From the course: CSSLP Cert Prep: 1 Secure Software Concepts

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Separation of duties

Separation of duties

From the course: CSSLP Cert Prep: 1 Secure Software Concepts

Start my 1-month free trial

Separation of duties

- [Instructor] As organizations grow in size, they often grow in complexity, as well. This complexity is particularly evident when it comes to the apps that users rely on and their access to those apps. As it becomes more and more difficult to determine who has access to what, it becomes that much harder to determine whether your users should have access they shouldn't. That access comes with risks that could be mitigated before anything bad happens. You can get ahead of those risks, though, if you understand separation of duties. When you implement separation of duties controls, you set up sensitive functions so that no one person can do too much. SOD Controls offer you a simple, yet effective way to prevent users from committing fraud. It's generally accepted that people need three things to commit fraud. They need a motive, like the need to pay bills; they need a mindset that lets them justify their actions; and they…

Contents