From the course: CISSP Cert Prep (2021): 7 Security Operations

Unlock the full course today

Join today to access over 22,400 courses taught by industry experts or purchase this course individually.

Separation of duties and responsibilities

Separation of duties and responsibilities

From the course: CISSP Cert Prep (2021): 7 Security Operations

Start my 1-month free trial

Separation of duties and responsibilities

- [Instructor] The separation of duties principle says that no single person should possess two permissions that in combination, allow them to perform a sensitive operation. Instead, those permissions should be separated and held by two different groups of people. Account reviews and audit should inspect permissions to ensure that separation of duties is properly enforced. Let's take a look at a couple of examples of separation of responsibilities. One of the most common requirements for separation of duties comes in the world of accounting. Organizations normally separate the duties of creating new vendors in their accounting systems and authorizing payments to vendors. This separation prevents a single employee in the accounting department from creating a fake vendor and then issuing payments to that vendor in an attempt to embezzle funds. When separation of responsibilities is properly implemented, no single employee would…

Contents