Update to all SSA-Baan users: Automated SOD Segregation of Duties scan now available

 

September 2006

In this issue
How to achieve successful (SOD) Segregation of Duties validation with minimal cost & effort for your company
New Alliance – InfoStretch Corporation
Stay connected via the EZ-Workflow Wireless PDA Worklist
 


How to achieve successful (SOD) Segregation of Duties validation with minimal cost & effort for your company

For all organizations seeking adequate governance (either related to a SOX certification or not), a proper Segregation of Duties (SOD) validation is critical. To protect the integrity of companies’ data & transactions and to prevent fraud, the SOD validation requires reviewing on a regular basis individuals’ access authorizations. For organizations with hundreds/thousands of employees and various corporate applications, this task is time consuming and requires significant resources. In most case, it simply cannot be done manually. To address this need, EZ-Compliance provides an automated SOD scan. Not only does it provide precisely who is able to access what across diverse applications, it also uses dynamic SOD Conflicts Rules to automatically identify SOD Conflicts, and this within only minutes. Finally, the combination of what-if simulation capabilities and the fact that the scan can be performed/scheduled on a daily basis enable your company to implement true "Preventive SOD Controls".

1- The dynamic SOD Scan engine:

Within minutes only, the EZ-Compliance SOD rule-based engine will:

  • Determine all employee accesses across diverse applications (Baan, Mapics, Oracle, SAP, etc…):

    • Which employees can access a selected application?

    • Which applications can be accessed by a selected employee?

    • Which applications and employees are linked to a selected user-role?

  • Scan the entire employee/applications access structure to dynamically identify all Segregation of Duties SOD conflicts

  • Send notifications to the appropriate process owner or department head to resolve identified conflicts

  • Perform the required conflict resolution and/or mitigation to satisfy auditors requirements

2- SOD Rules Library of Baan conflicting sessions:


Corporations using the Baan applications (all versions) can benefit of the pre-defined Baan conflicting sessions library. Acting as a valuable knowledge base (used by other Baan users to pass SOX certification successfully), this library includes more that 450+ Baan sessions and how they create SOD conflicts. Within minutes of being loaded, this library can be used by the SOD engine to scan your current Baan authorizations and report back all conflicts found. With little effort, you will know exactly which employee accesses are to be resolved, documented or mitigated. And since the scan process requires only minutes, you can launch it as often as needed or schedule it as a daily business control, keeping your SOD validation always accurate no matter the frequent changes made to the Employees -> Roles -> Applications structure.
 


For more information about the pre-defined
Baan Conflicting Sessions SOD Library, visit
http://www.ez-process.net/EZ-ProcessCD/ezcompliance_BaanSOD.htm
 

 


 

 

Customer testimonial:

For our first round, we came up with home made scripts, tables and spreadsheets along with countless hours of manual analysis. Not only was this a tedious task, the results of our analysis were good only as long as the Employee-Roles-Process-Applications relationships were not modified. Needless to say, when our SOD validation was completed, it was time to start it over again…”.

We have since then implemented the EZ-Compliance rules-driven SOD conflicts identification solution. In a manner of minutes we are able to scan thousands of users, roles, processes and applications! Not only we know precisely who is able to access what, we have direct visibility of any SOD conflicts for us to investigate, resolve and mitigate. In addition to saving us considerable effort, the EZ-Compliance solution has enhanced the accuracy of our conflicts identification, critical to maintain our SOX certification for years to come”.

Director Finance Shared Services, Herman Miller


You wish to learn more ...

"I missed the SSAU 2006 sessions about SOD validation"
Simply visit the BWU/SSAU section at  http://www.ez-process.net/EZ-ProcessCD to view/download all presentation materials.

"I wish to read a SOD implementation Customer Case Study
."

Visit http://www.ez-process.net/EZ-ProcessCD (EZ-Compliance section - link #1) 

"I wish to have a personalized demo of the SOD Conflicts Scan"
Only 30 minutes of your time are required to perform "live" (1) the Access Scan (what sessions/applications my users are able to access), (2) the Conflicts Scan (what SOD conflicts exist of them have such accesses) and (3) the Resolution Scan (to mitigate known conflicts). Simply indicate the date/time convenient to your agenda and we will take care of the web-demo invitation and telephone bridge setup.

"I wish to see my own SOD conflicts"
At no cost, DynaFlow will scan your Baan users-sessions authorizations and provide you with a list of SOD conflicts identified by the EZ-Compliance scan. Try it today!


Contact us at
 SOD4Baan@EZ-Process.com
 

.:

title


New Alliance – InfoStretch Corporation

The importance of software quality assurance (SQA) has been pushed to the forefront as compliance regulations warrant companies to document and validate their processes and systems.  To address the growing need for third party verification and validation, DynaFlow is proud to introduce its alliance with Silicon Valley based InfoStretch Corporation. InfoStretch is a leading software QA, Test Automation and Process Optimization services company with over 50 satisfied clients globally.

Pierre Beaulieu, President and CIO of DynaFlow said:  “Software testing and the overall quality assurance process is very important to any compliance initiative.  The QA expertise, technology and strategic ideas InfoStretch brings to the table are a value add to any software initiative we are involved with.  Their QA methodology and ability to understand and adapt different client needs has proven complimentary to DynaFlow solutions and the way we work with our clients.”

“Upgrades or any change to enterprise applications is often regarded as a task laden with uncertainty and risk”, says InfoStretch President and CEO, Rutesh Shah.  “InfoStretch was founded on a solutions approach to ensure software quality through QA process optimization, and we are excited to be working with DynaFlow to help companies enhance their SQA, sustain regulatory compliance and at the same time enrich system experience for the end user.”

For more information about InfoStretch, visit www.infostretch.com/dynaflow

 

Stay connected via the EZ-Workflow Wireless PDA Worklist

Critical approvals are to be done but your approvers are on the move? You have your customer on the phone asking for the status of his/her order but you are away on the shop floor? Not a problem anymore. Simply use your wireless PDA or smart phone device (Blackberry, Treo, HP, etc…) and within a few clicks, you can act in a timely and professional manner. Not only used to notify you of tasks to be done, your EZ-Workflow Online PDA Worklist will enable you also to:

  • View all tasks currently on your online worklist
  • Lookup transaction details, status and documented events history
  • See what process steps have been completed and those awaiting execution
  • Perform electronically signed approval or rejection (with optional notes)
  • Execute your tasks or others delegated to you
  • Consult your collaboration messages and respond to them
  • Monitor color-coded Key Performance Indicators and drill-down to reporting details
  • Identify urgent and/or overdue instances to
  • Resolve, re-route, forward-to any instances needing attention
  • Etc …

More than only a notification channel, your wireless device enables complete workflow execution capabilities. “Shadowing” your full browser User Worklist, you can swap between your PC/laptop worklist and your PDA worklist anytime, or even operating both simultaneously.

Test drive the PDA mode at http://www.ez-process.net/ezprodemo/pda.htm (even from a full browser). Enter username "peter" with password "xp".