From the course: Certified Information Security Manager (CISM) Cert Prep (2022): 1 Information Security Governance

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

Separation of duties and responsibilities

Separation of duties and responsibilities

- [Instructor] The separation of duties principle says that no single person should possess two permissions that in combination, allow them to perform a sensitive operation. Instead, those permissions should be separated and held by two different groups of people. Account reviews and audits should inspect permissions to ensure that separation of duties is properly enforced. Let's take a look at a couple of examples of separation of responsibilities. One of the most common requirements for separation of duties comes in the world of accounting. Organizations normally separate the duties of creating new vendors in their accounting systems and authorizing payments to vendors. This separation prevents a single employee in the accounting department from creating a fake vendor and then issuing payments to that vendor in an attempt to embezzle funds. When separation of responsibilities is properly implemented, no single employee…
