Skip to content
compliancebase
ISO 27001A.5 — Segregation of duties

A.5.3

Segregation of duties

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Separate conflicting duties and areas of responsibility to reduce opportunities for unauthorized or unintentional modification or misuse.

Points of focus

  • Define scope and requirements for segregation of duties
  • Assign ownership and operating cadence
  • Integrate with risk treatment and SoA status
  • Retain dated records proving operation

Implementation notes

Encode segregation in PR approvals, deploy permissions, and finance/security splits. Document compensating controls when startups cannot fully separate roles. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.

Audit tip: Present the SoA line for A.5.3, the current procedure, and one recent dated operating sample with a named owner.

Evidence auditors typically request:

  • Approved information security policy set with version and owner
  • Statement of Applicability entry with applicability rationale
  • Management review minutes referencing the control theme
  • Ticket or register samples showing the process operated

Common gaps

  • SoA marks segregation of duties applicable without dated operating samples
  • Procedure exists but interviews describe a different tribal process
  • Owner unclear or last review older than the stated cadence

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.3This control
SOC 2CC8.1Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.
GDPRArticle 25Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.

Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.

Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above