19
SESSION ID: #RSAC Lenka Fibikova Compliance Goal: Implementing Segregation Of Duties In An Organization GRM-R01 Independent Consultant

Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

Embed Size (px)

DESCRIPTION

Compliance Goal

Citation preview

Page 1: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

SESSION ID:

#RSAC

Lenka Fibikova

Compliance Goal: Implementing Segregation Of Duties In An Organization

GRM-R01

Independent Consultant

Page 2: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Why Segregation of Duties

Compliance with the national laws requiring correctness of the financial information and financial reporting

Business requirements on integrity of business information

2

Page 3: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

The story starts with…

Identified misuse

Findings from an external auditor

Findings from an internal auditor

Push from an enlightened leader

3

Page 4: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Challenges

4

Page 5: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Areas of concern

within business functions

X

within IT functions

X

not acceptable (B-IT, IT-B)

defined by the BP owner (B-B)

defined by the IT(IT-IT)

X

X

X

5

Page 6: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Implementing SoD Step by Step

Define IT SoD Matrix

Define BP SoD Matrix

Identify BP in Scope

Define Project

Identify IT Processes in

Scope

DefineSoD Matrix

Identify Scope

Identify Conflicts

Identify Actions

Implement Actions

Define Project

B-B

IT-IT

B-IT/ IT-B

Identify IT Applications

in Scope

6

Page 7: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Exercise: Define a B-B SoD Matrix

1. Document the process, its sub-processes and tasks

2. Identify SoD-relevant tasks ◄

3. Create the SoD matrix

7

Page 8: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Exercise: Define an IT SoD Matrix

Areas of responsibility:

Change Management

Access Management

Operation

8

Page 9: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Implementing SoD Step by Step

Define IT SoD Matrix

Define BP SoD Matrix

Identify BP in Scope

Identify Conflicts

in BPDefine Project

Identify IT Processes in

Scope

DefineSoD Matrix

Identify Scope

Identify Conflicts

Identify Actions

Implement Actions

Define Project

B-B

IT-IT

B-IT/ IT-B

Identify IT Applications

in Scope

9

Page 10: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Exercise: Identify conflicts

1. Identify business roles

2. Document which SoD-relevant tasks each of the roles executes

3. Verify whether any of the roles currently violates defined SoD rules

10

Page 11: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Implementing SoD Step by Step

Define IT SoD Matrix

Define BP SoD Matrix

Identify BP in Scope

Identify Conflicts

in BP

Identify Actionsfor BP

Define Project

Identify IT Processes in

Scope

DefineSoD Matrix

Identify Scope

Identify Conflicts

Identify Actions

Implement Actions

Define Project

B-B

IT-IT

B-IT/ IT-B

Identify IT Applications

in Scope

11

Page 12: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Exercise: Identify Actions

For each of the identified conflicts, an action has to be defined and documented: Immediate removal of the conflict Immediate setup of administrative measures to minimize the

risk Implementation plan for removal of the conflict or for setup of

administrative measures to minimize the risk Formal risk acceptance by the Business Process Owner (might

not be possible for some risks)

12

Page 13: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Implementing SoD Step by Step

Define IT SoD Matrix

Define BP SoD Matrix

Identify BP in Scope

Identify Conflicts

in BP

Identify Actionsfor BP

Identify B-B Conflicts in

Applications

Define Project

Identify IT Processes in

Scope

DefineSoD Matrix

Identify Scope

Identify Conflicts

Identify Actions

Implement Actions

Define Project

B-B

IT-IT

B-IT/ IT-B

Identify IT Applications

in Scope

13

Page 14: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Exercise: Mapping the SoD Matrix to IT

1. Identify which applications and application functions support the tasks

2. Extract which user IDs use the identified functions

3. Identify SoD conflicts

14

Page 15: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Implementing SoD Step by Step

Define IT SoD Matrix

Define BP SoD Matrix

Identify BP in Scope

Identify Conflicts

in BP

Identify Actionsfor BP

Identify B-BConflicts in

Applications

Identify B-IT/IT-B

Conflicts in Applications

Identify IT-IT Conflicts in

Applications

Identify Conflicts in

IT Processes

Identify B-B Actions in

Applications

Identify B-IT/IT-BActions in

Applications

Identify IT-IT Actions in

Applications

Identify Actions for

IT Processes

Implement Actions in

Applications

Implement Actions

in BPDefine Project

Identify IT Processes in

Scope

DefineSoD Matrix

Identify Scope

Identify Conflicts

Identify Actions

Implement Actions

Define Project

B-B

IT-IT

B-IT/ IT-B

Identify IT Applications

in Scope

Implement Actions in

IT Processes

15

Page 16: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Lessons Learned: Good Approach

1.

2.

3.

4.

5.

6.

16

Page 17: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Lessons Learned: The Hard Part

1.

2.

3.

4.

17

Page 18: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Apply in Your Organization

Next week you should: Verify how you handle integrity of your financial data and whether

Segregation of Duties has been consistently applied Consider whether there are any further (business-related) reasons for SoD

In the first three months you should: If there is no consistent approach for SoD, initiate a discussion with the

senior management

Within six months you should: Set up an SoD project Remember: Implementation of SoD takes longer than it might appear

18

Page 19: Grm r01 Compliance Goal Implementing Segregation of Duties in an Organization

#RSAC

Questions

19