AM-12 Access Management
Segregation of Duties (SoD)
Conflicting duties are separated.
- Domain
- Access Management
- Control type
- Preventive
- Automated / manual
- Hybrid
- Frequency
- Continuous
- Framework reference
- COBIT DSS05; MAS TRM – Access
What good looks like
A SoD matrix defines incompatible duties; roles enforce it with compensating controls where needed.
Risk if it fails
Fraud, error concealment, unauthorised transactions.
How Tess tests it
4 tests — each concludes only on cited evidence.
SoD matrix defines incompatible duties
Design- Procedure
- Inspect the SoD matrix.
- Expected
- Documented and approved.
- Sample
- 1 (design inspection)
- Evidence
- SoD matrix, role mapping, conflict analysis, comp-control evidence.
Roles designed to avoid conflicts
Design- Procedure
- Inspect role design.
- Expected
- Roles do not combine conflicting functions.
- Sample
- 1 (design inspection)
- Evidence
- SoD matrix, role mapping, conflict analysis, comp-control evidence.
No unmitigated SoD conflicts in entitlements
Operating- Procedure
- Run/inspect a conflict analysis over entitlements.
- Expected
- Zero unmitigated conflicts.
- Sample
- 25 (or full config inspection)
- Evidence
- SoD matrix, role mapping, conflict analysis, comp-control evidence.
Compensating controls operate where conflicts exist
Operating- Procedure
- Inspect compensating-control evidence.
- Expected
- Documented and operating effectively.
- Sample
- 25 (or full config inspection)
- Evidence
- SoD matrix, role mapping, conflict analysis, comp-control evidence.
Evidence Tess looks for
SoD matrix, role mapping, conflict analysis, comp-control evidence.
More in Access Management
Want Tess to test AM-12 against your evidence?
Book a demo