflow config showing dual-user approve/fulfill
- Quarterly SoD report sample
- Backup restore witnessed checklist (compensating control)
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.