individuals requiring separation
A category of personnel—defined during an organization's access-control and duty-analysis process—whose assigned roles, privileges, or functions must not be held or exercised by the same person simultaneously, because doing so would create an unacceptable risk of fraud, error, or abuse of privilege. Identifying the duties of individuals requiring separation is the first step toward defining system access authorizations to support separation of duties. Separation of duties addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion. In practice, this includes dividing mission functions and support functions among different individuals or roles—for example, ensuring that personnel who administer access-control functions do not also administer audit functions. The phrase operates as a shorthand within separation-of-duties (SoD) control language for the set of role-holders whose job functions have been formally flagged as incompatible, and it drives downstream decisions about access provisioning and organizational design.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- individuals requiring separations
- possessive
- individuals requiring separation's
- pluralpossessive
- individuals requiring separations'