managing segregation of duties (sod) in r3 session code: 808 donnie looper, eastman chemical company...

28
Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Post on 15-Jan-2016

219 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Managing Segregation of Duties (SOD) in R3

Session Code: 808

Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Page 2: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Goals of this session:

Managing Segregation of Duties

• What is SOD?

• SOD Challenges

• SOD Solutions

• SOD Best Practices

• Questions/Discussion

Page 3: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

What is SOD?

Managing Segregation of Duties

• SOD - “Segregation of Duties”– Most definitions include something along the

lines of: “Internal controls intended to prevent or reduce the risk of errors/fraud, identify problems, and ensure corrective action is taken.”

Page 4: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

What is SOD (continued)?

Managing Segregation of Duties

• SOD objectives:– Avoid conflicting access and reducing risk of fraud– Ensuring system stability/integrity is not at risk.

• Examples of SOD’s:– Create a Vendor & pay a Vendor– Process Sales Orders & Rebates

• Mitigating Controls (Compensating Controls):– Accept risk for situations (i.e. limited staff) by running

specialized reports or developing additional controls.

Page 5: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Goals of this session:

Managing Segregation of Duties

• What is SOD?

• SOD Challenges

• SOD Solutions

• SOD Best Practices

• Questions/Discussion

Page 6: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 7: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)– How do you build a good set of data relevant

to your needs?– How do you upgrade SOD rules in the future?

Page 8: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 9: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Automating SOD Analysis– How can you automate SOD analysis at all

levels (User, Role, Profile, Composites)?

Page 10: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 11: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Proactive/Ongoing SOD Compliance– How do you ensure that once your system is

clean it remains clean (free of SOD issues)?

Page 12: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 13: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Challenges:

Managing Segregation of Duties

• Documenting Mitigating Controls– How do you automate Risk Mitigation Controls

and use them in SOD analysis/resolution?

Page 14: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Goals of this session:

Managing Segregation of Duties

• What is SOD?

• SOD Challenges

• SOD Solutions

• SOD Best Practices

• Questions/Discussion

Page 15: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 16: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions (Building SOD Rules):

Managing Segregation of Duties

• Identify user community

• Management Support (Proactive)

• Rule Database starting point:– Vendor Supplied Rules

– Internal Control Standards For Your Company

– Information from Other Contacts (ASUG, etc…)

• Customizing rules to meet your needs

• Automate the development of rules

Page 17: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 18: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions (Automating SOD Analysis):

Managing Segregation of Duties

• A tool is needed (Ad hoc solutions don’t work)

• Tool must fully automate SOD analysis:– At the role level, user level , transaction code

level and authorization object level.

• Tool must automate SOD rule definition, validation and customization.

• Tool should provide corrective analysis.

Page 19: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 20: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions (Ongoing SOD Compliance):

Managing Segregation of Duties

• Ensure compliance when either roles are changed or assigned to users

• All additions and modifications should have “What-If” scenarios performed

• The tool should fully automate simulation and be based on live data (Users & Roles)

Page 21: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions:

Managing Segregation of Duties

• Building/Upgrading SOD Data (Rules)

• Automating SOD Analysis

• Proactive/Ongoing SOD Compliance

• Documenting Mitigating Controls

Page 22: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Solutions (Documenting Mitigating Controls):

Managing Segregation of Duties

• Tool must provide:– Online definition and documentation of the

mitigating controls– Capability to define:

• Controls at the User, Role or Rule Level• Mitigation approvers and monitors• Validity date for mitigation controls

– Analysis with/without mitigation controls

Page 23: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Goals of this session:

Managing Segregation of Duties

• What is SOD?

• SOD Challenges

• SOD Solutions

• SOD Best Practices

• Questions/Discussion

Page 24: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

SOD Best Practices:

Managing Segregation of Duties

• Identify and resolve issues at the earliest phase possible.– Once SODs creep into PRD they are more expensive

and time consuming to resolve.

• Incorporate the use of the tool into your corporate processes and procedures– Changes should be simulated prior to submission.

• Rule definition process should be optimized– All objects aren’t needed all the time.

Page 25: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Goals of this session:

Managing Segregation of Duties

• What is SOD?

• SOD Challenges

• SOD Solutions

• SOD Best Practices

• Questions/Discussion

Page 26: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Questions/Discussion:

Managing Segregation of Duties

???

Page 27: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

If you wish to contact us:

Managing Segregation of Duties

Donnie Looper:

[email protected]

Jasvir Gill:

[email protected]

Page 28: Managing Segregation of Duties (SOD) in R3 Session Code: 808 Donnie Looper, Eastman Chemical Company Jasvir Gill, Virsa Systems

Thank you for attending!Please remember to complete and return your evaluation form following this session.

Session Code: 808