Identities (users) have been provisioned with access to assets which breaches a segregation of duties requirement
Context and Guidance: Segregation of duties is an important access control principle designed to prevent identities (users) from bypassing validation and verification checks when performing actions, and significantly limits the potential for unauthorised activity.
Segregation of duty violations must be identified and mitigated, given the increased risk that they present to business activities.
Example activities that indicate this Anti-Pattern is Present include: