AM-12 Access Management

Segregation of Duties (SoD)

Conflicting duties are separated.

Domain
Access Management
Control type
Preventive
Automated / manual
Hybrid
Frequency
Continuous
Framework reference
COBIT DSS05; MAS TRM – Access

What good looks like

A SoD matrix defines incompatible duties; roles enforce it with compensating controls where needed.

Risk if it fails

Fraud, error concealment, unauthorised transactions.

How Tess tests it

4 tests — each concludes only on cited evidence.

SoD matrix defines incompatible duties

Design
Procedure
Inspect the SoD matrix.
Expected
Documented and approved.
Sample
1 (design inspection)
Evidence
SoD matrix, role mapping, conflict analysis, comp-control evidence.

Roles designed to avoid conflicts

Design
Procedure
Inspect role design.
Expected
Roles do not combine conflicting functions.
Sample
1 (design inspection)
Evidence
SoD matrix, role mapping, conflict analysis, comp-control evidence.

No unmitigated SoD conflicts in entitlements

Operating
Procedure
Run/inspect a conflict analysis over entitlements.
Expected
Zero unmitigated conflicts.
Sample
25 (or full config inspection)
Evidence
SoD matrix, role mapping, conflict analysis, comp-control evidence.

Compensating controls operate where conflicts exist

Operating
Procedure
Inspect compensating-control evidence.
Expected
Documented and operating effectively.
Sample
25 (or full config inspection)
Evidence
SoD matrix, role mapping, conflict analysis, comp-control evidence.

Evidence Tess looks for

SoD matrix, role mapping, conflict analysis, comp-control evidence.

More in Access Management

Want Tess to test AM-12 against your evidence?

Book a demo