Is the following statement accurate regarding Separation of Duties (SoD)?
Is the following statement accurate regarding Separation of Duties (SoD)?
Solution: An SoD policy must define control matrix.
A . Yes
B . No
Answer: B
Explanation:
No, an SoD (Separation of Duties) policy does not require a control matrix to be defined. While a control matrix can be a useful tool for organizations to visualize and enforce SoD policies by mapping roles to potential conflicting access rights, it is not a mandatory component of an SoD policy. An SoD policy primarily focuses on preventing conflicts of interest by ensuring that no individual has access to perform conflicting tasks within a business process (e.g., approving and processing payments). The control matrix is a recommended method for managing SoD but not a requirement.
Key Reference from SailPoint Documentation:
SoD Policy Overview: SailPoint recommends structuring SoD policies to focus on preventing conflicting access but does not mandate the use of a control matrix, which is an optional best practice for visualizing these controls.
Latest IdentityNow Engineer Dumps Valid Version with 108 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund