Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO4.11 - Segregation of Duties

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO4.11 - Segregation of Duties is contained within Process Popup Define the IT Processes, Organisation and Relationships

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
111 Members
0 Online
5416 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer


Segregation of Duties

Implement a division of roles and responsibilities that reduces the possibility for a single individual to compromise a critical process. Make sure that personnel are performing only authorised duties relevant to their respective jobs and positions.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Effective and efficient functioning of business-critical systems and processes
  • Proper protection of information assets
  • Reduced risk of financial loss and reputational damage
  Risk Drivers
  • Inappropriate subversion of critical processes
  • Financial loss and reputational damage
  • Malicious or unintentional damages
  • Non-compliance with external requirements for segregation of materially significant systems and business processes

View Control Practices  help

Hide Control Practices  help

  1. Establish standards that enforce appropriate segregation of duties. Periodically review and update the standards.
  2. Identify and document conflicting functions, such as the ability to initiate, authorise, execute and verify transactions. Ensure that segregation of duties is enforced physically and logically where appropriate.
  3. Ensure that procedures address the maintenance of appropriate segregation of duties and responsibilities during periods when regular personnel are unavailable (e.g., vacations, illness or leaves of absence).
  4. Review the impact on segregation of duties and reassign responsibilities where necessary when job roles and responsibilities are created or updated as a result of changing business needs or reorganisation.
  5. Design and implement compensating controls (e.g., regular review of individuals’ activities by senior IT management) where the size or nature of the IT function precludes full segregation of duties.

Discussions: 5 total

Must be a Topic member to contribute
Hi All,having some difficulty giving some guidance to an IT Manager in the way of SOD best-practices using AD groups. There's lots of discussion out there about conflicting roles, but it's usually a review of financial (vendor creator vs. vendor payer) or...
Jeff Murfin | 12/28/2017 12:41:34 PM | COMMENTS(0)
Does anyone have any references or experience with SOD as it applies to Healthcare Revenue Cycle SOD?  I'm looking to start an Revenue Cycle SOD effort with a Healthcare client and would like to find an existing starting point if one already exists.
Yuriy022 | 11/14/2016 12:32:44 PM | COMMENTS(0)
Hello: Does anyone have suggestions or ideas on the best way to perform Segregation of Duties in NetSuite? Thank you. Regards, Karen Andersen
Karen953 | 7/22/2016 8:15:40 AM | COMMENTS(0)
Dear all, I would like to get a piece of advice about strange suggestion that I received. I was invited to a meeting to discuss on the skippable scope for project audit under PMO(Project management office)  functions.You may pop up the question mark when ...
Kyeong Hee341 | 10/19/2015 1:46:08 PM | COMMENTS(1)
Hi! I read an article of the Journal (What Every IT Auditor Should Know About Proper Segregation of Incompatible IT Activities). AT the bottom of the article there's a figure (Sample Organization Chart Demonstrating Effectual Segregation of IT Duties). ...
Lia471 | 11/15/2012 1:16:49 PM | COMMENTS(0)

Documents & Publications: 173 total

Must be a Topic member to contribute
View All »
Downloads
Posted by FarmService 1416 days ago
Downloads
Posted by FarmService 2501 days ago
Books
Posted by ISACA 37 days ago
Books
Posted by ISACA 719 days ago

Events & Online Learning: 10 total

Journal Articles: 218 total

Volume 3, 2107
by Jayakumar Sundaram, CISA, ISO 27001 LA
The SoA is a continuously updated and controlled document that provides an overview of information security implementation.
Volume 1, 2018
by Aditya K. Sood, Ph.D., and Rehan Jalil
With the robust requirements listed by upcoming regulations, such as GDPR, the importance of a cloud app security solution cannot be ignored.
Volume 1, 2018
by Kiran Maraju, CEH, CISSP
The use of artificial intelligence (AI) in cyber security will help organizations enhance existing application security capabilities.
Volume 1, 2018
by Ofir Eitan, CISM and Aviv Srour
Cyberincident response is no different than any other type of warfare. It requires strategy, tactics, planning, technology, psychology and intelligence.
Volume 6, 2017
by Daniel Gnana, CISA, ISO/IEC 27001:2013 LA, PRINCE2
The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC)’s ISO/IEC 27001:2013 standard has defined the requirements for an information security management system (ISMS).
Volume 6, 2017
by Guy Pearce
The modern GRC landscape has a significant impact on how an enterprise-scale big data project would be undertaken today.

Wikis: 2 total

Blog Posts: 196 total

21 Feb 2018
We are happy to announce that  on Feb//2018  the ISACA awareness session  was held in Baghdad.This the first time to speak about ISACA Value in Iraq.Professional from government and private sector were excited to hear about ISACA value and they started to...
Posted By : Ali099 | 1 comments
Ransomware is a form of malware and is engineered to infect your personal computer and restrict access in some way, while demanding payment or ransom  to remove the restriction. First identified in 1989  under the name of PC Cyborg, today there are over 2...
Posted By : Robert658 | 2 comments
Have you experienced ransomware attack so far and, if yes, what did you do to resolve? I set up Twitter poll here: https://twitter.com/DPleskonjic/status/953608717399941120 It lasts for seven days. Thank you for taking part in the poll.
Posted By : Dragan Pleskonjic | 2 comments
There are some math models for business that MBAs are taught. Just like assembling burgers for fast food or call wait queue management in a call center, vulnerability patching is a time based business opportunity. Leadership can be expected to use this ...
Posted By : Don Turnblade | 1 comments
My personal thoughts after listening to C-level executives at the CxO Roundtable Series sponsored by Intel, IBM, HyTrust & ReedSmith. For an invite, please reach out to me. Data Protection under the GDPR For past few months, I’ve been helping to org...
Posted By : Thomas152 | 1 comments
I predict that on 1 July 2018, I will be calmly eating a barbecue sandwich, talking with friends and possibly, I will burn a copy of the RFC2246: TLS version 1.0 standard for entertainment value.  Those will less effective Vendor, Network, Systems, Applic...
Posted By : Don Turnblade | 0 comments