isms.coach
← All controls

A.5.3 · Organizational

Segregation of duties

Why it matters

Prevents one person having enough access to cause or hide a serious incident alone.

How a self-led small team implements it

In a small team, focus on the highest-risk pairs (who deploys code vs. who approves it) rather than trying to segregate everything.

What auditors expect to see

Access review showing no single person holds conflicting critical permissions.

Track A.5.3 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls