Segregation of Duties (SoD)
Segregation of Duties (SoD) is a control principle according to which critical tasks and the permissions required for them are distributed across several persons or roles in such a way that no one can control a sensitive process alone from start to finish. The aim is to prevent, or at least detect, errors, misuse and fraud.
Typical conflicting combinations are creating and releasing payments, creating and approving purchase orders, or administering and auditing a system. In identity and governance systems, incompatible roles and permissions are stored in an SoD matrix. During access requests or review campaigns, the system detects violations automatically and blocks the assignment or requires a documented exception with a compensating control. A related form that refers to individual transactions is the four-eyes principle.
ISO/IEC 27001 lists segregation of duties as a control of its own (Annex A 5.3); in regulated industries it is part of internal control systems, for example under the German Minimum Requirements for Risk Management (MaRisk) for banks. Technically, SoD requires clean role models as provided by Role-Based Access Control (RBAC). As a governance principle, segregation of duties is a building block of Identity Security.