home/glossary/individuals requiring separation

individuals requiring separation

nounid 163559·updated Aug 30, 2026
verified

A category of personnel—defined during an organization's access-control and duty-analysis process—whose assigned roles, privileges, or functions must not be held or exercised by the same person simultaneously, because doing so would create an unacceptable risk of fraud, error, or abuse of privilege. Identifying the duties of individuals requiring separation is the first step toward defining system access authorizations to support separation of duties. Separation of duties addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion. In practice, this includes dividing mission functions and support functions among different individuals or roles—for example, ensuring that personnel who administer access-control functions do not also administer audit functions. The phrase operates as a shorthand within separation-of-duties (SoD) control language for the set of role-holders whose job functions have been formally flagged as incompatible, and it drives downstream decisions about access provisioning and organizational design.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0185
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
Identify the duties of individuals requiring separation.the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

** A classification of personnel whose assigned roles, functions, or privileges must be distributed across distinct people or accounts so that no single person can exercise end-to-end control over a sensitive process. The distinguishing characteristic is that the conflict or risk arises from the *combination* of duties — initiating, approving, implementing, and auditing a transaction or access decision — not from any one duty in isolation; it is the overlap that creates the exposure. In compliance and access-control practice, identifying this population is the prerequisite step before system access authorizations can be designed: once the conflicting duties are named, the organization grants the corresponding privileges to separate individuals and enforces the split through role-based or attribute-based controls. **VERDICT:** COMPOSITIONAL The phrase is not a defined term of art with its own glossary entry; it is a precise but compositional description used as an assessment-objective label in NIST SP 800-171A Revision 3 (objective A.03.01.04.a), referring naturally to the set of persons whose job duties fall under the separation-of-duties principle (NIST SP 800-171 control 3.1.4

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.04.a

Classifications

Entity Type

Group100%manual reviewaxis_review_queue.v1

Sensitivity

Internal78%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
individuals requiring separations
possessive
individuals requiring separation's
pluralpossessive
individuals requiring separations'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A category of personnel—defined during an organization's access-control and duty-analysis process—whose assigned roles, privileges, or functions must not be held or exercised by the same person simultaneously, because doing so would create an unacceptable risk of fraud, error, or abuse of privilege. Identifying the duties of individuals requiring separation is the first step toward defining system access authorizations to support separation of duties. Separation of duties addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion. In practice, this includes dividing mission functions and support functions among different individuals or roles—for example, ensuring that personnel who administer access-control functions do not also administer audit functions. The phrase operates as a shorthand within separation-of-duties (SoD) control language for the set of role-holders whose job functions have been formally flagged as incompatible, and it drives downstream decisions about access provisioning and organizational design.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.