This objective requires organizations to explicitly include separation of duties (SoD) in their written access control policies. It ensures your policy formally defines which responsibilities must be distributed across roles, supporting secure, auditable system operations.