Cybersecurity Glossary
Separation of Duties
Splitting a sensitive process so that no single person can complete it alone.
What Separation of Duties means
Separation of duties means the person who creates a payment is not the person who approves it, and the person who requests access is not the person who grants it. Where a small team makes full separation impossible, compensating controls such as after the fact review and alerting take its place.
Why Separation of Duties matters for small businesses and nonprofits
It is the control that stops both fraud and the most expensive mistakes. It is also the specific weakness that business email compromise exploits, since a single approver can be deceived once.
What to do about Separation of Duties
- Require a second approver for payments above a threshold you set
- Separate requesting access from granting it, even informally
- Where the team is too small, add review after the fact and alert on exceptions
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.