A.5.3
    Organizational Controls

    Segregation of duties

    Conflicting duties and areas of responsibility should be segregated.

    Purpose

    To reduce opportunities for unauthorized or unintentional modification or misuse of the organization's assets.

    Implementation Guidance

    Identify conflicting duties that should not be performed by the same person

    Implement technical controls to enforce segregation where possible

    Document exceptions and implement compensating controls

    Review user access rights regularly to ensure segregation is maintained

    Consider separation between development, testing, and production environments

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.3 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.3 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.3 Segregation of duties. Built for compliance professionals.

    Try ISMS Copilot free