Discuss the importance of the separation of duties for personnel. For example, with good separation of duties in place within the organization, one employee cannot abuse a policy–it takes at least two to do it. Good policy keeps everyone honest.

As part of your discussion, name examples of roles you would separate and why. For example, an administrator has full administrative server login access, and a network technician has limited administrative access but can view system login details. Payroll has access to employee financial records, but only payroll managers can approve raises. What are other examples?

If possible use examples from your organization, security experience, or a researched example. This way we can learn from real-life examples.


