XML Feeds

Search Big4Guy

Custom Search

Sponsored

« Information Security Glossary - Definition of RISKAuthorization Concept in SAP R/3 - How to define User Roles, Profiles and authorizations in SAP. »

SAP R/3 Security in the Sarbanes OXley Era - 7 Steps for Better SOX Compliance

SAP R/3 Security in the Sarbanes OXley Era - 7 Steps for Better SOX Compliance

Post Sarbanes Oxley, focus for corporations is more on compliance and security. Sarbanes Oxley has had a major impact on the organizations using SAP R/3 as their ERP. Some of the changes seen in the corporate landsacpe include identifying and documenting processes, implementing controls and safeguards, documenting user access approvals etc. In short, there has been a cultural shift in organizations post Sarbanes Oxley. Below, I have listed 7 major pointers which can help organizations towards better SAP security in the Sarbanes Oxley Era.

SAPSarbanesOxleySecurity

1. Provide users access on a need to know and need to do basis.
2. Adequately secure programs, transactions and tables.
3. All user accesses to SAP R/3 are properly authorized and approved.
4. Segregation of duties is maintained for all sensitive business transactions
5. All controls and business processes are documented.
6. Anti-fraud preventive controls are in place to prevent & detect fraud before an audit.
7. User profiles and roles in SAP are secured and designed to meet business requirements.

Related Posts on Sarbanes Oxley >>

Sarbanes Oxley Project Management
Internal Control Report Contents
Criteria for Designing Internal Controls
Entity Level Controls for SOX


Permalink 01/22/06 09:34:38 pm , by big4guy Email , 1607 views, Sarbanes Oxley, 1 comment »

1 comment

Comment from: Robin-Jan de Lange [Visitor]
This is a good high level summary. The devil is in detail though. A tool that can help you with implementing these points on a continuous basis is the product suite from D2C Solutions.
More details at www.d2c.net
04/04/06 @ 15:58

This post has 60 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)