Split sensitive tasks so no single person can abuse a process end-to-end.
What it actually means
Separation of duties reduces the risk of fraud or error by ensuring no one person controls an entire sensitive process. For small teams with few people this is hard, so the common compensating control is detective: strong logging and independent review so single-person actions stay visible. Document how you separate duties where you can, and how you compensate where you can't.
Pass or fail — an assessor needs a "yes" to each
- Have you identified sensitive functions and separated them across people where feasible?
- Where separation isn't possible, do you compensate with logging and independent review?
What to have ready
- Documented role / duty-separation matrix
- Review logs or oversight evidence for compensating controls
Where teams trip up
- One admin with unchecked control over everything and no review
- Assuming a small team makes the control N/A without any compensating control
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Access Control (3.1)
3.1.1 — Limit who (and what) can get in3.1.2 — Limit what users can do3.1.3 — Control the flow of CUI3.1.5 — Least privilege (especially for admins)3.1.6 — Use non-privileged accounts for routine work3.1.7 — Restrict and log privileged functions3.1.8 — Limit failed logons3.1.9 — Show privacy and security notices3.1.10 — Lock idle screens3.1.11 — End sessions automatically3.1.12 — Monitor and control remote access3.1.13 — Encrypt remote access sessions3.1.14 — Funnel remote access through managed points3.1.15 — Authorize privileged remote actions3.1.16 — Authorize wireless access first3.1.17 — Protect wireless with authentication + encryption3.1.18 — Control mobile device connections3.1.19 — Encrypt CUI on mobile devices3.1.20 — Control connections to external systems3.1.21 — Limit portable storage on external systems3.1.22 — Control what goes on public systems