Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.3 Segregation of duties

1. Operational Isolation and Role Mapping

anDREa enforces the segregation of conflicting duties and areas of operational responsibility to minimize the risk of unauthorized modifications, undetected errors, or malicious exploitation of corporate and technical assets. Operational boundaries, system permissions, and administrative roles are explicitly separated and governed through the anDREa Roles and Responsibilities Matrix in accordance with ISO/IEC 27001 Annex A.5.3.


2. Constraints of Scale and Mitigating Compensating Controls

As a cloud-native scale-up organization, anDREa explicitly recognizes that its tight organizational structure occasionally requires personnel to hold dual roles or bridge multiple operational disciplines. To maintain strict security integrity despite these constraints, anDREa does not permit unmonitored overlapping capabilities.

2.1 Toxic Combination Management

Our Roles and Responsibilities Matrix formally identifies and documents toxic combinations—scenarios where overlapping access controls or responsibilities could allow an individual to execute a critical process from end-to-end without independent oversight. Examples of strictly controlled or separated domains include:

  • Separation between software development and production code deployment authorizations.
  • Separation between incident triage execution and final post-incident compliance validation.
  • Separation between financial procurement authorization and operational resource provisioning.

2.2 Compensating Control Framework

Where a dual role is operationally unavoidable due to corporate sizing, anDREa implements strict, documented compensating controls directly within the matrix. These include:

  • Mandatory Multi-Party Sign-off: High-impact technical modifications (such as cloud fabric adjustments or master policy changes) require explicit peer review and secondary management approval before execution.
  • Immutable Audit Logging: System administrative actions are captured via non-repudiation logging within Azure DevOps and Google Workspace, ensuring all operational modifications are visible and auditable by the full Management Team.
  • Regular Governance Reviews: The Management Team regularly checks the allocation of permissions during ISMB sessions to ensure that temporary privileges are promptly revoked.