Segregation of duties is an essential principle in security architecture aimed at minimizing the risk of errors and fraud. It enables organizations to distribute responsibilities and thus ensure the integrity of processes.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Segregation of Duties separates critical tasks and privileges across multiple people or roles.
The principle emerged in internal control and governance to limit error, misuse, and unchecked individual decisions. ISO/IEC 27001 places organizational security measures within an information security management system.
One person should not control every critical step such as requesting, approving, and executing an action. Role separation, two-person control, and independent review reduce conflicts; exceptions need documented compensating measures.
Critical power and responsibility are distributed across independent roles.
Separate requests, approvals, and execution make unnoticed error or manipulation harder.
Separation must fit risk and operations, with traceable compensating measures for exceptions.
SoD supports robust access design, approvals, and controls in security-sensitive processes.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.