SlideShare une entreprise Scribd logo
1  sur  29
Effective Segregation of Duties
for PeopleSoft
SmartERP: Doris Wong, CEO; Dan White, VP of Product Strategy
Q Software: Lewis Hopkins, Product Manager

February 23, 2011
Webinar Recordings available at smarterp.com/webinars
Our webinar will begin shortly. Please note all phone lines and computer microphones will
be placed on mute throughout the presentation. Please use the GoToWebinar QUESTION
feature to ask questions.
Welcome & Introductions
  Doris Wong
  CEO, Smart ERP Solutions, Inc.
  Former Oracle Group VP and GM for PeopleSoft Enterprise
  Over 15 Years Experience with PeopleSoft

  Dan White
  VP, Product Strategy, Smart ERP Solutions, Inc.
  Former Oracle/PeopleSoft Functional Architect
  Over 12 Years Experience with PeopleSoft

  Lewis Hopkins
  Product Manager, Q Software, Ltd.
  Over 10 years experience in risk management, governance, and
  security for compliance for ERP applications
Agenda
• “Effective” Segregation of Duties (SoD)
• About Smart ERP Solutions, Inc.
• Smart SoD™: Effective SoD for
  PeopleSoft
• Demo
• Summary and Q & A


  Please note all phone lines and computer microphones will be placed on mute throughout
  the presentation. Please use the GoToWebinar QUESTION feature to ask questions.
“Effective”
Segregation of Duties
Lewis Hopkins, Q Software, Ltd.
Segregation of Duties
A key element in the compliance lifecycle
Effective Segregation of Duties


                  Proactive
                    SoD




                  SoD
                              Reactive
     Mitigation
                               SoD
Characteristics/Benefits of Effective SoD
• Built-in model enables SoD enforcement
   – Violations checked BEFORE go-live
   – Your decision to enforce rules or allow violations
• Saves time (= money)
   –   Easy set-up
   –   Easy testing for violations
   –   Quick and easy reporting
   –   Reduces number of compensating controls required
   –   Reduces auditing effort / costs
• Reduces risk
   – Enforcing and reporting SoD violations reduces
     opportunity for fraud
SoD – The Issues

• Nothing in PeopleSoft
  – Any release
• Use a Spreadsheet?
• How do you…
  – Ensure the actual access control mirrors the
    spreadsheet?
  – Right people access the right data?
  – Manage change control problems?
  – Assess impact of changes?
  – Manage enforcement of SoD?
Proactive SoD



                           Aim:
Prevent SoD Violations occurring during security Assignment.
        Ensure Security Policy is enforced long term.
‘Proactive’ SoD

    A/P “Super”
 Voucher Clerk Role                          SoD
                                                                       OK
1.   AP Voucher clerk
                                          Violations
2.   Secondary role 2                       Check
3.   Secondary role 3
                    6

                                                  Violations
                          Segregate this task:   From this task
                                                                            Build Security
       Change
   Role assignment        Sales Order Entry      Purchase Order

          Or              Vendor Master          Bank Payments

       Security           Sales Pricing          Sales Order Entry
        without           Purchase Order         Goods Receipt
affecting live security   Customer Master        Sales Order Entry

                          Sales Order Entry      Credit limits

                          Credit Notes           Invoicing (A/R)

                          Purchase Order         Vendor Master

                          Purchase Order         Invoice entry (A/P)

                          Vendor Master          Purchase Order

                          Vendor Master          Credit Notes

                          Invoice entry (A/P)    Bank Payments
                                                                        Extract from pre-populated,
                                                                        model
Reactive SoD




                       Aim:
Accurately assess existing security for remediation.
           Reduce Audit time and cost.
       Build case for restructuring security.
‘Reactive’ SoD


                                   Roles
                                (High-Level)




                   Permission
                       List
                    (Process)



                                           Components
                                         (In-depth Audit)



Reporting directly on
  existing security
Top 10 Rules

•   Creating a journal entry and opening a closed accounting period
•   Maintaining accounts receivable master data and posting receipts
•   Depositing cash and reconciling bank statements
•   Completing goods transfer and adjusting physical inventory counts
•   Approving time cards and distributing paychecks
•   Preparing an order and changing a billing document
•   Changing an order and creating a delivery
•   Creating a journal entry and opening a closed accounting period
•   Creating general ledger accounts and posting journal entries
•   Maintaining bank account information and posting payments
•   Maintaining assets and creating a goods receipt
Creation of SoD Rules
• Role level
   – Create matrix of all active system roles
   – Identify all roles that should not be linked to the same user
       • Such as purchasing and payments
• Permission List / Business Process level
   – Include Application security & processing options
   – Add to / modify as needed
• Component / Program level
   – Add in any custom or modified processing
   – If creating your own rules
       • Start with most important controls & gradually add to them
SoD Logic
• AND/OR Logic
  – Applied to rules at the component and permission list level.
  – The user is either in conflict with all the items in a rule (AND
    logic) or,
  – The user is in conflict with at least two items in the rule (OR
    logic)
  Example – AND Logic:                   Example – OR Logic:
         Rule 1:                               Rule 1:
    Sales Order Entry                     Sales Order Entry
          AND                                   AND
     Purchase Order                        Purchase Order
          AND                                    OR
     Bank Payments                         Bank Payments

 Result: Extreme Flexibility and Maximum Benefit to customers!
Mitigation – The Issues

• Current Economic Climate
  – Many redundancies equates to less people doing more.
  – Major requirement from Audit to allow remediation
    where a user is considered a risk.
  – SOX requires that during an audit all risks must at least
    be visible and understood by the business.
  – With this comes risk assessment and documentation.
• Seasonal Changes
  – Staff holidays or time away from office requires other
    users be able to perform these additional duties.
Mitigation Solutions

• Ability to mitigate users once a validation has
  occurred.
• Details of mitigation, including notes get added to
  a mitigation table.
• The user gets checked during the next validation
  but is not added to the violations table.
• Ability to time out mitigations, i.e. allowing for staff
  who are on holiday, etc.
About Smart ERP Solutions, Inc.
Smart ERP Solutions, Inc.
   Comprised of the best former developers, architects and
   executives from PeopleSoft/Oracle
   Providing cost-effective, robust and repeatable “Smart Solutions”
   for PeopleSoft applications
   Unique best practices and expertise in PeopleSoft strategic
   planning, Smart implementation and upgrade services

            KEY DIFFERENTIATOR−OUR SMARTADVANTAGE

Rather than assigning teams of consultants to projects we apply our
   pre-built, proven solutions to efficiently address those efforts
   common to any PeopleSoft project thus saving time, reducing
   costs, minimizing risks and lowering total cost of ownership by
   avoiding costly difficult-to-maintain customizations.
SmartERP: Our Philosophy
                         Solutions
• Enhance and Extend Standard PeopleSoft Functionality
  to Meet Business Needs
   – 3Cs : Common, Critical, Complementary
• Repeatable, Pre-Packaged, Highly-Configurable and
  Innovative Solutions
• Release Independence
• Customer-Driven Requirements
• Architected and Designed as Add-On Solutions
• Lower Total Cost of Ownership
   – Minimal to No Customizations
   – Minimal Upgrade Impact
• Affordable and Cost-Effective
SmartERP: Our Solutions
Business Requirements                                                           Smart Solutions
Row level security on any data that requires limited or authorized access
                                                                                Smart Security
Define , manage and enforce segregation of duties for various roles within
an organization to adhere to compliance requirements
                                                                                Smart SoD
Robust workflow approval capabilities across any business transaction or
documents across your Enterprise
                                                                                Smart Workflow
Streamlined and easy-to-use data entry pages configured to meet your
specific business process requirements, incl. industry reqmts; Easily add
                                                                                Smart Docs including
features anywhere such as Save as Draft, Copy from Templates,                   ERP Gadget
Attachments, Configurable Print, Collaborative Comments, Workflow, User
Help, Business Process View
Configuring and tailoring business processes to meet your organization’s
specific processes, including defining step-by-step actions for each
                                                                                Smart Enterprise BPM
process and managing your users through your organizations specific
business process.
One-stop visibility into the full business process lifecycle of a transaction
                                                                                Smart Lifecycle Viewer
Addressing additional compliance requirements not in standard
PeopleSoft: I-9/W-4 Form, 1042 Foreign National Requirements
                                                                                Smart Compliance
Manageable solutions for complex integration needs
                                                                                Smart Integration Packs
Other Common, Critical and Complementary business requirements
                                                                                Tell us, we’ll build it!
Smart SoD™
Smart SoD Summary

                             • Developed expressly for PeopleSoft
                               by SmartERP in cooperation with Q
Q Software
                               Software
                             • Uniquely integrated within your
             SmartERP
                               current PeopleSoft
                             • Powerful Proactive, Reactive and
                               Mitigation features
                             • Built-in
 Smart SoD™                    Analytics/Reporting/Dashboards
                             • Use delivered SoD rules or easily
                               create your own
DEMO
Smart SoD™
Smart SoD Demo Scenario

• SoD Model and Rules
• Reactive: Mass check for user violations
• Proactive: Validate new user profile against
  established SoD rules
• Dashboard/Analytics
Summary
Value Statement
  Segregation of Duties is an important element of your overall
           PeopleSoft security and risk management

Key Features of Smart SoD can help you maintain legislative
compliance (SoX), meet audit requirements and reduce the
likelihood and impacts of fraud and errors
• Expressly designed for your current PeopleSoft
• Powerful Proactive, Reactive and Mitigation Features
• Automated Workflow Approvals
• Reporting/Dashboards facilitate audits and compliance
• Use pre-packaged built-in SoD rules or easily create your
   own
• Add-on Architecture Lowers Total Cost of Ownership
   – Seamless Integration
   – Utilize Best Practices
   – Maintenance and Upgrades
Q&A
To ask a question please use the GoToMeeting QUESTION feature (please note
all phone lines and computer microphones have been placed on mute).

If we can’t get to your question live we will respond to you directly via email
after the webinar.


   For more information visit:                  smarterp.com
   View Webinar Replays: smarterp.com/webinars
   View Solution Previews: smarterp.com/previews
   Copyright © 2011 Smart ERP Solutions, Inc.
Thank You
For more information visit:                  smarterp.com
View Webinar Replays: smarterp.com/webinars
View Solution Previews: smarterp.com/previews
Copyright © 2011 Smart ERP Solutions, Inc.

Contenu connexe

Tendances

Sod remediation best practices for isaca
Sod remediation best practices for isacaSod remediation best practices for isaca
Sod remediation best practices for isaca
pooshu
 
Sap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoftSap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoft
PennonSoft
 

Tendances (20)

Sod remediation best practices for isaca
Sod remediation best practices for isacaSod remediation best practices for isaca
Sod remediation best practices for isaca
 
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
 
Seg dutieschecklist
Seg dutieschecklistSeg dutieschecklist
Seg dutieschecklist
 
Ey segregation of_duties
Ey segregation of_dutiesEy segregation of_duties
Ey segregation of_duties
 
Sap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoftSap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoft
 
Building continuous auditing capabilities
Building continuous auditing capabilitiesBuilding continuous auditing capabilities
Building continuous auditing capabilities
 
Visual Risk Iq + Audimation Deck For Charlotte Iia For Pdf Only
Visual Risk Iq + Audimation Deck For Charlotte Iia For Pdf OnlyVisual Risk Iq + Audimation Deck For Charlotte Iia For Pdf Only
Visual Risk Iq + Audimation Deck For Charlotte Iia For Pdf Only
 
How to Effectively Audit your IT Infrastructure
How to Effectively Audit your IT InfrastructureHow to Effectively Audit your IT Infrastructure
How to Effectively Audit your IT Infrastructure
 
Continuous auditing
Continuous auditingContinuous auditing
Continuous auditing
 
SDLC Control
SDLC ControlSDLC Control
SDLC Control
 
Webinar: Simplify, Gain Insight, Strengthen with SAP GRC 10.1
Webinar: Simplify, Gain Insight, Strengthen with SAP GRC 10.1Webinar: Simplify, Gain Insight, Strengthen with SAP GRC 10.1
Webinar: Simplify, Gain Insight, Strengthen with SAP GRC 10.1
 
Life of the software - SDLC
Life of the software - SDLCLife of the software - SDLC
Life of the software - SDLC
 
GRC_2016_US_Brochure
GRC_2016_US_BrochureGRC_2016_US_Brochure
GRC_2016_US_Brochure
 
Ais Romney 2006 Slides 19 Ais Development Strategies
Ais Romney 2006 Slides 19 Ais Development StrategiesAis Romney 2006 Slides 19 Ais Development Strategies
Ais Romney 2006 Slides 19 Ais Development Strategies
 
IS Audits and Internal Controls
IS Audits and Internal ControlsIS Audits and Internal Controls
IS Audits and Internal Controls
 
SAP Risk Management
SAP Risk ManagementSAP Risk Management
SAP Risk Management
 
Business continuity planning guide
Business continuity planning guideBusiness continuity planning guide
Business continuity planning guide
 
Database auditing models
 Database auditing models  Database auditing models
Database auditing models
 
IT Compliance: Shifting from Cost Center to Profit Center
IT Compliance: Shifting from Cost Center to Profit CenterIT Compliance: Shifting from Cost Center to Profit Center
IT Compliance: Shifting from Cost Center to Profit Center
 
Segregation of Duties and Continuous Delivery
Segregation of Duties and Continuous DeliverySegregation of Duties and Continuous Delivery
Segregation of Duties and Continuous Delivery
 

En vedette

Po report 5 - Role Conflict
Po report 5 - Role ConflictPo report 5 - Role Conflict
Po report 5 - Role Conflict
Syaff Hk
 

En vedette (14)

IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOX
 
SAP GRC 10 Access Control
SAP GRC 10 Access ControlSAP GRC 10 Access Control
SAP GRC 10 Access Control
 
Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)
 
CrossIdeas Roadshow IAM Governance IBM Marco Venuti
CrossIdeas Roadshow IAM Governance IBM Marco VenutiCrossIdeas Roadshow IAM Governance IBM Marco Venuti
CrossIdeas Roadshow IAM Governance IBM Marco Venuti
 
Customer Identity Builds Digital Trust - London Identity Summit
Customer Identity Builds Digital Trust - London Identity SummitCustomer Identity Builds Digital Trust - London Identity Summit
Customer Identity Builds Digital Trust - London Identity Summit
 
Predictive analytics
Predictive analytics Predictive analytics
Predictive analytics
 
SOX- IT Perspective
SOX- IT PerspectiveSOX- IT Perspective
SOX- IT Perspective
 
AIA SOX Conference May 2009 - CCM & Data Analytics
AIA SOX Conference May 2009 - CCM & Data AnalyticsAIA SOX Conference May 2009 - CCM & Data Analytics
AIA SOX Conference May 2009 - CCM & Data Analytics
 
Sox Compliance Solution
Sox Compliance SolutionSox Compliance Solution
Sox Compliance Solution
 
Sox In Telecom Industry
Sox In Telecom IndustrySox In Telecom Industry
Sox In Telecom Industry
 
Po report 5 - Role Conflict
Po report 5 - Role ConflictPo report 5 - Role Conflict
Po report 5 - Role Conflict
 
3 Way Match for Purchasing Professionals
3 Way Match for Purchasing Professionals3 Way Match for Purchasing Professionals
3 Way Match for Purchasing Professionals
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance Presentation
 
eTOM - Foundation
eTOM - FoundationeTOM - Foundation
eTOM - Foundation
 

Similaire à Effective Segregation of Duties for PeopleSoft 2011-02-23

20111012 Sap Datasheet Site
20111012 Sap Datasheet Site20111012 Sap Datasheet Site
20111012 Sap Datasheet Site
Nicola_Milone
 
Ofs trust banking
Ofs trust bankingOfs trust banking
Ofs trust banking
Relevantz
 
Managing the Role Hierarchy at Enterprise Scale
Managing the Role Hierarchy at Enterprise ScaleManaging the Role Hierarchy at Enterprise Scale
Managing the Role Hierarchy at Enterprise Scale
Salesforce Developers
 

Similaire à Effective Segregation of Duties for PeopleSoft 2011-02-23 (20)

Implementing security and controls in people soft best practices - may 2017
Implementing security and controls in people soft   best practices - may 2017Implementing security and controls in people soft   best practices - may 2017
Implementing security and controls in people soft best practices - may 2017
 
20111012 Sap Datasheet Site
20111012 Sap Datasheet Site20111012 Sap Datasheet Site
20111012 Sap Datasheet Site
 
Workflow and Row-Level Security Solutions for PeopleSoft
Workflow and Row-Level Security Solutions for PeopleSoftWorkflow and Row-Level Security Solutions for PeopleSoft
Workflow and Row-Level Security Solutions for PeopleSoft
 
Sap GRC Basic Information | GRC 12 online training
Sap GRC Basic Information | GRC 12 online trainingSap GRC Basic Information | GRC 12 online training
Sap GRC Basic Information | GRC 12 online training
 
Identity & Access Governance versus Process Agility
Identity & Access Governance versus Process AgilityIdentity & Access Governance versus Process Agility
Identity & Access Governance versus Process Agility
 
Evolving the Product Management Process to Match Company Growth
Evolving the Product Management Process to Match Company GrowthEvolving the Product Management Process to Match Company Growth
Evolving the Product Management Process to Match Company Growth
 
Skyward Erp Presentation
Skyward Erp PresentationSkyward Erp Presentation
Skyward Erp Presentation
 
Overview of Identity and Access Management Product Line
Overview of Identity and Access Management Product LineOverview of Identity and Access Management Product Line
Overview of Identity and Access Management Product Line
 
Securing the Office of Finance in the Cloud -- Separating Fact from Fiction
Securing the Office of Finance in the Cloud -- Separating Fact from FictionSecuring the Office of Finance in the Cloud -- Separating Fact from Fiction
Securing the Office of Finance in the Cloud -- Separating Fact from Fiction
 
Workflow Automation in SolidWorks Enterprise PDM
Workflow Automation in SolidWorks Enterprise PDMWorkflow Automation in SolidWorks Enterprise PDM
Workflow Automation in SolidWorks Enterprise PDM
 
ISACA Ireland Keynote 2015
ISACA Ireland Keynote 2015ISACA Ireland Keynote 2015
ISACA Ireland Keynote 2015
 
Mayank-Tamrakar
Mayank-TamrakarMayank-Tamrakar
Mayank-Tamrakar
 
Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824Advanced Controls access and user security for superusers con8824
Advanced Controls access and user security for superusers con8824
 
Ofs trust banking
Ofs trust bankingOfs trust banking
Ofs trust banking
 
VMworld 2013: Building the Management Stack for Your Software Defined Data Ce...
VMworld 2013: Building the Management Stack for Your Software Defined Data Ce...VMworld 2013: Building the Management Stack for Your Software Defined Data Ce...
VMworld 2013: Building the Management Stack for Your Software Defined Data Ce...
 
Defying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with AutomationDefying Logic - Business Logic Testing with Automation
Defying Logic - Business Logic Testing with Automation
 
Managing the Role Hierarchy at Enterprise Scale
Managing the Role Hierarchy at Enterprise ScaleManaging the Role Hierarchy at Enterprise Scale
Managing the Role Hierarchy at Enterprise Scale
 
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & ImplementationsThousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
Thousands of Hours Saved and Risk Reduced for EBS Upgrades & Implementations
 
People soft risks and controls for educational institutions
People soft risks and controls for educational institutionsPeople soft risks and controls for educational institutions
People soft risks and controls for educational institutions
 
Introduction to Identity Management
Introduction to Identity ManagementIntroduction to Identity Management
Introduction to Identity Management
 

Plus de Smart ERP Solutions, Inc.

Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2
Smart ERP Solutions, Inc.
 

Plus de Smart ERP Solutions, Inc. (20)

Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2
 
Transforming Financial Insights with Oracle EPM
Transforming Financial Insights with Oracle EPMTransforming Financial Insights with Oracle EPM
Transforming Financial Insights with Oracle EPM
 
Maximize your Oracle Cloud Investment and Drive Innovation
 Maximize your Oracle Cloud Investment and Drive Innovation Maximize your Oracle Cloud Investment and Drive Innovation
Maximize your Oracle Cloud Investment and Drive Innovation
 
SmartERP PeopleSoft Security
SmartERP PeopleSoft  Security SmartERP PeopleSoft  Security
SmartERP PeopleSoft Security
 
SmartERP Oracle Capabilities 2023.pptx
SmartERP Oracle Capabilities 2023.pptxSmartERP Oracle Capabilities 2023.pptx
SmartERP Oracle Capabilities 2023.pptx
 
Best Practices to Modernizing your Oracle Applications
Best Practices to Modernizing your Oracle ApplicationsBest Practices to Modernizing your Oracle Applications
Best Practices to Modernizing your Oracle Applications
 
Manufactures whats keeping you up
Manufactures   whats keeping you upManufactures   whats keeping you up
Manufactures whats keeping you up
 
The Fully Automated Enterprise (RPA)
The Fully Automated Enterprise (RPA)The Fully Automated Enterprise (RPA)
The Fully Automated Enterprise (RPA)
 
Smart erp solutions oracle cloud services overview - 2021 - 2022
Smart erp solutions   oracle cloud services overview - 2021 - 2022Smart erp solutions   oracle cloud services overview - 2021 - 2022
Smart erp solutions oracle cloud services overview - 2021 - 2022
 
PeopleSoft Webinar - Configure vs. Customize Page and Field Configurator
PeopleSoft Webinar - Configure vs. Customize Page and Field ConfiguratorPeopleSoft Webinar - Configure vs. Customize Page and Field Configurator
PeopleSoft Webinar - Configure vs. Customize Page and Field Configurator
 
Alert framework2021
Alert framework2021Alert framework2021
Alert framework2021
 
No One Size Fits All - Form I-9 and E-Verify presentation from the DHS
No One Size Fits All - Form I-9 and E-Verify presentation from the DHSNo One Size Fits All - Form I-9 and E-Verify presentation from the DHS
No One Size Fits All - Form I-9 and E-Verify presentation from the DHS
 
E-Verify for PeopleSoft - Streamline and automate your Employment Authorizati...
E-Verify for PeopleSoft - Streamline and automate your Employment Authorizati...E-Verify for PeopleSoft - Streamline and automate your Employment Authorizati...
E-Verify for PeopleSoft - Streamline and automate your Employment Authorizati...
 
Pre-board Your New Hires for PeopleSoft - Streamline and automate your pre-bo...
Pre-board Your New Hires for PeopleSoft - Streamline and automate your pre-bo...Pre-board Your New Hires for PeopleSoft - Streamline and automate your pre-bo...
Pre-board Your New Hires for PeopleSoft - Streamline and automate your pre-bo...
 
Configure Versus Customize: Using PeopleSoft Page and Field Configurator
Configure Versus Customize: Using PeopleSoft Page and Field ConfiguratorConfigure Versus Customize: Using PeopleSoft Page and Field Configurator
Configure Versus Customize: Using PeopleSoft Page and Field Configurator
 
Managed Services - Small, Medium, or Large - what's the best fit for your org...
Managed Services - Small, Medium, or Large - what's the best fit for your org...Managed Services - Small, Medium, or Large - what's the best fit for your org...
Managed Services - Small, Medium, or Large - what's the best fit for your org...
 
Convert manual paper-based business processes into automated paperless
Convert manual paper-based business processes into automated paperlessConvert manual paper-based business processes into automated paperless
Convert manual paper-based business processes into automated paperless
 
3 steps to successfully analyzing your PeopleSoft Security for Segregation of...
3 steps to successfully analyzing your PeopleSoft Security for Segregation of...3 steps to successfully analyzing your PeopleSoft Security for Segregation of...
3 steps to successfully analyzing your PeopleSoft Security for Segregation of...
 
Alert Framework - Alert your organization to errors, changes, and stalled tra...
Alert Framework - Alert your organization to errors, changes, and stalled tra...Alert Framework - Alert your organization to errors, changes, and stalled tra...
Alert Framework - Alert your organization to errors, changes, and stalled tra...
 
The 6 Biggest Trends for AP Leaders in 2021
The 6 Biggest Trends for AP Leaders in 2021The 6 Biggest Trends for AP Leaders in 2021
The 6 Biggest Trends for AP Leaders in 2021
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Dernier (20)

Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 

Effective Segregation of Duties for PeopleSoft 2011-02-23

  • 1. Effective Segregation of Duties for PeopleSoft SmartERP: Doris Wong, CEO; Dan White, VP of Product Strategy Q Software: Lewis Hopkins, Product Manager February 23, 2011 Webinar Recordings available at smarterp.com/webinars Our webinar will begin shortly. Please note all phone lines and computer microphones will be placed on mute throughout the presentation. Please use the GoToWebinar QUESTION feature to ask questions.
  • 2. Welcome & Introductions Doris Wong CEO, Smart ERP Solutions, Inc. Former Oracle Group VP and GM for PeopleSoft Enterprise Over 15 Years Experience with PeopleSoft Dan White VP, Product Strategy, Smart ERP Solutions, Inc. Former Oracle/PeopleSoft Functional Architect Over 12 Years Experience with PeopleSoft Lewis Hopkins Product Manager, Q Software, Ltd. Over 10 years experience in risk management, governance, and security for compliance for ERP applications
  • 3. Agenda • “Effective” Segregation of Duties (SoD) • About Smart ERP Solutions, Inc. • Smart SoD™: Effective SoD for PeopleSoft • Demo • Summary and Q & A Please note all phone lines and computer microphones will be placed on mute throughout the presentation. Please use the GoToWebinar QUESTION feature to ask questions.
  • 5. Segregation of Duties A key element in the compliance lifecycle
  • 6. Effective Segregation of Duties Proactive SoD SoD Reactive Mitigation SoD
  • 7. Characteristics/Benefits of Effective SoD • Built-in model enables SoD enforcement – Violations checked BEFORE go-live – Your decision to enforce rules or allow violations • Saves time (= money) – Easy set-up – Easy testing for violations – Quick and easy reporting – Reduces number of compensating controls required – Reduces auditing effort / costs • Reduces risk – Enforcing and reporting SoD violations reduces opportunity for fraud
  • 8. SoD – The Issues • Nothing in PeopleSoft – Any release • Use a Spreadsheet? • How do you… – Ensure the actual access control mirrors the spreadsheet? – Right people access the right data? – Manage change control problems? – Assess impact of changes? – Manage enforcement of SoD?
  • 9. Proactive SoD Aim: Prevent SoD Violations occurring during security Assignment. Ensure Security Policy is enforced long term.
  • 10. ‘Proactive’ SoD A/P “Super” Voucher Clerk Role SoD OK 1. AP Voucher clerk Violations 2. Secondary role 2 Check 3. Secondary role 3 6 Violations Segregate this task: From this task Build Security Change Role assignment Sales Order Entry Purchase Order Or Vendor Master Bank Payments Security Sales Pricing Sales Order Entry without Purchase Order Goods Receipt affecting live security Customer Master Sales Order Entry Sales Order Entry Credit limits Credit Notes Invoicing (A/R) Purchase Order Vendor Master Purchase Order Invoice entry (A/P) Vendor Master Purchase Order Vendor Master Credit Notes Invoice entry (A/P) Bank Payments Extract from pre-populated, model
  • 11. Reactive SoD Aim: Accurately assess existing security for remediation. Reduce Audit time and cost. Build case for restructuring security.
  • 12. ‘Reactive’ SoD Roles (High-Level) Permission List (Process) Components (In-depth Audit) Reporting directly on existing security
  • 13. Top 10 Rules • Creating a journal entry and opening a closed accounting period • Maintaining accounts receivable master data and posting receipts • Depositing cash and reconciling bank statements • Completing goods transfer and adjusting physical inventory counts • Approving time cards and distributing paychecks • Preparing an order and changing a billing document • Changing an order and creating a delivery • Creating a journal entry and opening a closed accounting period • Creating general ledger accounts and posting journal entries • Maintaining bank account information and posting payments • Maintaining assets and creating a goods receipt
  • 14. Creation of SoD Rules • Role level – Create matrix of all active system roles – Identify all roles that should not be linked to the same user • Such as purchasing and payments • Permission List / Business Process level – Include Application security & processing options – Add to / modify as needed • Component / Program level – Add in any custom or modified processing – If creating your own rules • Start with most important controls & gradually add to them
  • 15. SoD Logic • AND/OR Logic – Applied to rules at the component and permission list level. – The user is either in conflict with all the items in a rule (AND logic) or, – The user is in conflict with at least two items in the rule (OR logic) Example – AND Logic: Example – OR Logic: Rule 1: Rule 1: Sales Order Entry Sales Order Entry AND AND Purchase Order Purchase Order AND OR Bank Payments Bank Payments Result: Extreme Flexibility and Maximum Benefit to customers!
  • 16. Mitigation – The Issues • Current Economic Climate – Many redundancies equates to less people doing more. – Major requirement from Audit to allow remediation where a user is considered a risk. – SOX requires that during an audit all risks must at least be visible and understood by the business. – With this comes risk assessment and documentation. • Seasonal Changes – Staff holidays or time away from office requires other users be able to perform these additional duties.
  • 17. Mitigation Solutions • Ability to mitigate users once a validation has occurred. • Details of mitigation, including notes get added to a mitigation table. • The user gets checked during the next validation but is not added to the violations table. • Ability to time out mitigations, i.e. allowing for staff who are on holiday, etc.
  • 18. About Smart ERP Solutions, Inc.
  • 19. Smart ERP Solutions, Inc. Comprised of the best former developers, architects and executives from PeopleSoft/Oracle Providing cost-effective, robust and repeatable “Smart Solutions” for PeopleSoft applications Unique best practices and expertise in PeopleSoft strategic planning, Smart implementation and upgrade services KEY DIFFERENTIATOR−OUR SMARTADVANTAGE Rather than assigning teams of consultants to projects we apply our pre-built, proven solutions to efficiently address those efforts common to any PeopleSoft project thus saving time, reducing costs, minimizing risks and lowering total cost of ownership by avoiding costly difficult-to-maintain customizations.
  • 20. SmartERP: Our Philosophy Solutions • Enhance and Extend Standard PeopleSoft Functionality to Meet Business Needs – 3Cs : Common, Critical, Complementary • Repeatable, Pre-Packaged, Highly-Configurable and Innovative Solutions • Release Independence • Customer-Driven Requirements • Architected and Designed as Add-On Solutions • Lower Total Cost of Ownership – Minimal to No Customizations – Minimal Upgrade Impact • Affordable and Cost-Effective
  • 21. SmartERP: Our Solutions Business Requirements Smart Solutions Row level security on any data that requires limited or authorized access Smart Security Define , manage and enforce segregation of duties for various roles within an organization to adhere to compliance requirements Smart SoD Robust workflow approval capabilities across any business transaction or documents across your Enterprise Smart Workflow Streamlined and easy-to-use data entry pages configured to meet your specific business process requirements, incl. industry reqmts; Easily add Smart Docs including features anywhere such as Save as Draft, Copy from Templates, ERP Gadget Attachments, Configurable Print, Collaborative Comments, Workflow, User Help, Business Process View Configuring and tailoring business processes to meet your organization’s specific processes, including defining step-by-step actions for each Smart Enterprise BPM process and managing your users through your organizations specific business process. One-stop visibility into the full business process lifecycle of a transaction Smart Lifecycle Viewer Addressing additional compliance requirements not in standard PeopleSoft: I-9/W-4 Form, 1042 Foreign National Requirements Smart Compliance Manageable solutions for complex integration needs Smart Integration Packs Other Common, Critical and Complementary business requirements Tell us, we’ll build it!
  • 23. Smart SoD Summary • Developed expressly for PeopleSoft by SmartERP in cooperation with Q Q Software Software • Uniquely integrated within your SmartERP current PeopleSoft • Powerful Proactive, Reactive and Mitigation features • Built-in Smart SoD™ Analytics/Reporting/Dashboards • Use delivered SoD rules or easily create your own
  • 25. Smart SoD Demo Scenario • SoD Model and Rules • Reactive: Mass check for user violations • Proactive: Validate new user profile against established SoD rules • Dashboard/Analytics
  • 27. Value Statement Segregation of Duties is an important element of your overall PeopleSoft security and risk management Key Features of Smart SoD can help you maintain legislative compliance (SoX), meet audit requirements and reduce the likelihood and impacts of fraud and errors • Expressly designed for your current PeopleSoft • Powerful Proactive, Reactive and Mitigation Features • Automated Workflow Approvals • Reporting/Dashboards facilitate audits and compliance • Use pre-packaged built-in SoD rules or easily create your own • Add-on Architecture Lowers Total Cost of Ownership – Seamless Integration – Utilize Best Practices – Maintenance and Upgrades
  • 28. Q&A To ask a question please use the GoToMeeting QUESTION feature (please note all phone lines and computer microphones have been placed on mute). If we can’t get to your question live we will respond to you directly via email after the webinar. For more information visit: smarterp.com View Webinar Replays: smarterp.com/webinars View Solution Previews: smarterp.com/previews Copyright © 2011 Smart ERP Solutions, Inc.
  • 29. Thank You For more information visit: smarterp.com View Webinar Replays: smarterp.com/webinars View Solution Previews: smarterp.com/previews Copyright © 2011 Smart ERP Solutions, Inc.