What is the term for dividing steps in a function among different individuals to prevent subversion?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is the term for dividing steps in a function among different individuals to prevent subversion?

Explanation:
Separation of duties is the practice of dividing responsibilities so that no single person completes a process from start to finish. By distributing steps among different individuals, it creates checks and balances that deter subversion and reduce the risk of fraud. In PCI DSS and security in general, this means separating tasks like initiating, approving, implementing, and reconciling changes or transactions across distinct roles. This way, potential fraud or errors require collusion to go undetected. Dual control is related, as it often enforces SoD for especially sensitive actions by requiring two people, but the broader concept described here is separation of duties. The other terms describe related but distinct controls—access reviews focus on evaluating who has access, and the terminology isn’t the standard way to name this overarching practice.

Separation of duties is the practice of dividing responsibilities so that no single person completes a process from start to finish. By distributing steps among different individuals, it creates checks and balances that deter subversion and reduce the risk of fraud. In PCI DSS and security in general, this means separating tasks like initiating, approving, implementing, and reconciling changes or transactions across distinct roles. This way, potential fraud or errors require collusion to go undetected. Dual control is related, as it often enforces SoD for especially sensitive actions by requiring two people, but the broader concept described here is separation of duties. The other terms describe related but distinct controls—access reviews focus on evaluating who has access, and the terminology isn’t the standard way to name this overarching practice.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy