SlideShare uma empresa Scribd logo
1 de 32
Baixar para ler offline
Fraud	
  &	
  it’s	
  part	
  in	
  YOUR	
  downfall	
  
                           	
  
                MIKE	
  WARD	
  
              Managing	
  Director	
  
                           	
  
                           	
  
                           	
  
                           	
  
                The most comprehensive Oracle applications & technology content under one roof
If	
  your	
  job	
  was	
  at	
  stake.....	
  
	
  
Can	
  you	
  with	
  certainty	
  state	
  that	
  users	
  
     of	
  your	
  Oracle	
  erp	
  system	
  are	
  locked	
  
     out	
  of	
  the	
  areas	
  they	
  should	
  not	
  be	
  
     able	
  to	
  see?	
  



                          The most comprehensive Oracle applications & technology content under one roof
The most comprehensive Oracle applications & technology content under one roof
Agenda	
  
•  Q	
  SoEware:	
  Who	
  are	
  we?	
  
•  What	
  are	
  the	
  Problems?	
  
    –  Fraud	
  &	
  Compliance	
  
•  Key	
  QuesKons?	
  
•  Summary	
  &	
  QuesKons	
  
	
  




                    The most comprehensive Oracle applications & technology content under one roof
 	
  	
  	
  	
  	
  	
  The	
  Oracle	
  Security	
  &	
  Compliance	
  People	
  




                                                                   270+ Customers



                                The most comprehensive Oracle applications & technology content under one roof
Agenda	
  
•  Q	
  SoEware:	
  Who	
  are	
  we?	
  
•  What	
  are	
  the	
  Problems?	
  
    –  Fraud	
  &	
  Compliance	
  
•  Key	
  QuesKons	
  
•  Summary	
  &	
  QuesKons	
  
	
  




                        The most comprehensive Oracle applications & technology content under one roof
Fraud	
  will	
  never	
  happen	
  to	
  You	
  
•  75%	
  of	
  fraud	
  is	
  due	
  to	
  ineffecKve	
  internal	
  
   controls,	
  split	
  between	
  	
  
    –  Lack	
  of	
  controls	
  38%	
  
    –  Over	
  riding	
  controls	
  19%	
  
    –  Lack	
  of	
  management	
  review	
  18%	
  
•  80%	
  of	
  businesses	
  modify	
  controls	
  aEer	
  Fraud	
  
                  AssociaKon	
  of	
  CerKfied	
  Fraud	
  Examiners	
  




                                 The most comprehensive Oracle applications & technology content under one roof
It	
  doesn’t	
  happen	
  here.......	
  
 UK: Canada:61% admit businesses suffered crime
 NewSouth 50% largesuffered “significant fraud
  Germany: 55% companieseconomicfraud
USA:almost Africa: 62%persuffering fraud
      35% companies to business suffered
                                  companies
        Zealand: 42% suffered suffered crime
      almost83%incidents experiencedmost common
      -  Average 8 - average cost $491,000
economic crime”asset misappropriation bribery &
                - 75% of 59% (5,000+ employees)
                       -    larger
      - Average cost 40% suffered economic crime
         Australia: of sufferedchancemilliontip-off
        -
          -most 38% detected by 100 incidentsEuros
                            crime cost 4.2
             increasingly corruption or by
           -33% of these by middle / senior management
                - likely cause is pressure due to economy
                  Source: PwC 2009 fraud survey Crime survey
        Source: PwCopportunitySource: PwC driver survey
                                               2009
       - increased 2009Source: PwCPwC 2009 crime survey
                          fraud Source: 2009 Crimecrime
                              Source: PwC 2009 survey
                                survey
                                  is primary
                       Source: PwC 2009 crime survey




                      The most comprehensive Oracle applications & technology content under one roof
Security	
  Creep	
  

•  Ex-­‐employees	
  sKll	
  have	
  access	
  
•  Changes	
  to	
  business	
  processes	
  
•  OrganisaKonal	
  &	
  process	
  changes	
  
•  Upgrades.........	
                                                  Task 8

                                                                 Risk   Task 7

                                                          Task 6        Task 6



	
  
                                                          Task 5        Task 5

                                                          Task 4        Task 4
                                                        Task 4
                         Task 3                                         Task 3
                                                        Task 3

                                            Task 2      Task 2 2
                                                          Task          Task 2

                                            Task 1      Task 1 1
                                                          Task          Task 1
                                                                           Task 1


                                                                 Time
                  The most comprehensive Oracle applications & technology content under one roof
•  VP	
  in	
  Finance	
  Department	
  
•  July	
  –	
  December	
  2010	
  
•  Stole	
  $19m	
  
 “Defendant	
  bought	
  a	
  Masera3,	
  6	
  Proper3es,	
  
           and	
  a	
  $½m	
  entertainment	
  system”	
  
                  “Excessive	
  Access	
  Rights”	
  



                      The most comprehensive Oracle applications & technology content under one roof
SegregaKon	
  of	
  DuKes	
  (SoD)	
  
                               Jones & Jones Inc.

                              A Manager
                              Sets up MB Inc. as a supplier

Accepts Purchase Invoices from MB Inc.
      Approves Invoices
               Processes for Payment
                        Transfers the funds
  Runs	
  off	
  with	
  £1m	
  

                         The most comprehensive Oracle applications & technology content under one roof
Deloiee	
  –	
  Auditor	
  Survey	
  
•  3	
  Most	
  Common	
  Frauds	
  
   –  MisappropriaKon	
  of	
  Assets	
  –	
  31%	
  
   –  Improper	
  Expenditures	
  –	
  22%	
  
   –  Procurement	
  Fraud	
  –	
  16%	
  
•  63%	
  companies	
  say	
  vulnerability	
  has	
  increased	
  
•  83%	
  UK	
  companies	
  had	
  suffered	
  fraud	
  



                             The most comprehensive Oracle applications & technology content under one roof
Agenda	
  
•  Q	
  SoEware:	
  Who	
  are	
  we?	
  
•  What	
  are	
  the	
  Problems?	
  
    –  Fraud	
  &	
  Compliance	
  
•  Key	
  QuesKons	
  
•  Summary	
  &	
  QuesKons	
  
	
  




                        The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  What	
  is	
  it?	
  
•  	
  …no	
  single	
  individual	
  should	
  have	
  control	
  
   over	
  two	
  or	
  more	
  phases	
  of	
  a	
  transacKon	
  or	
  
   operaKon…	
  
  	
  (University	
  of	
  Utah	
  Department	
  of	
  Internal	
  Audit	
  IdenKfy	
  the	
  DuKes)	
  


	
  
•  …no	
  one	
  individual	
  employee	
  can	
  complete	
  
     a	
  significant	
  business	
  transacKon	
  in	
  its	
  
     enKrety…	
  
  	
  (UCSD	
  Audit	
  &	
  Management	
  Advisory	
  Services)	
  




                                                                   The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  What	
  is	
  it?	
  
Examples	
  Include	
  …..	
  
    	
  
§  Those	
  responsible	
  for	
  physical	
  receipt	
  of	
  goods	
  should	
  
    not	
  be	
  responsible	
  for	
  paying	
  for	
  the	
  goods.	
  

§  Those	
  responsible	
  for	
  custody	
  of	
  goods	
  	
  

§  should	
  not	
  be	
  responsible	
  for	
  maintaining	
  the	
  records	
  of	
  
    the	
  assets.	
  

§  Those	
  responsible	
  for	
  collecEon	
  of	
  receivables	
  should	
  
    not	
  be	
  responsible	
  for	
  entries	
  in	
  the	
  book	
  of	
  accounts.	
  
                                                                                                             Source:	
  	
  
                                                                                    Sawyer’s	
  Internal	
  AudiEng	
  
                                                                                        5th	
  EdiEon,	
  page	
  1198	
  




                                      The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  EBS	
  
                    •  Monitoring	
  ApplicaKon	
  Controls	
  
                         –  e.g.	
  Post	
  Journal	
  Approval	
  –	
  Journal	
  
Application Layer

                            Sources	
  
                    •  Lack	
  of	
  Audit	
  All	
  
                         –  Certain	
  Forms	
  without	
  Audit	
  Trail	
  
                    •  Inability	
  to	
  audit	
  WHAT	
  	
  
                    •  Data	
  Growth	
  
                    •  UnintuiKve	
  info	
  
                         –  Vendor	
  ID,	
  Cust	
  ID	
  
                         –  Same	
  with	
  Log	
  based	
  soluKons	
  



                                        The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  EBS	
  
                                     •  SensiKve	
  InformaKon	
  
Application Layer
                                        –  e.g.	
  Employee	
  Bank	
  Info,	
  NI	
  #	
  
                    Database Layer      –  MulKple	
  Forms	
  
                                             •  Different	
  Views	
  of	
  Same	
  Info	
  
                                        –  SQL	
  Forms	
  
                                        –  Request	
  Groups	
  
                                        –  External	
  ReporKng	
  SoluKons	
  
                                        –  Hiding/Masking	
  impacts	
  
                                           ApplicaKons	
  
                                        –  SegregaKon	
  Policies	
  difficult	
  to	
  
                                           enforce	
  


                                          The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  Principles	
  
1.    Least	
  Privilege	
  Rule	
  
2.    Access	
  to	
  fulfill	
  a	
  job	
  funcKon	
  
3.    Minimise	
  Risks	
  to	
  SensiKve	
  FuncKons	
  
4.    Segregate	
  Roles	
  in	
  CriKcal	
  Processes	
  
5.    Monitor	
  known	
  high	
  risks	
  
6.    Use	
  Tools	
  



                           The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  What	
  to	
  do?	
  
•  But	
  use	
  the	
  right	
  tools!	
  
      –    PrevenKon	
  
      –    DetecKon	
  
      –    Approval	
  Process	
  
      –    MiKgaKon	
  Handling	
  
      –    False	
  PosiKve	
  Handling	
  
•  And	
  look	
  for	
  lower	
  TCO	
  
      –    Embedded	
  into	
  EBS	
  
      –    No	
  addiKonal	
  Hardware	
  
      –    Rapid	
  ImplementaKon	
  
      –    Quick	
  InstallaKon	
  




                                         The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD	
  




Access	
  Control	
  AudiEng	
  
   Ø 	
  	
  Full	
  audit	
  trail	
  

   Ø 	
  	
  TransacKon	
  Data	
  

   Ø 	
  	
  Enquire	
  &	
  Report	
  




               The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD	
  




  	
  	
  	
  
  SoD	
  ImplementaEon	
  	
  	
  	
  
  Ø 	
  	
  Real	
  Kme	
  SoD	
  controls	
  	
  	
  

  Ø 	
  	
  Approvals	
  	
  	
  

  Ø 	
  	
  What	
  if	
  Analysis	
  

  Ø 	
  	
  ReporKng	
  



              The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD	
  




	
  
Implement	
  Complex	
  Security	
  
Ø 	
  	
  Data	
  SegregaKon	
  

Ø 	
  	
  Data	
  Masking	
  	
  

Ø 	
  	
  Dynamic	
  Security	
  Policies	
  




              The most comprehensive Oracle applications & technology content under one roof
Agenda	
  
•  Q	
  SoEware:	
  Who	
  are	
  we?	
  
•  What	
  are	
  the	
  Problems?	
  
    –  Fraud	
  &	
  Compliance	
  
•  Case	
  Studies	
  
•  Summary	
  &	
  QuesKons	
  
	
  




                        The most comprehensive Oracle applications & technology content under one roof
QsoEware	
  SoluKon	
  

•    DetecKve	
  SoD	
  
•    PrevenKve	
  SoD	
  
•    Blanket	
  FuncKon	
  Lockout	
  
•    Trend	
  InformaKon	
  
•    Integrated	
  	
  
•    Rapid	
  ImplementaKon	
  
•    Pre-­‐Seeded	
  Content	
  


                    The most comprehensive Oracle applications & technology content under one roof
Key	
  audit	
  quesKons:	
  
•  Who	
  is	
  in	
  violaKon	
  of	
  SoD	
  rules?	
  
     –  &	
  how?	
  
•  What	
  programs	
  can	
  a	
  user	
  access?	
  
     –  &	
  with	
  what	
  authoriKes?	
  
•  Who	
  can	
  access	
  a	
  parKcular	
  program?	
  
     –  &	
  with	
  what	
  authoriKes?	
  
•  Who	
  can	
  access	
  criKcal	
  programs?	
  
     –  Such	
  as	
  Address	
  Book	
  Master	
  Maintenance,	
  Bank	
  
        Payments	
  and	
  Credit	
  Limits	
  
•  Who	
  can	
  access	
  Master	
  Data?	
  
     –  Such	
  as	
  AutomaKc	
  AccounKng	
  InstrucKons,	
  Bank	
  
        Account	
  details,	
  Chart	
  of	
  Accounts	
  	
  
•  What	
  security	
  sesngs	
  does	
  a	
  parKcular	
  user	
  have?	
  

                                  The most comprehensive Oracle applications & technology content under one roof
Solve	
  Business	
  Problems	
  with	
  Good	
  Security	
  
•    Audit	
  Security	
  –	
  KNOW	
  your	
  status	
  
•    Map	
  Security	
  to	
  Business	
  Processes	
  
•    Build	
  in	
  SoD	
  
•    Make	
  Security	
  more	
  Manageable	
  	
  
  	
  	
  &	
  Reduce	
  Costs	
  
•  Consider	
  Outsourcing	
  	
  
  	
  	
  Security	
  Management	
  
•  Compliance	
  Management	
  	
  
  	
  	
   	
   	
  &	
  ReporKng	
  


                            The most comprehensive Oracle applications & technology content under one roof
SegregaKon	
  of	
  Duty	
  Issues	
  
•    Spread-­‐sheets	
                         No	
  Integrity	
  
•    Queries	
                                 No	
  Accuracy	
  
•    Manual	
  Review	
                        Time	
  consuming	
  
•    Responsibility	
  level	
  SoD	
          Omits	
  key	
  risks	
  (needs	
  to	
  be	
  at	
  
                                               the	
  FuncKon	
  level)	
  

•  Periodic	
  Reviews	
                       Risk	
  between	
  reviews	
  
•  External	
  SoluKons	
                      High	
  Cost	
  




                                 The most comprehensive Oracle applications & technology content under one roof
EffecKve	
  control	
  of	
  SOD:	
  Reduce	
  Costs	
  
 •  Tools	
  reduce	
  Cost	
  of	
  CorrecKng	
  Errors….	
  
     –  Prevent	
  Unwanted	
  Access	
  
     –  Approval	
  Process	
  
     –  MiKgaKon	
  Handling	
  
     –  False	
  PosiKve	
  Handling	
  
 •  Reduced	
  Staff	
  Time……	
  
     –  Embedded	
  into	
  EBS	
  
     –  No	
  addiKonal	
  Hardware	
  
     –  Rapid	
  ImplementaKon	
  of	
  Complex	
  Security	
  
     –  No	
  impact	
  on	
  Upgrades	
  



                           The most comprehensive Oracle applications & technology content under one roof
SegregaKon	
  of	
  DuKes	
  (SoD)	
  
                               Jones & Jones Inc.

                              A Manager
                              Sets up MB Inc. as a supplier

Accepts Purchase Invoices from MB Inc.
      Approves Invoices
               Processes for Payment
                        Transfers the funds
  Runs	
  off	
  with	
  £1m	
  

                         The most comprehensive Oracle applications & technology content under one roof
SegregaKon	
  of	
  DuKes	
  (SoD)	
  
                               Jones & Jones Inc.

                              A Manager
                              Sets up MB Inc. as a supplier

Accepts Purchase Invoices from MB Inc.
      Approves Invoices
               Processes for Payment
                        Transfers the funds
  Runs	
  off	
  with	
  £1m	
  

                         The most comprehensive Oracle applications & technology content under one roof
QuesKons?	
  




  The most comprehensive Oracle applications & technology content under one roof
Have	
  pity	
  on	
  the	
  homeland.....	
  




                 The most comprehensive Oracle applications & technology content under one roof

Mais conteúdo relacionado

Semelhante a E-Business Suite 2 _ Mike Ward _ Fraud and its part in your downfall.pdf

JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdf
JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdfJDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdf
JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdfInSync2011
 
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...InSync2011
 
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...InSync2011
 
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdf
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdfNew & Emerging _ David Gresham _ Building and Event Driven Architecture.pdf
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdfInSync2011
 
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...InSync2011
 
Wendy Nather - Building a Rube Goldberg Application Security Program
Wendy Nather - Building a Rube Goldberg Application Security ProgramWendy Nather - Building a Rube Goldberg Application Security Program
Wendy Nather - Building a Rube Goldberg Application Security ProgramSource Conference
 
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...InSync2011
 
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...InSync2011
 
Application Security Done Right
Application Security Done RightApplication Security Done Right
Application Security Done Rightpvanwoud
 
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdf
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdfPrimavera _ Richard Houghton _ Integrated Project Control Systems.pdf
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdfInSync2011
 
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdf
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdfReporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdf
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdfInSync2011
 
Open Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureOpen Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureWhiteSource
 
Open Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureOpen Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureDevOps.com
 
SCADA Software or Swiss Cheese Software - CODE BLUE, Japan
SCADA Software or Swiss Cheese Software - CODE BLUE, JapanSCADA Software or Swiss Cheese Software - CODE BLUE, Japan
SCADA Software or Swiss Cheese Software - CODE BLUE, JapanSignalSEC Ltd.
 
EAS-SEC Project
EAS-SEC ProjectEAS-SEC Project
EAS-SEC ProjectERPScan
 
Oracle PeopleSoft applications are under attack (HITB AMS)
Oracle PeopleSoft applications are under attack (HITB AMS)Oracle PeopleSoft applications are under attack (HITB AMS)
Oracle PeopleSoft applications are under attack (HITB AMS)ERPScan
 
AMIS 25: DevOps Best Practice for Oracle SOA and BPM
AMIS 25: DevOps Best Practice for Oracle SOA and BPMAMIS 25: DevOps Best Practice for Oracle SOA and BPM
AMIS 25: DevOps Best Practice for Oracle SOA and BPMMatt Wright
 
Oracle PeopleSoft applications are under attacks (Hack in Paris)
Oracle PeopleSoft applications are under attacks (Hack in Paris)Oracle PeopleSoft applications are under attacks (Hack in Paris)
Oracle PeopleSoft applications are under attacks (Hack in Paris)ERPScan
 
SCADA Software or Swiss Cheese Software?  by Celil UNUVER
SCADA Software or Swiss Cheese Software?  by Celil UNUVERSCADA Software or Swiss Cheese Software?  by Celil UNUVER
SCADA Software or Swiss Cheese Software?  by Celil UNUVERCODE BLUE
 

Semelhante a E-Business Suite 2 _ Mike Ward _ Fraud and its part in your downfall.pdf (20)

JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdf
JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdfJDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdf
JDE & Peoplesoft 2 _ Mike Ward _ Security implications of Upgrading JDE.pdf
 
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...
New & Emerging _ Soner Bekir _ The 5 most common pitfalls when implementing E...
 
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...
JD Edwards & Peoplesoft 1 _ Basheer Khan _ Fusion apps overview form an imple...
 
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdf
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdfNew & Emerging _ David Gresham _ Building and Event Driven Architecture.pdf
New & Emerging _ David Gresham _ Building and Event Driven Architecture.pdf
 
Webinar: "La supply chain del software vista a raggi X"
Webinar: "La supply chain del software vista a raggi X" Webinar: "La supply chain del software vista a raggi X"
Webinar: "La supply chain del software vista a raggi X"
 
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...
JD Edwards & Peoplesoft 2 _ Mark Elley _ Real word experiences disaster recov...
 
Wendy Nather - Building a Rube Goldberg Application Security Program
Wendy Nather - Building a Rube Goldberg Application Security ProgramWendy Nather - Building a Rube Goldberg Application Security Program
Wendy Nather - Building a Rube Goldberg Application Security Program
 
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...
Reporting _ Darrell Hawkes _ Operational Information - The Business Case for ...
 
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...
JDE & Peoplesoft 3 _ Sumedh Vipradas _ Reduce Invoice Processing Costs and Cy...
 
Application Security Done Right
Application Security Done RightApplication Security Done Right
Application Security Done Right
 
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdf
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdfPrimavera _ Richard Houghton _ Integrated Project Control Systems.pdf
Primavera _ Richard Houghton _ Integrated Project Control Systems.pdf
 
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdf
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdfReporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdf
Reporting _ Rick Cooper _ Planning and budgeting with QUT and Hyperion.pdf
 
Open Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureOpen Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure Culture
 
Open Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure CultureOpen Source Security: How to Lay the Groundwork for a Secure Culture
Open Source Security: How to Lay the Groundwork for a Secure Culture
 
SCADA Software or Swiss Cheese Software - CODE BLUE, Japan
SCADA Software or Swiss Cheese Software - CODE BLUE, JapanSCADA Software or Swiss Cheese Software - CODE BLUE, Japan
SCADA Software or Swiss Cheese Software - CODE BLUE, Japan
 
EAS-SEC Project
EAS-SEC ProjectEAS-SEC Project
EAS-SEC Project
 
Oracle PeopleSoft applications are under attack (HITB AMS)
Oracle PeopleSoft applications are under attack (HITB AMS)Oracle PeopleSoft applications are under attack (HITB AMS)
Oracle PeopleSoft applications are under attack (HITB AMS)
 
AMIS 25: DevOps Best Practice for Oracle SOA and BPM
AMIS 25: DevOps Best Practice for Oracle SOA and BPMAMIS 25: DevOps Best Practice for Oracle SOA and BPM
AMIS 25: DevOps Best Practice for Oracle SOA and BPM
 
Oracle PeopleSoft applications are under attacks (Hack in Paris)
Oracle PeopleSoft applications are under attacks (Hack in Paris)Oracle PeopleSoft applications are under attacks (Hack in Paris)
Oracle PeopleSoft applications are under attacks (Hack in Paris)
 
SCADA Software or Swiss Cheese Software?  by Celil UNUVER
SCADA Software or Swiss Cheese Software?  by Celil UNUVERSCADA Software or Swiss Cheese Software?  by Celil UNUVER
SCADA Software or Swiss Cheese Software?  by Celil UNUVER
 

Mais de InSync2011

Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...
Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...
Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...InSync2011
 
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdf
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdfNew & Emerging _ KrisDowney _ Simplifying the Change Process.pdf
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdfInSync2011
 
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdf
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdfOracle Systems _ Kevin McIsaac _The IT landscape has changed.pdf
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdfInSync2011
 
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfReporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfInSync2011
 
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...InSync2011
 
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...InSync2011
 
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...InSync2011
 
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...InSync2011
 
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...InSync2011
 
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdf
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdfDatabase & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdf
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdfInSync2011
 
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdf
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdfDatabase & Technology 1 _ Tom Kyte _ SQL Techniques.pdf
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdfInSync2011
 
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...InSync2011
 
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...InSync2011
 
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...InSync2011
 
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...InSync2011
 
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...InSync2011
 
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...InSync2011
 
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...InSync2011
 
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...InSync2011
 
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...InSync2011
 

Mais de InSync2011 (20)

Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...
Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...
Developer & Fusion Middleware 2 _ Scott Robertson _ SOA, Portals and Enterpri...
 
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdf
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdfNew & Emerging _ KrisDowney _ Simplifying the Change Process.pdf
New & Emerging _ KrisDowney _ Simplifying the Change Process.pdf
 
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdf
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdfOracle Systems _ Kevin McIsaac _The IT landscape has changed.pdf
Oracle Systems _ Kevin McIsaac _The IT landscape has changed.pdf
 
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdfReporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
Reporting _ Scott Tunbridge _ Op Mgmt to Perf Excel.pdf
 
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...
Developer and Fusion Middleware 2 _ Scott Robertson _ SOA, portals and entepr...
 
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...
Primavera _ Loretta Bayliss _ Implementing EPPM in rapidly changing and compe...
 
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...
Database & Technology 1 _ Martin Power _ Delivering Oracles hight availabilit...
 
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...
Database & Technology 1 _ Craig Shallahamer _ Unit of work time based perform...
 
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...
Database & Technology 1 _ Marcelle Kratchvil _ Why you should be storing unst...
 
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdf
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdfDatabase & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdf
Database & Technology 1 _ Milina Ristic _ Why use oracle data guard.pdf
 
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdf
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdfDatabase & Technology 1 _ Tom Kyte _ SQL Techniques.pdf
Database & Technology 1 _ Tom Kyte _ SQL Techniques.pdf
 
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...
Database & Technology 1 _ Clancy Bufton _ Flashback Query - oracle total reca...
 
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...
Databse & Technology 2 _ Francisco Munoz Alvarez _ Oracle Security Tips - Som...
 
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...
Databse & Technology 2 _ Francisco Munoz alvarez _ 11g new functionalities fo...
 
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...
Databse & Technology 2 | Connor McDonald | Managing Optimiser Statistics - A ...
 
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...
Databse & Technology 2 _ Shan Nawaz _ Oracle 11g Top 10 features - not your u...
 
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...
Databse & Technology 2 _ Paul Guerin _ The biggest looser database - a boot c...
 
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...
Developer and Fusion Middleware 1 _ Kevin Powe _ Log files - a wealth of fore...
 
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...
Developer and Fusion Middleware 2 _ Aaron Blishen _ Event driven SOA Integrat...
 
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...
Developer and Fusion Middleware 2 _Greg Kirkendall _ How Australia Post teach...
 

E-Business Suite 2 _ Mike Ward _ Fraud and its part in your downfall.pdf

  • 1. Fraud  &  it’s  part  in  YOUR  downfall     MIKE  WARD   Managing  Director           The most comprehensive Oracle applications & technology content under one roof
  • 2. If  your  job  was  at  stake.....     Can  you  with  certainty  state  that  users   of  your  Oracle  erp  system  are  locked   out  of  the  areas  they  should  not  be   able  to  see?   The most comprehensive Oracle applications & technology content under one roof
  • 3. The most comprehensive Oracle applications & technology content under one roof
  • 4. Agenda   •  Q  SoEware:  Who  are  we?   •  What  are  the  Problems?   –  Fraud  &  Compliance   •  Key  QuesKons?   •  Summary  &  QuesKons     The most comprehensive Oracle applications & technology content under one roof
  • 5.              The  Oracle  Security  &  Compliance  People   270+ Customers The most comprehensive Oracle applications & technology content under one roof
  • 6. Agenda   •  Q  SoEware:  Who  are  we?   •  What  are  the  Problems?   –  Fraud  &  Compliance   •  Key  QuesKons   •  Summary  &  QuesKons     The most comprehensive Oracle applications & technology content under one roof
  • 7. Fraud  will  never  happen  to  You   •  75%  of  fraud  is  due  to  ineffecKve  internal   controls,  split  between     –  Lack  of  controls  38%   –  Over  riding  controls  19%   –  Lack  of  management  review  18%   •  80%  of  businesses  modify  controls  aEer  Fraud   AssociaKon  of  CerKfied  Fraud  Examiners   The most comprehensive Oracle applications & technology content under one roof
  • 8. It  doesn’t  happen  here.......   UK: Canada:61% admit businesses suffered crime NewSouth 50% largesuffered “significant fraud Germany: 55% companieseconomicfraud USA:almost Africa: 62%persuffering fraud 35% companies to business suffered companies Zealand: 42% suffered suffered crime almost83%incidents experiencedmost common -  Average 8 - average cost $491,000 economic crime”asset misappropriation bribery & - 75% of 59% (5,000+ employees) - larger - Average cost 40% suffered economic crime Australia: of sufferedchancemilliontip-off - -most 38% detected by 100 incidentsEuros crime cost 4.2 increasingly corruption or by -33% of these by middle / senior management - likely cause is pressure due to economy Source: PwC 2009 fraud survey Crime survey Source: PwCopportunitySource: PwC driver survey 2009 - increased 2009Source: PwCPwC 2009 crime survey fraud Source: 2009 Crimecrime Source: PwC 2009 survey survey is primary Source: PwC 2009 crime survey The most comprehensive Oracle applications & technology content under one roof
  • 9. Security  Creep   •  Ex-­‐employees  sKll  have  access   •  Changes  to  business  processes   •  OrganisaKonal  &  process  changes   •  Upgrades.........   Task 8 Risk Task 7 Task 6 Task 6   Task 5 Task 5 Task 4 Task 4 Task 4 Task 3 Task 3 Task 3 Task 2 Task 2 2 Task Task 2 Task 1 Task 1 1 Task Task 1 Task 1 Time The most comprehensive Oracle applications & technology content under one roof
  • 10. •  VP  in  Finance  Department   •  July  –  December  2010   •  Stole  $19m   “Defendant  bought  a  Masera3,  6  Proper3es,   and  a  $½m  entertainment  system”   “Excessive  Access  Rights”   The most comprehensive Oracle applications & technology content under one roof
  • 11. SegregaKon  of  DuKes  (SoD)   Jones & Jones Inc. A Manager Sets up MB Inc. as a supplier Accepts Purchase Invoices from MB Inc. Approves Invoices Processes for Payment Transfers the funds Runs  off  with  £1m   The most comprehensive Oracle applications & technology content under one roof
  • 12. Deloiee  –  Auditor  Survey   •  3  Most  Common  Frauds   –  MisappropriaKon  of  Assets  –  31%   –  Improper  Expenditures  –  22%   –  Procurement  Fraud  –  16%   •  63%  companies  say  vulnerability  has  increased   •  83%  UK  companies  had  suffered  fraud   The most comprehensive Oracle applications & technology content under one roof
  • 13. Agenda   •  Q  SoEware:  Who  are  we?   •  What  are  the  Problems?   –  Fraud  &  Compliance   •  Key  QuesKons   •  Summary  &  QuesKons     The most comprehensive Oracle applications & technology content under one roof
  • 14. EffecKve  control  of  SOD:  What  is  it?   •   …no  single  individual  should  have  control   over  two  or  more  phases  of  a  transacKon  or   operaKon…    (University  of  Utah  Department  of  Internal  Audit  IdenKfy  the  DuKes)     •  …no  one  individual  employee  can  complete   a  significant  business  transacKon  in  its   enKrety…    (UCSD  Audit  &  Management  Advisory  Services)   The most comprehensive Oracle applications & technology content under one roof
  • 15. EffecKve  control  of  SOD:  What  is  it?   Examples  Include  …..     §  Those  responsible  for  physical  receipt  of  goods  should   not  be  responsible  for  paying  for  the  goods.   §  Those  responsible  for  custody  of  goods     §  should  not  be  responsible  for  maintaining  the  records  of   the  assets.   §  Those  responsible  for  collecEon  of  receivables  should   not  be  responsible  for  entries  in  the  book  of  accounts.   Source:     Sawyer’s  Internal  AudiEng   5th  EdiEon,  page  1198   The most comprehensive Oracle applications & technology content under one roof
  • 16. EffecKve  control  of  SOD:  EBS   •  Monitoring  ApplicaKon  Controls   –  e.g.  Post  Journal  Approval  –  Journal   Application Layer Sources   •  Lack  of  Audit  All   –  Certain  Forms  without  Audit  Trail   •  Inability  to  audit  WHAT     •  Data  Growth   •  UnintuiKve  info   –  Vendor  ID,  Cust  ID   –  Same  with  Log  based  soluKons   The most comprehensive Oracle applications & technology content under one roof
  • 17. EffecKve  control  of  SOD:  EBS   •  SensiKve  InformaKon   Application Layer –  e.g.  Employee  Bank  Info,  NI  #   Database Layer –  MulKple  Forms   •  Different  Views  of  Same  Info   –  SQL  Forms   –  Request  Groups   –  External  ReporKng  SoluKons   –  Hiding/Masking  impacts   ApplicaKons   –  SegregaKon  Policies  difficult  to   enforce   The most comprehensive Oracle applications & technology content under one roof
  • 18. EffecKve  control  of  SOD:  Principles   1.  Least  Privilege  Rule   2.  Access  to  fulfill  a  job  funcKon   3.  Minimise  Risks  to  SensiKve  FuncKons   4.  Segregate  Roles  in  CriKcal  Processes   5.  Monitor  known  high  risks   6.  Use  Tools   The most comprehensive Oracle applications & technology content under one roof
  • 19. EffecKve  control  of  SOD:  What  to  do?   •  But  use  the  right  tools!   –  PrevenKon   –  DetecKon   –  Approval  Process   –  MiKgaKon  Handling   –  False  PosiKve  Handling   •  And  look  for  lower  TCO   –  Embedded  into  EBS   –  No  addiKonal  Hardware   –  Rapid  ImplementaKon   –  Quick  InstallaKon   The most comprehensive Oracle applications & technology content under one roof
  • 20. EffecKve  control  of  SOD   Access  Control  AudiEng   Ø     Full  audit  trail   Ø     TransacKon  Data   Ø     Enquire  &  Report   The most comprehensive Oracle applications & technology content under one roof
  • 21. EffecKve  control  of  SOD         SoD  ImplementaEon         Ø     Real  Kme  SoD  controls       Ø     Approvals       Ø     What  if  Analysis   Ø     ReporKng   The most comprehensive Oracle applications & technology content under one roof
  • 22. EffecKve  control  of  SOD     Implement  Complex  Security   Ø     Data  SegregaKon   Ø     Data  Masking     Ø     Dynamic  Security  Policies   The most comprehensive Oracle applications & technology content under one roof
  • 23. Agenda   •  Q  SoEware:  Who  are  we?   •  What  are  the  Problems?   –  Fraud  &  Compliance   •  Case  Studies   •  Summary  &  QuesKons     The most comprehensive Oracle applications & technology content under one roof
  • 24. QsoEware  SoluKon   •  DetecKve  SoD   •  PrevenKve  SoD   •  Blanket  FuncKon  Lockout   •  Trend  InformaKon   •  Integrated     •  Rapid  ImplementaKon   •  Pre-­‐Seeded  Content   The most comprehensive Oracle applications & technology content under one roof
  • 25. Key  audit  quesKons:   •  Who  is  in  violaKon  of  SoD  rules?   –  &  how?   •  What  programs  can  a  user  access?   –  &  with  what  authoriKes?   •  Who  can  access  a  parKcular  program?   –  &  with  what  authoriKes?   •  Who  can  access  criKcal  programs?   –  Such  as  Address  Book  Master  Maintenance,  Bank   Payments  and  Credit  Limits   •  Who  can  access  Master  Data?   –  Such  as  AutomaKc  AccounKng  InstrucKons,  Bank   Account  details,  Chart  of  Accounts     •  What  security  sesngs  does  a  parKcular  user  have?   The most comprehensive Oracle applications & technology content under one roof
  • 26. Solve  Business  Problems  with  Good  Security   •  Audit  Security  –  KNOW  your  status   •  Map  Security  to  Business  Processes   •  Build  in  SoD   •  Make  Security  more  Manageable        &  Reduce  Costs   •  Consider  Outsourcing        Security  Management   •  Compliance  Management            &  ReporKng   The most comprehensive Oracle applications & technology content under one roof
  • 27. SegregaKon  of  Duty  Issues   •  Spread-­‐sheets   No  Integrity   •  Queries   No  Accuracy   •  Manual  Review   Time  consuming   •  Responsibility  level  SoD   Omits  key  risks  (needs  to  be  at   the  FuncKon  level)   •  Periodic  Reviews   Risk  between  reviews   •  External  SoluKons   High  Cost   The most comprehensive Oracle applications & technology content under one roof
  • 28. EffecKve  control  of  SOD:  Reduce  Costs   •  Tools  reduce  Cost  of  CorrecKng  Errors….   –  Prevent  Unwanted  Access   –  Approval  Process   –  MiKgaKon  Handling   –  False  PosiKve  Handling   •  Reduced  Staff  Time……   –  Embedded  into  EBS   –  No  addiKonal  Hardware   –  Rapid  ImplementaKon  of  Complex  Security   –  No  impact  on  Upgrades   The most comprehensive Oracle applications & technology content under one roof
  • 29. SegregaKon  of  DuKes  (SoD)   Jones & Jones Inc. A Manager Sets up MB Inc. as a supplier Accepts Purchase Invoices from MB Inc. Approves Invoices Processes for Payment Transfers the funds Runs  off  with  £1m   The most comprehensive Oracle applications & technology content under one roof
  • 30. SegregaKon  of  DuKes  (SoD)   Jones & Jones Inc. A Manager Sets up MB Inc. as a supplier Accepts Purchase Invoices from MB Inc. Approves Invoices Processes for Payment Transfers the funds Runs  off  with  £1m   The most comprehensive Oracle applications & technology content under one roof
  • 31. QuesKons?   The most comprehensive Oracle applications & technology content under one roof
  • 32. Have  pity  on  the  homeland.....   The most comprehensive Oracle applications & technology content under one roof