Term · 4. Roles, Policies & Access Rights
SoD Conflict
Definition
Combination of access rights that violates Separation of Duties — same identity has permissions that should never coexist (e.g., create vendor + approve payment to vendor). Detected by SoD rules in IGA platforms. Common in long-tenured employees with accumulated entitlements. Required to detect and remediate for SOX, PCI DSS, and bank regulator compliance.
- Application
- IGA SoD engines maintain rule matrix (which entitlement pairs conflict). Detected violations require either remediation (remove one entitlement) or compensating control (e.g., increased monitoring with management sign-off). Reported in compliance dashboards.
- Standards & regulations
-
- NIST SP 800-162:2014 «A conflict of duty is the term used when a user may have combined permissions and a set of such combined permissions is issued to identify access that is in conflict for enforcement of separation of d»
- OASIS XACML v3.0 Separation of Duties Version 1.0 (Committee Specification 01, 30 January 2024) «Separation of duties (SoD) is a security principle applied to minimize fraud, misuse of information, conflicts of interest and user errors by requiring that a task can only be completed by the active »
- Sources
-
- NIST SP 800-162 ABAC (csrc.nist.gov) primary source
Related terms
-
Access Certification (AC)
Periodic review process where designated reviewers (managers, role owners, application owners) attest that users still n …
-
Access Control (AC)
Mechanism that determines whether a principal is permitted to perform a specific action on a specific resource. Includes …
-
Audit
Independent examination of identity controls, processes, and records to verify compliance with policy and regulatory req …
-
Audit Trail
Chronological record of identity events — authentication, authorization decisions, provisioning actions, configuration c …
-
Cloud Data Access Governance
Discovery, classification, and access control for sensitive data across cloud data stores (S3, Snowflake, BigQuery, Data …
-
Compliance
Adherence to applicable laws, regulations, standards, and internal policies governing identity and access management. Co …