Mapped to NIST 800-171 Requirement: 3.1.4
CMMC Assessment Objective: AC.L2-3.1.4[b]
What This Objective Means
This assessment objective focuses on the policy layer of enforcing SoD. You’re expected to:
• Define separation of duties in your Access Control Policy
• Specify which roles must be kept separate
• Provide guidance on how conflicts are identified and resolved
This is what the assessor will review to confirm that SoD isn’t just informally understood—it’s documented, communicated, and enforced across the organization.
Why It Matters
When your access control policy doesn’t mention SoD:
• Staff might not understand the importance of avoiding conflicting roles
• Role assignments could be made inconsistently across teams
• You can’t prove compliance with CMMC or similar frameworks
A well-written policy serves as a foundation for secure operational practices.
How to Implement It
• Review your existing access control policy to ensure SoD is explicitly addressed
• Include language such as:
◦ “The organization enforces separation of duties by assigning system administration and security audit functions to different personnel.”
◦ “Users may not approve access they themselves request.”
• Reference your role matrix or SoD documentation created under AC.L2-3.1.4[a]
• Update your policy with version control and communicate it to system owners and managers
Evidence the Assessor Will Look For
• A current access control policy that includes SoD language
• Sections that define role conflict management or describe prohibited combinations
• Cross-references to role definitions or HR onboarding checklists
• Documented procedures for resolving SoD conflicts
Common Gaps
• Policy doesn’t mention SoD at all
• SoD is implied but not defined or enforced
• Policy is outdated or doesn’t match current system configurations
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Providing policy templates that include standardized language for separation of duties
• Enforcing SoD in role design and access provisioning workflows
• Logging all access and role assignments for policy enforcement and audit trails
• Helping you document how policy connects to actual system behavior
With Cuick Trac, policy and practice go hand in hand.
Final CTA
Separation of duties isn’t just a best practice—it’s a policy requirement.
Schedule a Cuick Trac demo and align your access control policy with secure, auditable practices.