Separation of duties makes sure that one individual cannot complete a critical task by herself.
Collusion means that at least two people are working together to cause some type of destruction or fraud.
Two variations of separation of duties are split knowledge and dual control. In the case of split knowledge, no one person knows or has all the details to perform a task. In the case of dual control, two individuals are again authorized to perform a task, but both must be available and active in their participation to complete the task or mission.
Rotation of duties (rotation of assignments) is an administrative detective control that can be put into place to uncover fraudulent activities.
Employees in sensitive areas should be forced to take their vacations, which is known as a mandatory vacation.
剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:1.17 人员安全