• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Structure
  • Schedule
    • First Half of the Semester
      • Week 1: Introduction
      • Week 2: Business Process; Assertions
      • Week 3: Fraud, P2P Controls
      • Week 4: OTC Process, Types of Controls
      • Week 5: Inventory & Shipping Controls
      • Week 6: Invoicing & Collection Controls
      • Week 7: IT vs. SAP Controls, Security 1
    • Second Half of the Semester
      • Week 8: Security: Roles, Finance Process & Controls
      • Week 9: Security: User Management, Segregation of Duties
      • Week 10: Data, SOD/SAT Review
      • Week 11: Change Management, Development
      • Week 12: Auditing, Table Security, Risk / Control Framework
      • Week 13: SAP Futures, Special System Access (updated Nov 30)
      • Week 14: Character vs. Controls
  • Assignments
    • Exercise 1: Procure to Pay
    • Exercise 2: Order to Cash
    • Exercise 3: Journal Entries
    • Exercise 4: Segregation of Duties (SOD)
    • Final Exercise: Risk-Controls Framework
    • Extra Credit Assignment
  • Roster / Schedule / Teams
  • Webex
  • Gradebook

Auditing Controls in ERP Systems

ERP Systems

Week 09: Security: User Mgmt, Segregation of Duties

Week 9: Security: User Management, Segregation of Duties (SOD) Wrap-up

November 1, 2016 by Edward N Beaver

Continuing great job on the discussions – I enjoy your thoughtfulness and depth in answering.  I trust the questions help you explore and understand topics being discussed in a given week.
You raised most of the important points but let me summarize my view.

Q1: What is segregation of duties (SOD) and why is it a commonly used control?  – We discussed this topic in class.  Great examples of IT roles that should be segregated (e.g. development from DBA, development and security, development and move code, developers not in production system, development from audits).  We’ll discuss controls related to development more thoroughly in future classes.

Q2: Security in an ERP system (e.g. SAP) is complex. What is the most fuzzy, difficult to understand component?  You nailed the core issue – ERP systems are large and complex.  Therefore the security is also large and complex – especially when there are complex requirements (many people needing broad access).

Q3: What are Key competencies of person responsible for security?  I like the terms you chose.  Specifically: Skepticism and curiosity
Functional Knowledge – critical to effectively make decisions
Decision making – to which I would add good judgement.
Data analytic – I call this basic smarts.  Security is highly complex and requires strong cognitive skills.

Q4: Companies are dynamic entities. Best practices for managing system users and their security access?   You provide many great ideas including:  Password policies and procedures, documenting change (more on this in a couple weeks), periodic user access reviews, least privilege access, proper management approvals, etc.  Bottom line is that security although sometimes viewed as a backroom IT task requires strong processes to be done well.

 

Week 9: Questions

October 25, 2016 by Edward N Beaver 134 Comments

  1. What is segregation of duties and why is it a commonly used control?  Give an example of two (e.g. IT) roles that should be segregated?
  2. Security in an ERP system (e.g. SAP) is complex.  What is the most fuzzy, difficult to understand component?  Explain
  3. What key (1-2) competencies does the person responsible in a company for security (e.g. for a given process) need to have to be successful?  Why?
  4. All companies are dynamic entities with employees and others using systems coming and going all the time.  What best practices have you experienced or would you recommend for managing system users and their related security access?

Primary Sidebar

Weekly Discussions

  • Assignments (11)
  • Exams (5)
  • General (6)
  • Real World Control Failure Presentations (27)
  • Week 01: Introduction (4)
  • Week 02: Business Process; Assertions (4)
  • Week 03: Fraud, P2P Controls (2)
  • Week 04: OTC Process, Types of Controls (3)
  • Week 05: Inventory & Shipping Controls (3)
  • Week 06: Invoicing & Collection Controls (1)
  • Week 07: General IT vs. SAP Controls, Security 1 (3)
  • Week 08: Security 2, Finance 2 (2)
  • Week 09: Security: User Mgmt, Segregation of Duties (2)
  • Week 10: Data; SOD/SAT Review (2)
  • Week 11: Change Management, Development (3)
  • Week 12: Table Security, Control Framework (2)
  • Week 13: SAP Futures, Special System Access (2)
  • Week 14: Character vs. Controls (4)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in