HomeControl Library › 3.1.4
3.1 Access Control1 ptPOA&M-eligible

3.1.4 — Separate duties

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

Split sensitive tasks so no single person can abuse a process end-to-end.

What it actually means

Separation of duties reduces the risk of fraud or error by ensuring no one person controls an entire sensitive process. For small teams with few people this is hard, so the common compensating control is detective: strong logging and independent review so single-person actions stay visible. Document how you separate duties where you can, and how you compensate where you can't.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library