Separation of Duties
• Use of deliberately separate design teams for separate modules
Commercial Security Policies : Separation of Duties
L-4 P.66
Example: No single person is allowed to:
• Issue an order
• Receive the order
• Write the check for payment
A person may be allowed to do all of the above
Separation of duties says no one person can do all processes on the same transaction
• May require that different persons do each of the possible processes