SOX Change Log Checker
Finding 5 of 10

One person, three roles: what the rows show and the clause behind it

The same person wrote, approved and deployed the change: the row carries one name in all three fields.

What does an auditor ask when one person wrote, approved and deployed a change?

This is the segregation-of-duties row an auditor reads first, because every other safeguard on the change depends on a second person. ISO/IEC 27001 5.3, NIST SP 800-53 AC-5 and COBIT DSS06.03 all ask that conflicting duties sit with different people, and AS 2201 has the auditor judge whether controls are operated by persons with the authority to do so. The checker lists the rows with one name in the author, approver and deployer fields.

The question the auditor is likely to ask

walkthrough pack

What stops one person from writing, approving and releasing a change, and who reviewed this one after the event?

The clause behind it

8 clauses in 7 frameworks
FrameworkThe clause behind it
SOX 404 / ICFRSOX 404 ITGC IT General Controls (ITGC) - Access, Change, Operations
PCAOB AS 2201AS 2201 ¶39-42 Walkthroughs and the selection of controls to test
COBIT 2019COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority
SOC 2 (Trust Services Criteria)SOC 2 CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks
ISO/IEC 27001:2022ISO 27001 5.3 Segregation of duties
PCI DSS v4.0PCI DSS 6.5.4 Roles separated between production and pre-production
NIST SP 800-53 Rev 5SP 800-53 AC-5 Separation of duties · SP 800-53 CM-5 Access restrictions for change

A result shows the frameworks you tick; SOX 404 brings COBIT and AS 2201 with it. PCI DSS clauses show on the cardholder systems only.

SOX 404 ITGC IT General Controls (ITGC) - Access, Change, Operations
The clause text

ITGC including access management, change management, computer operations, program development, backup, recovery.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: SOX 404 / ICFR
AS 2201 ¶39-42 Walkthroughs and the selection of controls to test

What the external auditor does under this standard (context, not a reading of your rows):

What the auditor does under it

Walkthroughs, selection, design effectiveness. Requirements include (a) perform Walkthroughs of significant transaction flows to confirm understanding of controls, identify control points, (b) Selecting Controls to Test focused on controls that sufficiently address the risk of misstatement to each relevant assertion, (c) evaluate Design Effectiveness via inquiry, observation, walkthrough, inspection, (d) determine whether the company's controls if operating as prescribed by persons possessing necessary authority, competence would satisfy the company's control objectives, (e) document understanding, selection rationale, design conclusions, (f) update design conclusions as controls or processes change.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: PCAOB AS 2201
COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority
The clause text

Business roles, responsibilities, levels of authority and segregation of duties supporting the process objectives are managed, and access to all information assets related to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; levels of authority for approving transactions, transaction limits and other decisions follow approved job roles; sensitive activities are allocated so that duties are clearly segregated; access rights and privileges are the minimum needed for predefined job roles, removed or revised immediately on role change or termination; regular awareness and training cover roles, responsibilities, the importance of controls and the security, integrity, confidentiality and privacy of information; administrative privileges are secured, tracked and controlled to prevent misuse; and access control definitions, logs and exception reports are periodically reviewed so that privileges remain valid and aligned with current staff and roles.

Evidence an auditor expects: Authority and limit matrices; segregation of duties allocations; access aligned to roles with prompt removal; privilege reviews and exception reports
Where it usually falls short: Transaction limits not enforced in the system; Access accumulated across role changes
Source: COBIT 2019
SOC 2 CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks

Named, not quoted: the criteria text is not held in full here.

Evidence an auditor expects: Evidence control activities were selected in response to identified risks, traceable from the risk register to specific controls; The control matrix or equivalent, showing the mix of control types including preventive and detective and manual and automated; Evidence of consideration of the relevant business processes and of the level at which each control applies; Evidence of segregation of duties considered in control design, and compensating controls where segregation was not practicable; Evidence controls were assigned owners responsible for their performance
Where it usually falls short: Controls listed with no traceability to any risk, so the entity cannot show they mitigate anything identified; Detective controls absent, leaving no means to identify failure of the preventive ones
Source: SOC 2 (Trust Services Criteria)
ISO 27001 5.3 Segregation of duties
The clause text

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

Evidence an auditor expects: Role separation matrix; Approval workflow records; Access rights review reports; Segregation conflict log
Where it usually falls short: Combining conflicting roles in small teams; Lack of documented exceptions
Source: ISO/IEC 27001:2022
PCI DSS 6.5.4 Roles separated between production and pre-production

Roles and functions are separated between production and pre-production so that only reviewed and approved changes are deployed.

A one-line statement; the standard's own text is not quoted here.

The evidence list held against this requirement belongs to a different control, so none is shown.
Source: PCI DSS v4.0
SP 800-53 AC-5 Separation of duties
The clause text

Requires the organization to identify and document the individual duties that must be kept apart to limit malevolent activity without collusion, and to define system access authorizations so that those duties cannot be exercised by one person.

Evidence an auditor expects: Documented conflicting duty pairs for the mission and system in question; Role definitions and entitlement mapping showing conflicting duties are not held together; Toxic combination report from the identity system or a manual conflict analysis; Approved exceptions with the compensating detective controls applied
Where it usually falls short: Conflicting duties named for finance processes only and never for system administration; Small teams create unavoidable conflicts that are tolerated rather than documented and compensated
Source: NIST SP 800-53 Rev 5
SP 800-53 CM-5 Access restrictions for change
The clause text

Requires physical and logical access restrictions on who may make changes to the system to be defined, documented, approved and actually enforced, so that only authorized personnel can alter the system.

Evidence an auditor expects: Documented and approved restrictions on who may change what; Access control configuration for production change paths and deployment pipelines; Records showing enforcement, for example rejected unauthorized deployments; Review of privileged change access against the approved list
Where it usually falls short: Developers hold standing write access to production alongside the pipeline; Restrictions documented but not enforced, so the pipeline can be bypassed manually
Source: NIST SP 800-53 Rev 5

Change types where it shows most

Other findings

Run the specimen Check your own change log