COBIT 2019
Deliver, Service and Support – COBIT 2019

COBIT 2019 DSS06.03: DSS06.03 Manage roles, responsibilities, access privileges and levels of authority

Business roles and responsibilities, authority levels and segregation of duties that support process objectives are managed, and access to every information asset tied to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; authority levels for approving transactions and other decisions, and transaction limits, follow approved job roles; sensitive activities are allocated so duties are clearly separated; access rights and privileges are limited to the minimum that predefined job roles need and are removed or revised at once when a role changes or employment ends; regular awareness and training cover roles, responsibilities, why controls matter, and the privacy, confidentiality, integrity and security of information; administrative privileges are protected, tracked and controlled so they cannot be misused; and definitions of access control, together with logs and exception reports, are reviewed periodically so privileges stay valid and match current staff and roles.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

  • 5.15 Access control
  • 5.3 Segregation of duties
  • P3 Principle 3: Establishes structure, authority and responsibility

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Deliver, Service and Support – COBIT 2019

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.