Skip to content

Separation of Duties

What is Separation of Duties?

A security principle that divides critical tasks among multiple individuals to prevent fraud, error, and misuse by ensuring no single person controls all aspects of a process.

Information Security

Each of these is named in at least one of the same controls as separation of duties. The number is how many controls name both.

What the standards actually require on separation of duties

Requirements naming separation of duties across 6 standards, quoted from the control text.

Split duties across separate identities so no single person can both perform and approve a sensitive action.

CCM-IAM-04 · Separation of Duties

Separation of duties is implemented in performing administrative activities for gateways.

ISM-0616 · Separation of duties is implemented in performing administrative activities for gateways.

Define and implement an enterprise segmentation and separation of duties strategy that segments access to assets using a combination of identity, network, application and subscription or account controls.

ASBv3-GS-2 · Define and implement enterprise segmentation/separation of duties strategy
CMMC 2.01 control

Divide security relevant duties among different individuals so no single person can both carry out and conceal a harmful action without collusion.

AC.L2-3.1.4 · Separation of Duties
FedRAMP High1 control

Identify and document duties requiring separation; define access authorizations to support.

AC-5 · Separation of Duties

Identify and document duties requiring separation; define access authorizations to support.

AC-5 · Separation of Duties

Questions people ask about separation of duties

What is Separation of Duties?
A security principle that divides critical tasks among multiple individuals to prevent fraud, error, and misuse by ensuring no single person controls all aspects of a process.
Why is Separation of Duties important for compliance?
Separation of Duties is a key concept in Information Security. Understanding separation of duties helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Separation of Duties?
Separation of Duties appears in the requirement text of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Australian Information Security Manual, Azure Security Benchmark, CMMC 2.0, FedRAMP High. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Separation of Duties?
Explore our compliance framework pages to see how separation of duties applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Separation of Duties applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.