Find White Papers
Home
About Us
List Your Papers
    
> Winshuttle > Easing Sarbanes-Oxley Compliance by Giving Business Users Control of Their Data

Easing Sarbanes-Oxley Compliance by Giving Business Users Control of Their Data

White Paper Published By: Winshuttle

This white paper describes some easy-to-use data management tools that many companies are using to let business users do complex data updates and reporting tasks effortlessly. This technology is not only easing their Sarbanes-Oxley compliance, but is also saving these companies large amounts of time and money.



Tags : 
compliance, sox, sarbanes, sarbox, sarbanes-oxley, sarbanes oxley, data management, cost control

Winshuttle
Published:  Dec 04, 2006
Type:  White Paper
Length:  3 pages


 
  


      !
A WHITE PAPER BY WINSHUTTLE, INC. 1729 208TH STREET SE, SUITE 202 BOTHELL, WA 98012, USA (800) 711-9798 WWW.WINSHUTTLE.COM
"
 
The Sarbanes-Oxley Act (SOX) of 2002 is one of the top priorities at US-based public companies today. In companies that have implemented SAP, one of the most common open SOX audit issues is that users in the IT departments have very broad access to production data in SAP. Therefore, companies are finding that they have to take many data access privileges away from IT users. This has severely limited the ability of IT support staff to assist in routine data maintenance activities. Thus, there is a pressing need at many companies for business users to be responsible for their own production data maintenance activities. This paper describes how companies can give the business users control of their own data, and not only ease their compliance to the Sarbanes Oxley Act, but also improve corporate productivity.

 "#   $" 

In response to allegations of dubious financial accounting practices culminating in major corporate scandals, the Public Company Reform and Investor Protection Act of 2002, also known as the Sarbanes-Oxley Act (SOX), was implemented to establish good corporate governance and restore confidence in public companies.
Section 404 of SOX requires top management to establish an adequate internal control structure and include an assessment of the effectiveness of this control structure in the company's annual report. Additionally, an external auditor needs to verify the management's assertions.
Technical safeguards play an important role in complying with SOX Section 404 due to the extensive role of IT infrastructure and applications in today's financial reporting and accounting processes. Enforcing Segregation of Duties (SoD), strong user authentication, fine tuning of authorization rights, and access controls are among the technical controls needed to ensure the validity of the accounting information and to prevent fraudulent access to financial data in the process.

SEPTEMBER 9, 2005 © WINSHUTTLE, INC. 2005 EASING SARBANES-OXLEY COMPLIANCE BY GIVING BUSINESS USERS CONTROL OF THEIR DATA
& '  (' 
#"   )"$*
One key aspect of a Sarbanes-Oxley audit is checking that rights and duties are separately assigned to different individuals so that no individual has the power to divert business or transactions in a fraudulent manner.
It is the Sarbanes-Oxley IT auditor's job to check that individual permissions and roles are organized in such a way as to not make the company vulnerable to fraud. For example, no single individual should be able to access all systems involved in financial transactions, because knowledge of the full path through those systems could make it easier for that person to commit fraud. One often cited example is that a person who is authorized to create vendor payments should not be able to create new vendor accounts as well.
The principle of separation of duties and rights is often implemented using the concept of "roles" within an IT system. SAP already provides an extensive framework for maintaining role-based security and segregation of duties.
A key principle in the setting up of role-based security, however, is the principle of least privilege and it should be applied when assigning permissions within the ERP system. Any individual should be given only the permissions he/she needs in order to carry out his/her job.
This violation of the least privilege principle is one of the most prevalent open SOX audit issues across many corporations. Typically IT support staff has very broad access to the SAP production system, in part to enable them to handle business user's data maintenance and data upload and download tasks. Auditors have been requesting that such super user access be removed to reduce the risk of fraud.

    &  + !
Many companies are responding to the audit findings by taking many data access privileges away from IT users. Such restrictions are s... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search