Who's Online
0 registered (), 2 Guests and 5 Spiders online.
Key: Admin, Global Mod, Mod
Recent Posts
In which table is external learning data stored
by DMC
Yesterday at 03:43 PM
Pension Auto Enrolment
by CT
Yesterday at 09:46 AM
Vehicle Mileage Setup
by Shyam
Yesterday at 06:45 AM
11.5.10 "Extended Support" extended til..... when?
by Vigneswar Battu
17/05/12 10:59 AM
Hacking element definitions
by CT
15/05/12 08:42 AM
GB EOY reports
by Vigneswar Battu
09/05/12 02:07 PM
Oracle Payroll and Cash Management
by Vigneswar Battu
08/05/12 03:08 PM
BG setup/changes - brain dump
by Ryan
05/05/12 07:20 PM
Fusion Collateral
by CT
04/05/12 11:09 AM
BEE - ordering Batch lines
by Vigneswar Battu
03/05/12 04:22 PM
Top Posters (30 Days)
delboy 37
CT 35
Vigneswar Battu 15
pat.woodall 9
bcooper 4
Mani 3
7Giri 3
Gus 3
Ryan 3
SBi 2
(Views)Popular Topics
Family Pack K issues thread 20107
CREATE_GRADE api returns:PLS-00306: wrong number o 15174
Still trying to locate... 13817
Creating hr jobs ORA-20001: HR_289477_JOB_GROUP_ID 11848
Viewing Output of another user 10266
HR_PF.K RUP4 10240
Review of my Release 12 laptop 9703
Enhanced Retro & Release 12 9375
Adding a taskflow button to a form 9111
Family Pack K 7882
Topic Options
Rate This Topic
#111 - 09/05/05 10:01 AM Sarbanne Oxley -- the latest catch phrase
vkumar Offline
claiming squatters rights
*****

Registered: 16/03/05
Posts: 223
Loc: Fullers Brewery West London
Dear team leads and wannabe PMs . .Sarbanne Oxley desired . .Have you noticed lately that job specs come with the above requirement (especially with public sector and multi country implementations). Well here is an interesting set of things auditors are looking at . Remember that spectacled bloke in O doing healthchecks . .For the technical bods out there here is a brief checklist I came across . .Sox Rule = Applmgr account can't shared by two people. .Solution = Look at powerbroker unix account auditing. By implementing this we can share the applmgr account because you can track who is doing what. This is more powerful than shell history tracking. . . .Sox Rule = SYSADMIN user account can't be shared. .Solution = Don't de-activate the sysadmin account. Just change the password and don't release the password to anyone. Create independent accounts and grant the sysadmin responsibility. Make sure that Workfloe Admin role is set to a responsibility instead of sysadmin. Create an alert using pl/sql to monitor the SYSADMIN usage. If some tries to login as sysadmin you will get the alert. . . .Sox Rule = Multiple people are using "System Administration" Responsibility. .Solution = Enable the sign-on audit at form level. Every week-review the audit reports to make sure that authorized people are accessing the sysadmin responsibility. . .Sox Rule = Tracking the unsuccessful logins .Solution = Track the unsuccessful logins using a pl/sql monitoring alert. . .Sox Rule = Password Profiles .Solution = Make sure that hard-to-guess and min password length profiles are enabled. Make sure that password expiration set to 90 days. . .Sox Rule = Change the Oracle schema passwords .Solution = Negotiate a 30 min downtime window every quarter to change all the oracle schemas passwords in e-business environment. . .Sox Rule = Multiple people has access to the APPS schema. .Solution = Create APPSR schema with read only privileges. Grant .insert update delete privileges to APPSR from the apps schema for all .the interface & interim tables. (for ex mtl_transactions_interface etc). .Apply the latest CRM diagnostics patch so that all the BA'S and the .developers can Use the web diagnostics reports instead of sql scripts like omcheck.sql and omsellisql). . .Sox Rule = Developers has the access to functional modules .Solution = Create the read only user and read only responsibilities using CUSTOM.pll. For CRM users implement the CUSTOM roles which allows only the read privileges. . .Sox Rule = Tracking the changes to the $APPL_TOP .Solution = Implement the version Control (pvcs or startteam) . .Sox Rule = Change Control process .Solution = Implement a custom solution or mercury interactive. . . .By the way Sarbanes-Oxley is a US law passed in 2002 to strengthen Corporate governance and restore investor confidence. . .Laugh or lament

Top
#112 - 09/05/05 12:01 PM Re: Sarbanne Oxley -- the latest catch phrase
bcooper Offline

Guru
*****

Registered: 11/03/05
Posts: 1112
Loc: Earth, Europe, England, here
So is this saying that we can improve investor confidence by restricting access to APPS/ SYSADMIN etc to all us cowboy hackers! .Presumably we dont tell the investors that it cost x-million dollars to hire Sox Consultants to review and implement it all in the first place.
_________________________
HCM Aces is for sale! Please contact me if you are interested.
Also my random musings courtesy of Twitter

Top



Moderator:  Administrator, Geoff Dixon 
Forum Stats
790 Members
48 Forums
1580 Topics
7641 Posts

Max Online: 67 @ 14/04/12 05:38 PM
Today's Birthdays
No Birthdays
Recent vacancies
Top Posters
CT 1182
bcooper 1112
delboy 594
Geoff Dixon 369
SBi 356
vkumar 223
kp_rapolu 213
cbrookes 197
Gavin Harris 163
Gus 145
May
Su M Tu W Th F Sa
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31