QUESTION POSED BY: alok.dhar@aoa.nestle.com on 17 June 2003 Our SAP production support teams would like full transactional access
(display/change/create) into production systems. This conflicts with some
of our strategies and policies. Do you have any guidelines for best
practices in this area - what is generally the norm for internal support
roles for other companies? Any help will be appreciated.
>
Very simple question. No. There are a number of rules, best practices,
and common sense that would argue in your favor. The norm is for support
people to have display access for most transactional functions, where
problems are noted so they should be replicable in your testing environment
(assuming you have a good QA process). The support personnel should then
find the solution for the problem, move it to test and then promote to
production. If you give support people production functional access, they
will start processing transactions and have both the knowledge and access
to violate most internal controls.
Alternatively, I have seen some process teams identify specific
transactions they need in production due to specific business rules (Tax
rate updates, Monthly close support) and receive business sign-off. This
is acceptable and warranted. There are always exceptions.
Furthermore, you should work with your audit community to understand your
obligations under Sarbanes-Oxley Section 404 on internal and system
controls. Your external auditor may not be willing to attest to the
soundness of your control environment if multiple segregation of duty
issues exists.
Search and Browse the Expert Answer Center Search and browse more than 25,000 question and
answer pairs from more than 250 TechTarget industry experts.
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.
All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy SearchSAP.com is a search service provided by TechTarget and is completely independent of and not affiliated with SAP AG.