TechKnowSurge
NIST 800-53 AC-5 NIST CSF PR.AA-05 ISC2 CISSP 1.3 CompTIA Security+ 1.2 ISC2 CISSP 5.4 CompTIA Security+ 4.6
VideoSecurityFree

Separation of Duties

Separation of duties is a security and compliance principle that divides critical business processes across multiple individuals to prevent fraud, embezzlement, and unauthorized access. By ensuring no single person controls an entire workflow from start to finish, organizations create built-in checks and balances that deter and detect misconduct.

Complete this video to capture a CTF flag worth 1 point.

About this video

Separation of duties is a foundational internal control principle designed to prevent fraud, embezzlement, and unauthorized access by ensuring that no single individual has unchecked control over an entire business process. In a typical procurement workflow, this means the person who selects a vendor and initiates a purchase order is not the same person who approves it, and neither of those individuals is the one who cuts the check. Each handoff between roles creates an opportunity for oversight, making it far more difficult for any one employee to divert company funds for personal use without detection. Organizations often balance security with operational efficiency by setting approval thresholds. Below a defined dollar amount, a manager may be authorized to approve purchases independently, while larger expenditures require sign-off from a higher authority and separate payment processing through accounting. Even in these streamlined scenarios, periodic audits serve as an additional layer of accountability to ensure policies are being followed and no improper spending has occurred. Separation of duties extends beyond financial controls into areas like data access management. When an employee needs access to a protected resource, a structured process requiring a formal request, approval from the resource owner, and separate implementation by an administrator ensures that access is always documented and authorized. This paper trail is critical for identifying policy violations, investigating anomalies, and demonstrating compliance during audits. Wherever sensitive actions or assets are involved, distributing responsibility across multiple roles remains one of the most effective safeguards against both intentional misconduct and accidental misuse.

What you'll learn

What's covered

Separation of Duties

Aligned to

NIST 800-53
AC-5 Separation of Duties
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
ISC2 CISSP
1.3 Evaluate and apply security governance principles
5.4 Implement and manage authorization mechanisms
CompTIA Security+
1.2 Summarize fundamental security concepts.
4.6 Given a scenario, implement and maintain identity and access management.

Key terms

Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Authorization
The process of determining what actions or resources an authenticated user is permitted to access.
Checks and Balances
A system of controls in which multiple individuals or steps are required to complete a process, reducing the risk of fraud or error by ensuring mutual oversight.

Topics

Separation Of Duties Access Control Identity And Access Management Security Compliance Privilege Management Risk Management

Transcript

I've heard a lot of stories about people within a company embezzling money. These were people that were trusted — they trusted a certain person and they ended up stealing from the company. This wouldn't happen if you had a policy that was around separation of duties.

A Purchasing Scenario

Let's do a little scenario here so we can understand what this looks like. First of all, let's say we work for a company that has a process, and the process is that we choose a vendor or a product. From there we create what's called a purchase order. A purchase order just gives the detail of who we're buying this from and what we're buying. Then it goes through some sort of approval process, that somebody of proper clearance can do this approval and approve of this purchase. Then we cut this check, and then that check goes to this vendor, and then we get the product sent to us.

So the scenario is that I work for a company, and I need some work done on my house. So I choose a contractor that can do that work. I create the purchase order, and let's say I also can do the approvals for that, so I sign it off and approve it, and I also write the check for this construction company that's going to come and work on my house. Now what I've just done is, the company that I work for, I've spent that money from that company on something that's personal to me, fixing up my home. This is a big problem — I'm stealing from the company in this scenario, and so we want to avoid this from happening.

Splitting the Steps

This is where separation of duties comes into place: that maybe I can't do all of the steps in here. Maybe I can choose the vendor and product, and then from there I will create the purchase order and prepare the purchase order, but then maybe it's got to go for approval and my boss has to approve this. They might take a look at it and say, why are you paying for this construction company, we don't have any project like this within our company, why is it that you're doing this? And so they would question why this purchase order is coming through there, and now that ability has ended just there. And then if I have somebody else that actually cuts the check, that would be another step along the process, that accounting has to cut the check for this. Now we've got a separation of duties, and there's this checks and balances that happens through here and protects against this type of embezzlement from happening.

Thresholds and Audits

A lot of times this can be a time intensive process. Maybe I need to purchase something right away and it doesn't make sense to get all of the approvals for whatever I need to purchase, and maybe I'm in charge of my own budget. For instance, when I was a director I was able to do some approvals, but there were limits to how much approvals that I could do — that is, I could approve anything that was below 10,000. It was a threshold for the company that they deemed that it was acceptable for me to sign things up to $110,000, and then above that they wanted to go through this checks and balances of an official approval from somebody else, somebody higher up that could give this approval. But even then we still had somebody cutting their own checks, and there's also audits that would happen to make sure that this was the right stuff that we went through. So even though it skipped the process to make it more streamlined in cases where it was under $10,000, there is still checks and balances to make sure that there couldn't be any stealing of money, couldn't be any embezzlement happening.

Separation of Duties for Data Access

This happens in other areas of the company as well. For instance, let's say somebody needs access to data. Separation of duties, what it would look like, is maybe that person submits a request, so now there's an official document, a request that's being made. Maybe the next step now is that the resource owner has to give approvals for that, so the resource owner is going to reply to that email and say, yes, I accept this — or maybe we need to reach out and get approval from that resource owner. And then it would then implement the changes and give access to that user.

Now there's this checks and balances, so if there are ever steps that were skipped — maybe somebody gained access to a resource, we've implemented something but there's no documented proof that this was needed or approved of — we can go back and we have a paper trail that we can see. Okay, what is happening here, why have we not followed our policies and procedures? And we can take a look to see if there's some sort of action that's happening.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →