Skip to content

Understanding ISO 27001:2022 Annex A Control 5.3 – The Importance of Segregation of Duties

The purpose of ISO 27001:2022 Annex A 5.3 – segregation of duties in the form of functional separation is to establish a management framework that will be used to initiate and control the implementation and operation of information security within a company.

According to ISO 27001:2022 Annex A control 5.3, previously known as 6.1.2 in ISO 27001:2013, conflicting duties and conflicting areas of responsibility are separated.

An organisation should consider and implement appropriate segregation of duties as part of the risk evaluation and treatment process. While smaller organisations may have difficulty with this, the principle should be applied as much as possible and proper governance and controls put in place for information assets with a higher risk/higher value.

To reduce the likelihood of unauthorised or unintentional modification or misuse of the organisation’s assets, conflicting duties and areas of responsibility need to be segregated.

Conflicting Duties and Areas of Responsibilities Explained

Almost every organisation has a set of policies and procedures that govern its internal operations. These policies and procedures are supposed to be documented, but this is not always the case.

There exists a danger that employees will become confused about their areas of responsibility if the P&Ps are not transparent or well-communicated. This becomes even more problematic when employees have overlapping or conflicting areas of responsibility.

Occasionally, conflicts can arise when employees have responsibilities related to a particular task that are similar or differing. As a result, employees may do the same thing twice or perform different functions that cancel out the efforts of others. This wastes corporate resources and reduces productivity, adversely affecting the company’s bottom line and morale.

This problem can be avoided by ensuring that your organisation does not experience conflicting areas of responsibility and knowing why and what you can do to prevent them. For the most part, this means separating duties so that different people handle different organisational roles.




ISMS.online gives you an 81% Headstart from the moment you log on

ISO 27001 made easy

We’ve done the hard work for you, giving you an 81% Headstart from the moment you log on. All you have to do is fill in the blanks.




What Is The Purpose of ISO 27001:2022 Annex A 5.3?

In ISO 27001, Control 5.3 Segregation of Duties aims to separate conflicting duties. This reduces the risk of fraud and error and bypasses information security controls.

Annex A Control 5.3 Explained

In accordance with ISO 27001, Annex A Control 5.3 describes the implementation guidelines for segregating organisational tasks and duties.

By delegating sub-tasks to different individuals, this principle creates a system of checks and balances that can reduce the likelihood of errors and fraud occurring.

The control is designed to prevent a single person from being able to commit, conceal, and justify improper actions, thereby reducing the risk of fraud and error. It also prevents a single person from overriding information security controls.

In cases where one employee has all the rights required for the task, fraud and errors are more likely to occur. This is because one person can perform everything without any checks and balances. There is, however, a reduced risk of significant harm or financial loss from an employee when no single person has all the access rights required for a particular task.

What’s Involved and Requirements of Annex A 5.3

In the absence of proper separation of duties and responsibilities, fraud, misuse, unauthorised access, and other security issues may arise.

Additionally, segregation of duties is required to mitigate the risks of collaboration between individuals. These risks are increased when insufficient controls prevent or detect collusion.

As part of ISO 27001:2022, the organisation should determine which duties and responsibilities need to be separated and implement actionable separation controls.

Whenever such controls are not possible, particularly for small organisations with a limited number of employees, activity monitoring, audit trails, and management supervision can be used. Using automated tools, larger organisations can identify and segregate roles to prevent conflicting roles from being assigned.




climbing

Embed, expand and scale your compliance, without the mess. IO gives you the resilience and confidence to grow securely.




What Are the Changes and Differences From ISO 27001:2013?

ISO 27001:2022’s Annex A control 5.3 Segregation of Duties is a revised version of ISO 27001:2013’s Annex A control 6.1.2 Segregation of Duties.

Annex A 5.3 ISO 27001:2022 and Annex A 6.1.2 ISO 27001:2013 describe the same basic characteristics of the control “Segregation of duties”. However, the most recent version defines a number of activities that require segregation during implementation.

Among these activities are:

a) initiating, approving and executing a change;

b) requesting, approving and implementing access rights;

c) designing, implementing and reviewing code;

d) developing software and administering production systems;

e) using and administering applications;

f) using applications and administering databases;

g) designing, auditing and assuring information security controls.

Table of All ISO 27001:2022 Annex A Controls

In the table below you’ll find more information on each individual ISO 27001:2022 Annex A Control.

ISO 27001:2022 Organisational Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Organisational Controls Annex A 5.1 Annex A 5.1.1
Annex A 5.1.2
Policies for Information Security
Organisational Controls Annex A 5.2 Annex A 6.1.1 Information Security Roles and Responsibilities
Organisational Controls Annex A 5.3 Annex A 6.1.2 Segregation of Duties
Organisational Controls Annex A 5.4 Annex A 7.2.1 Management Responsibilities
Organisational Controls Annex A 5.5 Annex A 6.1.3 Contact With Authorities
Organisational Controls Annex A 5.6 Annex A 6.1.4 Contact With Special Interest Groups
Organisational Controls Annex A 5.7 NEW Threat Intelligence
Organisational Controls Annex A 5.8 Annex A 6.1.5
Annex A 14.1.1
Information Security in Project Management
Organisational Controls Annex A 5.9 Annex A 8.1.1
Annex A 8.1.2
Inventory of Information and Other Associated Assets
Organisational Controls Annex A 5.10 Annex A 8.1.3
Annex A 8.2.3
Acceptable Use of Information and Other Associated Assets
Organisational Controls Annex A 5.11 Annex A 8.1.4 Return of Assets
Organisational Controls Annex A 5.12 Annex A 8.2.1 Classification of Information
Organisational Controls Annex A 5.13 Annex A 8.2.2 Labelling of Information
Organisational Controls Annex A 5.14 Annex A 13.2.1
Annex A 13.2.2
Annex A 13.2.3
Information Transfer
Organisational Controls Annex A 5.15 Annex A 9.1.1
Annex A 9.1.2
Access Control
Organisational Controls Annex A 5.16 Annex A 9.2.1 Identity Management
Organisational Controls Annex A 5.17 Annex A 9.2.4
Annex A 9.3.1
Annex A 9.4.3
Authentication Information
Organisational Controls Annex A 5.18 Annex A 9.2.2
Annex A 9.2.5
Annex A 9.2.6
Access Rights
Organisational Controls Annex A 5.19 Annex A 15.1.1 Information Security in Supplier Relationships
Organisational Controls Annex A 5.20 Annex A 15.1.2 Addressing Information Security Within Supplier Agreements
Organisational Controls Annex A 5.21 Annex A 15.1.3 Managing Information Security in the ICT Supply Chain
Organisational Controls Annex A 5.22 Annex A 15.2.1
Annex A 15.2.2
Monitoring, Review and Change Management of Supplier Services
Organisational Controls Annex A 5.23 NEW Information Security for Use of Cloud Services
Organisational Controls Annex A 5.24 Annex A 16.1.1 Information Security Incident Management Planning and Preparation
Organisational Controls Annex A 5.25 Annex A 16.1.4 Assessment and Decision on Information Security Events
Organisational Controls Annex A 5.26 Annex A 16.1.5 Response to Information Security Incidents
Organisational Controls Annex A 5.27 Annex A 16.1.6 Learning From Information Security Incidents
Organisational Controls Annex A 5.28 Annex A 16.1.7 Collection of Evidence
Organisational Controls Annex A 5.29 Annex A 17.1.1
Annex A 17.1.2
Annex A 17.1.3
Information Security During Disruption
Organisational Controls Annex A 5.30 NEW ICT Readiness for Business Continuity
Organisational Controls Annex A 5.31 Annex A 18.1.1
Annex A 18.1.5
Legal, Statutory, Regulatory and Contractual Requirements
Organisational Controls Annex A 5.32 Annex A 18.1.2 Intellectual Property Rights
Organisational Controls Annex A 5.33 Annex A 18.1.3 Protection of Records
Organisational Controls Annex A 5.34 Annex A 18.1.4 Privacy and Protection of PII
Organisational Controls Annex A 5.35 Annex A 18.2.1 Independent Review of Information Security
Organisational Controls Annex A 5.36 Annex A 18.2.2
Annex A 18.2.3
Compliance With Policies, Rules and Standards for Information Security
Organisational Controls Annex A 5.37 Annex A 12.1.1 Documented Operating Procedures
ISO 27001:2022 People Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
People Controls Annex A 6.1 Annex A 7.1.1 Screening
People Controls Annex A 6.2 Annex A 7.1.2 Terms and Conditions of Employment
People Controls Annex A 6.3 Annex A 7.2.2 Information Security Awareness, Education and Training
People Controls Annex A 6.4 Annex A 7.2.3 Disciplinary Process
People Controls Annex A 6.5 Annex A 7.3.1 Responsibilities After Termination or Change of Employment
People Controls Annex A 6.6 Annex A 13.2.4 Confidentiality or Non-Disclosure Agreements
People Controls Annex A 6.7 Annex A 6.2.2 Remote Working
People Controls Annex A 6.8 Annex A 16.1.2
Annex A 16.1.3
Information Security Event Reporting
ISO 27001:2022 Physical Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Physical Controls Annex A 7.1 Annex A 11.1.1 Physical Security Perimeters
Physical Controls Annex A 7.2 Annex A 11.1.2
Annex A 11.1.6
Physical Entry
Physical Controls Annex A 7.3 Annex A 11.1.3 Securing Offices, Rooms and Facilities
Physical Controls Annex A 7.4 NEW Physical Security Monitoring
Physical Controls Annex A 7.5 Annex A 11.1.4 Protecting Against Physical and Environmental Threats
Physical Controls Annex A 7.6 Annex A 11.1.5 Working In Secure Areas
Physical Controls Annex A 7.7 Annex A 11.2.9 Clear Desk and Clear Screen
Physical Controls Annex A 7.8 Annex A 11.2.1 Equipment Siting and Protection
Physical Controls Annex A 7.9 Annex A 11.2.6 Security of Assets Off-Premises
Physical Controls Annex A 7.10 Annex A 8.3.1
Annex A 8.3.2
Annex A 8.3.3
Annex A 11.2.5
Storage Media
Physical Controls Annex A 7.11 Annex A 11.2.2 Supporting Utilities
Physical Controls Annex A 7.12 Annex A 11.2.3 Cabling Security
Physical Controls Annex A 7.13 Annex A 11.2.4 Equipment Maintenance
Physical Controls Annex A 7.14 Annex A 11.2.7 Secure Disposal or Re-Use of Equipment
ISO 27001:2022 Technological Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Technological Controls Annex A 8.1 Annex A 6.2.1
Annex A 11.2.8
User Endpoint Devices
Technological Controls Annex A 8.2 Annex A 9.2.3 Privileged Access Rights
Technological Controls Annex A 8.3 Annex A 9.4.1 Information Access Restriction
Technological Controls Annex A 8.4 Annex A 9.4.5 Access to Source Code
Technological Controls Annex A 8.5 Annex A 9.4.2 Secure Authentication
Technological Controls Annex A 8.6 Annex A 12.1.3 Capacity Management
Technological Controls Annex A 8.7 Annex A 12.2.1 Protection Against Malware
Technological Controls Annex A 8.8 Annex A 12.6.1
Annex A 18.2.3
Management of Technical Vulnerabilities
Technological Controls Annex A 8.9 NEW Configuration Management
Technological Controls Annex A 8.10 NEW Information Deletion
Technological Controls Annex A 8.11 NEW Data Masking
Technological Controls Annex A 8.12 NEW Data Leakage Prevention
Technological Controls Annex A 8.13 Annex A 12.3.1 Information Backup
Technological Controls Annex A 8.14 Annex A 17.2.1 Redundancy of Information Processing Facilities
Technological Controls Annex A 8.15 Annex A 12.4.1
Annex A 12.4.2
Annex A 12.4.3
Logging
Technological Controls Annex A 8.16 NEW Monitoring Activities
Technological Controls Annex A 8.17 Annex A 12.4.4 Clock Synchronization
Technological Controls Annex A 8.18 Annex A 9.4.4 Use of Privileged Utility ProgramsAccess Rights
Technological Controls Annex A 8.19 Annex A 12.5.1
Annex A 12.6.2
Installation of Software on Operational Systems
Technological Controls Annex A 8.20 Annex A 13.1.1 Networks Security
Technological Controls Annex A 8.21 Annex A 13.1.2 Security of Network Services
Technological Controls Annex A 8.22 Annex A 13.1.3 Segregation of Networks
Technological Controls Annex A 8.23 NEW Web filtering
Technological Controls Annex A 8.24 Annex A 10.1.1
Annex A 10.1.2
Use of Cryptography
Technological Controls Annex A 8.25 Annex A 14.2.1 Secure Development Life Cycle
Technological Controls Annex A 8.26 Annex A 14.1.2
Annex A 14.1.3
Application Security Requirements
Technological Controls Annex A 8.27 Annex A 14.2.5 Secure System Architecture and Engineering PrinciplesLearning From Information Security Incidents
Technological Controls Annex A 8.28 NEW Secure Coding
Technological Controls Annex A 8.29 Annex A 14.2.8
Annex A 14.2.9
Security Testing in Development and Acceptance
Technological Controls Annex A 8.30 Annex A 14.2.7 Outsourced Development
Technological Controls Annex A 8.31 Annex A 12.1.4
Annex A 14.2.6
Separation of Development, Test and Production Environments
Technological Controls Annex A 8.32 Annex A 12.1.2
Annex A 14.2.2
Annex A 14.2.3
Annex A 14.2.4
Change Management
Technological Controls Annex A 8.33 Annex A 14.3.1 Test Information
Technological Controls Annex A 8.34 Annex A 12.7.1 Protection of Information Systems During Audit Testing

Who Has Ownership of Annex A 5.3?

Several individuals are responsible for the segregation of duties in ISO 27001, beginning with a senior management team member. This individual is responsible for ensuring that the initial risk assessment has taken place.

As a result, other groups of qualified employees should be assigned processes that apply to different parts of the organisation. Order to prevent rogue employees from undermining company security is usually done by assigning tasks to other work units and departmentalising IT-related operations and maintenance activities.

The separation of duties cannot be established correctly without an effective risk management strategy, an appropriate control environment, and an appropriate IT audit programme.




[case_study_slider ids=”88859,101932,92016″ autoplay=”true” autoplay_speed=”5000″]


Use ISMS.online to Your Advantage

ISO 27001:2022 only requires you to update your ISMS processes to reflect the improved Annex A controls, and if your team can’t manage this, ISMS.online can.

In addition to DPIA and other related personal data assessments, like LIAs, ISMS.online provides simple, practical frameworks and templates for information security.

With ISMS.online, you can document information security management system procedures and checklists to ensure compliance with ISO 27001, automating the implementation process.

ISMS.online lets you:

  • Create an ISMS that is compatible with ISO 27001 standards.
  • Perform tasks and submit proof indicating they have met the standard’s requirements.
  • Allocate tasks and track progress toward compliance with the law.
  • Get access to a specialised team of advisors to assist you throughout your path towards compliance.

By using our cloud-based platform, you can centrally manage checklists, interact with colleagues, and use a comprehensive set of tools to help your organisation create and maintain an ISMS.

Get in touch today to book a demo.


Toby Cane

Partner Customer Success Manager

Toby Cane is the Senior Partner Success Manager for ISMS.online. He has worked for the company for close to 4 years and has performed a range of roles, including hosting their webinars. Prior to working in SaaS, Toby was a Secondary School teacher.

ISO 27001:2022 Annex A Controls

Organisational Controls