PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AC-5 — Separation of Duties

Framework: NIST SP 800-53 Rev.5 AC-5 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Obtain the documented separation-of-duties matrix and confirm it identifies conflicting duties and the incompatible role/entitlement pairs (e.g., request vs. approve, developer vs. production deployer, vendor setup vs. payment release).
Test Attempt to assign or exercise two conflicting roles with a test account (e.g., initiate and approve the same transaction) and confirm the system prevents the combination or flags the conflict.
Examine For a sample of users in sensitive functions, confirm no single individual holds a conflicting combination of entitlements defined in the SoD matrix.
Interview Ask control/process owners to describe how SoD conflicts are detected, reviewed, and remediated, and how exceptions are handled.
Examine Confirm access authorizations are defined to actively support separation of duties, and that where full separation is not feasible, documented compensating controls (e.g., independent review, additional logging) are in place and approved.
Examine Confirm a periodic SoD conflict review or toxic-combination report is produced at the defined frequency, with evidence that identified conflicts were dispositioned.