Segregration of Duties
Segregration of Duties
Segregration of Duties
Sundar Venkat, Senior Manager, Protiviti Tai Tam, Accounting Manager, Electronic Arts Core Competencies C23
Page 0 of 29
Agenda
Introductions Overview and Session Objectives Common Issues in Security Design Top-Down SoD, Security Design Methodology and benefits About Electronic Arts Project Meridian Background and Security Design Automation of Segregation of Duties (SoD) Monitoring using Oracle AACG Automation of Security Build Q&A
Page 1 of 29
Introductions
Protiviti
Sundar Venkat, Senior Manager Over 10 years of experience in ERP Implementation, Security and GRC Design
Electronic Arts
Tai Tam, Accounting Manager Global lead for Segregation of Duties. Over 15 years of experience in the Industry, working in various capacities in Finance, Audit and Compliance
Page 2 of 29
Page 3 of 29
No direct relationship between formal SoD policies and Oracle Responsibilities. Oracle Responsibilities are defined based on limited design of SoD rules. Oracle Responsibilities are not conflict-free. One-off results in each SoD test cycle. Heavy manual controls.
Bottom-up
Page 5 of 29
Top down
Page 7 of 29
Business Rules
Business System
Oracle Responsibilities
Authorized Conflicts
Model Users
Real Users
Page 8 of 29
SoD Policy
SoD Elements
Benefits
Provides a business view of Oracle Responsibilities and uses business-user friendly language. Oracle Functions are grouped into a brief list of business activities. The Design templates provide easy drill-down to Oracle Functions from business activities. Custom Responsibilities and Request Groups are designed based on business activities. The Design includes Responsibility and Request Group matrices showing SoD conflicts.
Page 12 of 29
Page 13 of 29
Page 14 of 29
Assign FND Profile Options to responsibilities Assign Security Profiles to responsibilities Assign Multi Organization Access Controls (MOAC) Assign Inventory Organizations to responsibilities
Page 16 of 29
Page 17 of 29
Page 18 of 29
Oracle Infrastructure
Phase 1 Deploy following Oracle modules in R12 Procurement: iClick + iExpense & iProcurement Finance : General Ledger, Accounts Payable, Indirect Purchasing, Fixed Assets Phase 2 Deploy following Oracle modules in R12 Publishing : Inventory, Order Management, Pricing, Supply Chain Finance: AR, Trade Management, Advanced Collection, Costing Online Publishing (Digital Order to Cash)
Meridian
Minimize SoD Risks on Oracle R12 custom responsibilities using the SoD Rule-set as a basis
Page 21 of 29
Page 22 of 29
Page 23 of 29
Page 24 of 29
Page 25 of 29
Page 26 of 29
Stores a repository of SoD rules for Oracle Ebusiness suite across Financials, Procure to Pay, Order to Cash, Human Resources, etc. Identifies SoD conflicts based on Oracle ERP environment
Provides the ability to configure exceptions
Reporting
Detects what access users have and what users can do; generates conflict reports for both within Oracle responsibility and multiple responsibilities assigned to users Acts as an effective monitoring tool and helps prevent fraud by limiting what users can do
Page 28 of 29
Continuous Monitoring
Q&A
Page 29 of 29