FedRAMP Controls / AC

AC-5 Separation of Duties

Family AC
Baselines moderate
Mapped KSIs 3

Control statement

a. Identify and document {{ insert: param, ac-05_odp }} ; and
    b. Define system access authorizations to support separation of duties.
        Guidance: CSPs have the option to provide a separation of duties matrix as an attachment to the SSP.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-04Just-in-Time Authorization
Use a least-privileged, role and attribute-based, and just-in-time security authorization model for all user and non-user accounts and services.
Identity and Access Management
KSI-PIY-04CISA Secure By Design
_Persistently_ review the effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles.
Policy and Inventory
KSI-PIY-06Security Investment Effectiveness
_Persistently_ review the effectiveness of the organization's investments in achieving security objectives.
Policy and Inventory