<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Adapt2 Consulting &#187; internal audit</title>
	<atom:link href="https://adapt2consulting.com.au/tag/internal-audit/feed/" rel="self" type="application/rss+xml" />
	<link>https://adapt2consulting.com.au</link>
	<description></description>
	<lastBuildDate>Sat, 28 Aug 2021 20:17:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Effective SAP Security through Engagement</title>
		<link>https://adapt2consulting.com.au/effective-sap-security-through-engagement/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=effective-sap-security-through-engagement</link>
		<comments>https://adapt2consulting.com.au/effective-sap-security-through-engagement/#comments</comments>
		<pubDate>Thu, 12 Sep 2013 12:47:49 +0000</pubDate>
		<dc:creator>Lynton Howes</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[grc]]></category>
		<category><![CDATA[internal audit]]></category>
		<category><![CDATA[SAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[segregation of duties]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://adapt2consulting.com.au/?p=866</guid>
		<description><![CDATA[<p>You are not authorised to use transaction ME21N. Pause.  (Thought bubble appears). Why don’t I have access?  I used to be able to create purchase orders.  I need to be able to do this.  Why is my manager stopping me from doing my job? (Sound of pencil snapping). “Rob, can I borrow your SAP password [...]</p><p>The post <a href="https://adapt2consulting.com.au/effective-sap-security-through-engagement/">Effective SAP Security through Engagement</a> appeared first on <a href="https://adapt2consulting.com.au">Adapt2 Consulting</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2><img class="alignleft  wp-image-916" alt="Access Denied" src="http://adapt2consulting.com.au/wp-content/uploads/2013/09/sap-error.png" width="57" height="53" />You are not authorised to use transaction ME21N.</h2>
<p>Pause.  (Thought bubble appears).</p>
<p><i>Why don’t I have access?  I used to be able to create purchase orders.  I need to be able to do this.  Why is my manager stopping me from doing my job?</i></p>
<p>(Sound of pencil snapping).</p>
<p><i>“Rob, can I borrow your SAP password to create this purchase order?  Need to get this invoice paid today, otherwise the vendor is not going to deliver the stock we need!”</i></p>
<p>Sound familiar?  Read on as we share our years of experience to help ensure that your organisation’s expenditure in SAP includes a comprehensive governance framework to ensure that this situation doesn’t occur.</p>
<p>Oh, and what’s the likely cost to your business if you get it wrong?</p>
<h2>$3.08 million.</h2>
<p>That’s the average loss to an organisation which experiences fraud, according to a recent KPMG report,[i] which also found that 91% of frauds are carried out by an individual with no known history of dishonesty, and 2012 saw an 82% increase in individual frauds exceeding $1 million.  And you’ve just spent how much on that SAP implementation or security remediation project?  Our tips below will help ensure that your investment is secure, so you’re less likely to become the next statistic in the news.</p>
<h2>Tip 1: Integrate Security in every SAP project, from Blueprint onwards</h2>
<p>Data governance is typically given top priority in any SAP project, and security is often the <i>last</i> thing to be considered (or sometimes even scrapped until after Go Live, which is painful!)  Yet it’s just as important, and should be integrated in every project, right from the Blueprint phase.  This requires executive sponsorship, team integration, effective stakeholder engagement and <a title="Experts in training" href="http://adapt2consulting.com.au/services/learning-content-development-delivery/" target="_blank">training</a>, which are just as important as effective access control and risk analysis tools, such as <a title="SAP Governance, Risk and Compliance explained" href="http://www.turnkeyconsulting.com.au/grc-integration/" target="_blank">SAP GRC</a>.</p>
<h2>Tip 2: Mix business with Security, consistently</h2>
<p>It’s critical that SAP Security is not viewed as a technical IT function, separate from the business requirements…that inevitably results in “Damned security!” frustration.  Functional Consultants need to dovetail their design with the goals of Security, then work with the business to ensure that practical solutions result, meeting the needs of the business while providing the required governance.  This is where expert <a title="Change Management and Training Consulting" href="http://adapt2consulting.com.au/services/change-management-and-training-consulting/" target="_blank">change management</a> guidance will help bring the parties together effectively, and assist with facilitating quality <a title="Experts in process mapping" href="http://adapt2consulting.com.au/services/business-process-development/" target="_blank">process mapping</a> and business validation, and role design and role mapping that everyone understands well before the access is provisioned.</p>
<p>Ultimately, proper security governance facilitates Best Practice business processes, and ensures that these are sustained, which results in your SAP return on investment being realised over the long term.</p>
<p>It might sound obvious, but don’t forget to engage with the Internal Audit team also!</p>
<h2>Tip 3: Test effectively</h2>
<p>Security is often overlooked during the Test phase of a project (or unable to be tested, if the role design was not considered early enough).  SAP Best Practice is to conduct User Acceptance Testing with the security roles which will be used in Production, to provide a comprehensive testing regime (both positive and negative testing) which will minimise the number of unexpected access restrictions (or segregation of duties risks) arising at Go Live.</p>
<div>
<div id="attachment_873" class="wp-caption alignleft" style="width: 171px"><img class="size-full wp-image-873 " alt="Don't compromise your SAP system" src="http://adapt2consulting.com.au/wp-content/uploads/2013/08/weakest-link.png" width="161" height="240" /><p class="wp-caption-text">Don&#8217;t compromise your SAP system</p></div>
<h3><strong><i>Case study:</i></strong></h3>
</div>
<p><em><strong>A greenfield implementation was running behind schedule, with process mapping and security role design partially incomplete when UAT commenced.  As a result, testing could not be done with the final roles.  The result at Go Live?  A large number of users could not perform key tasks, so the decision was made to drastically broaden the Production roles to allow the business to function.  This in turn exposed the business to high fraud risk for the interim period.  The resulting role re-design, re-mapping and re-provisioning into the Production environment consumed time and energy which should have been spent bedding down the system.  The total costs subsequently blew out.</strong></em>[ii]</p>
<div>
<h2>Tip 4: Include Security Awareness Training</h2>
</div>
<p>Nobody likes to have something enforced which they don’t understand the rationale for, yet security is often imposed as a “rule” without explaining the reasons why.  This is a critical piece of the engagement exercise, which should commence early and ideally expand to an organisation-wide cultural acknowledgment of security principles and their practical application, in the same way that safety awareness is embedded in today’s organisations.  Executives and the governance team should also be included, to drive engagement and demonstrate commitment from the top.</p>
<p>Furthermore, cultivating a culture of awareness among staff enhances even the best system controls.  In Australian organisations, 35% of fraud is detected through a tip off, both by internal and external sources and through formalised whistleblower programs.[iii]  Training staff in what to look for and identifying the ‘Red Flags’ of fraud is an invaluable fraud mitigation and detection tool. All organisations, regardless of size, should consider a <a title="Training programs" href="http://adapt2consulting.com.au/services/learning-content-development-delivery/" target="_blank">security awareness training program</a>, including:</p>
<div id="attachment_867" class="wp-caption alignright" style="width: 310px"><img class="size-medium wp-image-867 " alt="Educate staff to build vigilance" src="http://adapt2consulting.com.au/wp-content/uploads/2013/08/Meerkats-300x225.png" width="300" height="225" /><p class="wp-caption-text">Educate staff to build vigilance</p></div>
<ul>
<li>Fraud awareness</li>
<li>A whistleblower program that staff trust</li>
<li>Maintaining and promoting fraud reporting channels</li>
<li>Data security</li>
</ul>
<p>It’s not just about fraud.  The Age of Data is by definition also the Age of Data Breaches.  The average cost of a data breach to an Australian enterprise increased to $2.72 million last year,[iv] and if your business is managing sensitive customer data with SAP CRM, your security framework can’t be limited to the SAP ECC system.</p>
<h2>Tip 5: Finish strongly</h2>
<p>As Go-Live approaches, project teams have to set up new users, provision access and perform final checks, and ensure that user accounts activate on day one and not before.  These activities all need to be perfectly timed to ensure minimal disruption to the business, and if security is understood and integrated with the project team’s objectives, success is far more likely.</p>
<h2>Tip 6: Ensure that the security model is sustainable</h2>
<p>After Go Live, there are inevitably alterations to roles required, so all changes must go through a rigorous risk analysis and acceptance process to ensure that the good work done in role design is not unwound.  A sustainable governance model should include regular “Working Group” meetings, with Role Owners, Risk Owners and Internal Audit involved.  The <a title="SAP Governance, Risk and Control explained" href="http://www.turnkeyconsulting.com.au/grc-integration/" target="_blank">SAP GRC</a> toolset provides ample reporting capability for review of risks and mitigating control compliance, but this only yields value if the information is reviewed regularly.</p>
<h3><strong><i>Case study:</i></strong></h3>
<p><strong><em>An operational manager of a large manufacturing company had detailed knowledge of the invoicing systems which enabled them to create fraudulent invoices inflating the costs of regular supply of goods and services from a third party. In addition, the employee had responsibility for the management of asset disposal, and had the ability to write down stock to minimal value. This stock was then sold on the secondary market for a significant profit.</em></strong></p>
<p><strong><em>The total estimated loss was in the range of AUD 8 million.</em> </strong>[v]</p>
<div>
<h2>Tip 7: Don’t try to go it alone</h2>
</div>
<p>In an era of exponentially increasing data and interconnected IT systems, the potential for misuse of data is increasing correspondingly.  Likewise, there are more and more technical and consulting offerings; some tried and true, others recent and untested.  Recognise the limits of your expertise and <a title="Contact Us" href="http://adapt2consulting.com.au/contact-us/" target="_blank">engage trusted help</a> early, where you need to.</p>
<p>With the correct application of the latest risk analysis and management tools, combined with a strategic and practical <a title="Change Management and Training Consulting" href="http://adapt2consulting.com.au/services/change-management-and-training-consulting/" target="_blank">change management program</a> to achieve <i>implementation </i>and<i> sustainability</i>, not just installation, you’ll achieve the best possible security outcomes.</p>
<p>Don’t think of it as money spent; think of it as $3.08 million saved.</p>
<hr align="left" size="1" width="33%" />
<div>
<p><em>Like our content?  Use the LinkedIn <strong>Follow</strong> button at the top of the page to have our blog posts delivered directly to your feed.</em></p>
</div>
<div>
<hr align="left" size="1" width="33%" />
<div>
<p>[i] <a href="http://www.kpmg.com/au/en/issuesandinsights/articlespublications/fraud-survey/pages/fraud-bribery-corruption-survey-2012.aspx" target="_blank">http://www.kpmg.com/au/en/issuesandinsights/articlespublications/fraud-survey/pages/fraud-bribery-corruption-survey-2012.aspx</a></p>
<p>[ii] Observed first-hand by authors</p>
</div>
<div>
<p>[iii] <a href="http://www.pwc.com.au/consulting/assets/risk-controls/global-economic-crime/Global-Economic-Crime-AU-Mar11.pdf" target="_blank">http://www.pwc.com.au/consulting/assets/risk-controls/global-economic-crime/Global-Economic-Crime-AU-Mar11.pdf</a></p>
<p>[iv] <a href="http://www.computerworld.com.au/article/463792/data_breach_costs_rise_again_report/" target="_blank">http://www.computerworld.com.au/article/463792/data_breach_costs_rise_again_report/</a></p>
</div>
<div>
<p>[v] <a href="http://www.pwc.com.au/consulting/assets/risk-controls/global-economic-crime/Global-Economic-Crime-AU-Mar11.pdf" target="_blank">http://www.pwc.com.au/consulting/assets/risk-controls/global-economic-crime/Global-Economic-Crime-AU-Mar11.pdf</a></p>
</div>
</div>
<p>The post <a href="https://adapt2consulting.com.au/effective-sap-security-through-engagement/">Effective SAP Security through Engagement</a> appeared first on <a href="https://adapt2consulting.com.au">Adapt2 Consulting</a>.</p>]]></content:encoded>
			<wfw:commentRss>https://adapt2consulting.com.au/effective-sap-security-through-engagement/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
