Separation of duties
Separation of duties is a new technique in the information technology world. However, various concerns are being raised regarding the segregation of functions in the information technology security policy implementation process. Therefore, information technology organizations should put more emphasis on the separation of responsibilities, especially in security policy implementations. Two key objectives can be achieved through the separation of duties. The main one is that it helps in the prevention of conflict of interests or just the appearance of interests’ conflicts, abuse, fraud as well as errors. Whenever a conflict of interest is prevented, things like errors and fraud shall automatically be stopped at the same time. The second goal achieved by separation of duties is that it helps in detecting control failures, which include breaches of security, theft of information as well as circumvention of the security controls (Bollwein et al., 2017). Security controls are the measures that are taken into consideration to ensure those information systems are safeguarded from attacks.
The other advantage which is associated with the separation of duties is that it restricts the amount of influence as well as power, which is likely to be held just by a single individual. Additionally, it eliminates the conflict of responsibilities in the security policy implementation process. The person who is charged with the responsibility of designing as well as the implementation of security cannot be the same individual who is charged with the responsibility of testing security, conduction of security audits as well as monitoring and reporting on security issues (Layton, 2016). There would be an apparent conflict of responsibilities and, therefore, the urgency and importance of the separation of duties.