RE:[sap-security] What are Audit implications for overriding SOD violations?
Posted by
Admin at
|
Share this post:
|
0 Comments
| | Posted by Alex Ayers (Director of Operations) on Mar 9 at 1:18 PM | |
Hi Dan
There are 3 things you can do with an SOD conflict:
Remediate (fix the role)
Accept
Mitigate (put in a compensating control)
If you have tailored your ruleset to meet your business requirements then you can usually rule out acceptance of the risk otherwise you would have done already.
Where remediation is not an option then you need to mitigate the risk, that is operate an alternative control that is proportionate to the risk.
What an auditor (internal or external) will be looking is to see that there is an effective mitigating control operating to cover that risk. As you mentioned, reviewing key actions by a user may be one way of mitigating by using a detective control rather than using a preventative control such as authorisations.
---------------Original Message---------------
From: rdbarahona
Sent: Tuesday, March 09, 2010 12:44 PM
Subject: What are Audit implications for overriding SOD violations?
> Hi,
>
> It seems inevitable that organizations need to make exceptions to SOD conflicts (due to short staffing, etc.) from time to time. When you have this situation, do you have to manually review all the activity of the user with the SOD conflict? Have you ever had an auditor (internal or external) question you about SOD overrides?
>
> Thanks,
>
> Dan
__.____._ There are 3 things you can do with an SOD conflict:
Remediate (fix the role)
Accept
Mitigate (put in a compensating control)
If you have tailored your ruleset to meet your business requirements then you can usually rule out acceptance of the risk otherwise you would have done already.
Where remediation is not an option then you need to mitigate the risk, that is operate an alternative control that is proportionate to the risk.
What an auditor (internal or external) will be looking is to see that there is an effective mitigating control operating to cover that risk. As you mentioned, reviewing key actions by a user may be one way of mitigating by using a detective control rather than using a preventative control such as authorisations.
---------------Original Message---------------
From: rdbarahona
Sent: Tuesday, March 09, 2010 12:44 PM
Subject: What are Audit implications for overriding SOD violations?
> Hi,
>
> It seems inevitable that organizations need to make exceptions to SOD conflicts (due to short staffing, etc.) from time to time. When you have this situation, do you have to manually review all the activity of the user with the SOD conflict? Have you ever had an auditor (internal or external) question you about SOD overrides?
>
> Thanks,
>
> Dan
Copyright © 2010 Toolbox.com and message author.
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
SAP Security Helper
Posted helpful replies on 5 threads in a group to earn a Bronze Achievement
Related Content
In the Spotlight
White Papers
In the Spotlight
55% of IT Pros Use Social Media to Advance Their Careers. See the Survey Results
View this thread online
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion