Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
5 to work through
-
intermediate
An audit finds 40 engineers with permanent production database read access. The team says they need it for support. Resolve it.
2 min answer -
advanced
A financial platform must demonstrate segregation of duties. What is the concrete test, and where does it usually fail?
2 min answer -
advanced
A team owns its service end to end, including deploying to production. How is segregation of duties satisfied?
1 min answer -
advanced
On 27 July 2012 a Knight Capital technician deployed new order-routing code to seven of eight production servers. The eighth kept older code that a repurposed flag then activated on 1 August, and the firm booked a pre-tax loss of about $440 million in roughly 45 minutes. The SEC noted it had no written deployment procedures and no peer review of deployments. Which control would have prevented it, and which would only have reduced the damage?
2 min answer -
advanced
On 5 April 2022 an Atlassian maintenance script deleted 883 customer sites belonging to 775 customers in about 23 minutes. Restoration ran until 18 April, up to 14 days for some customers, although no customer lost more than about five minutes of data. What failed, and which design decisions made that gap between deleting and restoring possible?
2 min answer
5 terms in this topic
Irreversible Operation Guard
The set of design choices that make a destructive action recoverable by default - a delay before permanence, a type check on the target, and a second…
practicePartial Deployment Verification
Machine confirmation that every target in a fleet is running the intended artefact, independently checked, so that an incomplete rollout cannot prese…
conceptSegregation of Duties
Ensuring no single individual can both initiate and approve a sensitive action, so that fraud or error requires collusion.
practiceSingle-Credential Test
Asking whether any single credential - including a database administrator, a root account or a deployment pipeline - can both initiate and approve a …
conceptToxic Combination
A pair of permissions that is acceptable individually and dangerous together, which is what a segregation-of-duties model exists to identify.
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.