Can anybody explain (short n simple) about SOX & SoDs with 3
examples for each functional module? n ur experience on SoDs.
Answer Posted / sakthi
SOD stands for Segregation of duties.
It helps us to identify frauds and Misstatements.
For example in virsa tool we have critical SOD conflict S017
for SD module where it identifies and checks for user who
could Perform credit approval function and modify cash
received for fraudulent purposes.
SOD conflict F017 for FICO module where it checks for users
who could Maintain a non bona-fide bank account and divert
incoming payments to it.
SOD conflict P001 for PP module where it checks for users
who could Maintain a fictitious vendor and enter a Vendor
invoice for automatic payment
As far my experience concerned we need to avoid critical SOD
conflicts as much as possible and these SOD conflicts are
the ones which the auditor checks and they ask for the
mitigation control that we have outside like trace.
| Is This Answer Correct ? | 3 Yes | 0 No |
Post New Answer View All Answers
What does the pfcg_time_dependency clean up?
Why is it important to delete sap-new profile? What steps will you take to do this?
How we Provided SAP Security design, configuration, and support for SAP Net Weaver systems running BI/BW 7.0 (Net Weaver 2004s)
Giving fire call access and extending fire call access by using VIRSA’s VFAT tool.can any one brief this
How to do SAP R/3 Security configuration, design, development, testing, implementation and production support.
what is the use of defaults tab in start menu
What is the use of Personalization tab in SU01?
Provides online GRC10 online training,covers configuration & suuport activities on all the four components. ARA,ARM,EAM,BRM. SAP Securty covers--R3 Security,BW BI Security,HR Security,SRM Security,CRM Security Practicals on each component in GRC Provides documentation and notes on each component supports resume preparation and certification For more details contact 8499995600.
What is sap internet transaction server?
Explain snc in sap security?
Is there a table for authorizations where I can quickly see the values entered in a group of fields?
How can I do a mass delete of the roles without deleting the new roles?
What does the account assessment category specify in a purchasing requisition in SAP Materials Management?
what are the issues you faced with UME?
authorization issue. We had asssigned company codes 'BUKRS' in range for example 4000-4220 some come company code is working some are not working means in between ranges . could you please post the answer as early as possible.