SAP - TINET - Tarragona Internet

(Ron) #1

Table 16-2 Suggested Guidelines for Policy Building Sessions


Participants Topics Deliverables

Executives Sensitive information Sensitive transactions
and transactions and data

Process Managers Process risks and Segregation of duties
process overlaps risks between processes

Auditors Segregation of duties Risks and control
and internal controls omissions

Security Administrators Security design Naming conventions and
and processes approval processes

Move to Strategic Adoption of Automated Controls ...............................


Manual controls can only check a sample of transactions, and the controls
have to be tested every day. Automatic controls check every transaction, and
after initial testing, can simply run, allowing you to manage by exception. Not
all controls can be automated controls, but the more automated controls you
put in place, the easier your job becomes.

Adopt Strategies for Cleaning Up Access Control ...................................


Segregation of duties violations are largely prevented through effective
access control. Because these problems have evolved over time, you’ll need
to get everyone on board in cleaning up this area.

Be sure to separate technical and business issues:

Roles and profiles belong to IT.
User assignments and circumstances belong to business.

Collaboration of both required to validate results.

302 Part V: The Part of Tens

Free download pdf