Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO4.11 - Segregation of Duties

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO4.11 - Segregation of Duties is contained within Process Popup Define the IT Processes, Organisation and Relationships

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
20 Members
0 Online
2777 Visits

 Recent Discussions

About DBA. Posted by Lia471.

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Segregation of Duties

Implement a division of roles and responsibilities that reduces the possibility for a single individual to compromise a critical process. Make sure that personnel are performing only authorised duties relevant to their respective jobs and positions.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Effective and efficient functioning of business-critical systems and processes
  • Proper protection of information assets
  • Reduced risk of financial loss and reputational damage
  Risk Drivers
  • Inappropriate subversion of critical processes
  • Financial loss and reputational damage
  • Malicious or unintentional damages
  • Non-compliance with external requirements for segregation of materially significant systems and business processes

View Control Practices  help

Hide Control Practices  help

  1. Establish standards that enforce appropriate segregation of duties. Periodically review and update the standards.
  2. Identify and document conflicting functions, such as the ability to initiate, authorise, execute and verify transactions. Ensure that segregation of duties is enforced physically and logically where appropriate.
  3. Ensure that procedures address the maintenance of appropriate segregation of duties and responsibilities during periods when regular personnel are unavailable (e.g., vacations, illness or leaves of absence).
  4. Review the impact on segregation of duties and reassign responsibilities where necessary when job roles and responsibilities are created or updated as a result of changing business needs or reorganisation.
  5. Design and implement compensating controls (e.g., regular review of individuals’ activities by senior IT management) where the size or nature of the IT function precludes full segregation of duties.

Discussions: 1 total

Must be a Topic member to contribute
Hi! I read an article of the Journal (What Every IT Auditor Should Know About Proper Segregation of Incompatible IT Activities). AT the bottom of the article there's a figure (Sample Organization Chart Demonstrating Effectual Segregation of IT Duties). ...
Lia471 | 11/15/2012 1:16:49 PM | COMMENTS(0)

Documents & Publications: 237 total

Must be a Topic member to contribute
View All »
Downloads
Posted by ISACA 711 days ago
Downloads
Posted by ISACA 764 days ago
Downloads
Experienced business and IT professionals know that optimizing their use of big data as a resource will deliver real business value to the enterprise stakeholders.
Posted by ISACA 67 days ago

Events & Online Learning: 7 total

29 Oct 2012
ISACA International Event
New York, NY, USA
10 Jun 2013
ISACA International Event
Berlin, Germany
Early bird deadline has been extended: save over US $350 when you register by 1 May. Learn from industry-leading IT experts at Insights 2013. This is a unique opportunity to discover revolutionary new ideas at the world’s premier business event.
16 Sep 2013
ISACA International Event
London, England
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2013 in Berlin—the leading European conference for IT audit, assurance, security and risk professionals. Save over US $200 when you register by 22 July!
30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!
14 Oct 2013
ISACA International Event
Boston, MA, USA

Journal Articles: 500 total

Volume 3, 2013
by Santhosh Patil
Health care spending is a key component of any industrialized nation’s economy.
Volume 3, 2013
by Walter Smiechewicz, CPA
Walter Smiechewicz is a managing director in PricewaterhouseCoopers (PwC)’s Los Angeles, California, USA, office.
Volume 3, 2013
by Vasant Raval, CISA, DBA
Cheating, of course, is a type of indiscretion and suggests the degradation of moral fabric as much as other indiscretions such as financial fraud.
Volume 3, 2013
by Dan Bogdanov, Ph.D., and Aivo Kalu, Ph.D., CISA
A cloud is a remote-access platform; thus, technical controls that remotely enforce a particular security policy are especially efficient.
Volume 2, 2013
by Nurudeen Odeshina, CISA, CISM, CRISC, ISO 27001 LI, ITSM
As is often said, “information security is not a destination, it is a journey,” and for the organization it means continuous improvement.
Volume 2, 2013
by Samuel Pierre-Louis, CISSP-ISMP, René Sanchez, CISM, CBCP, MBCI, and Molly Shek, CISM, CGEIT, CRISC, PMP, RHIA
How does an organization that is faced with numerous federal and state compliance requirements meet the challenge?

Wikis: 2 total

Blog Posts: 182 total

A recent publication in a local newspaper, indicated that an employee was charged with fraud with regards to claims of insurance payments that were lodged with the company were paid out to people who were not entitled to receive such payments. What po...
Posted By : Paulina.PNI | 1 comments
მოგესალმებით და ამ პოსტში შევეცდები სტანდარტებზე გესაუბროთ. სტანდარტები... მაშ ასე, ინფორმაციული უსაფრთხოების სტანდარტებზე სანამ გადავალთ, გლობალურად არის 2-3 სტანდარტების ტერიტორიები.
Posted By : David190 | 0 comments
Check out the video interview with Jack Danahy on the 2013 Global Reputational Risk and IT Study and please leaving your ratings and feedback on the video landing page. https://ibm.biz/Bdxb3k
Posted By : Calvin Powers | 0 comments
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
Hoy les comentaré de OpenSSL que es una herramienta muy flexible, que proporciona muchos módulos cada uno de los cuales realiza una tarea específica. Cada módulo no es un ejecutable separado sin embargo se selecciona con el primer parámetro del ejecut...
Posted By : ArthurHuamani | 0 comments