Systems enforce role-based security responsibilities
Configuring systems so each defined responsibility can only be exercised by the assigned person is access control applied to governance roles, backing A.5.15's requirement that access maps to genuine need.
Configuring system permissions so each security responsibility can only be exercised by the people formally assigned to it supports segregation of duties, but role-based permissions alone do not stop one role from both requesting and approving the same change.
Configuring system permissions so each security responsibility can only be exercised by the assigned person is the technical precondition that makes A.8.2's privilege restriction enforceable rather than aspirational.
https://sekit.ai/api/mcp/crosswalk