Skip to main content

← Back to glossary

Term · 4. Roles, Policies & Access Rights

SoD Conflict

IDM/IGA Domain

Definition

Combination of access rights that violates Separation of Duties — same identity has permissions that should never coexist (e.g., create vendor + approve payment to vendor). Detected by SoD rules in IGA platforms. Common in long-tenured employees with accumulated entitlements. Required to detect and remediate for SOX, PCI DSS, and bank regulator compliance.

Application
IGA SoD engines maintain rule matrix (which entitlement pairs conflict). Detected violations require either remediation (remove one entitlement) or compensating control (e.g., increased monitoring with management sign-off). Reported in compliance dashboards.
Standards & regulations
  • NIST SP 800-162:2014 «A conflict of duty is the term used when a user may have combined permissions and a set of such combined permissions is issued to identify access that is in conflict for enforcement of separation of d»
  • OASIS XACML v3.0 Separation of Duties Version 1.0 (Committee Specification 01, 30 January 2024) «Separation of duties (SoD) is a security principle applied to minimize fraud, misuse of information, conflicts of interest and user errors by requiring that a task can only be completed by the active »
Sources