Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.1.4OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.1.4Separation of duties

3.1 Access Control · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

No one person should be able to both commit and conceal a damaging act — the classic pairs are requesting and approving access, making and reviewing changes, administering systems and auditing them. Small companies rarely have the headcount for full separation, which makes documented compensating review, not silence, the honest answer.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Identify the duty pairs that matter in your operation and write down who holds each side.
  • Where one person unavoidably holds both sides, add a second-person review or independent log review and record that it happens.
  • Keep security administration and audit review in different hands where at all possible — it is the pair assessors probe first.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • A documented separation-of-duties matrix, including the accepted exceptions
  • Records of the compensating reviews actually occurring for the exception cases
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated