I always wondered about hand editing orders of some expensive stuff to some
cohort overseas. Or skimming little things on orders, to the extent the
payer wouldn't notice. Like how the phone company sneaks charges on your
phone bill. I understand their are checks and balances before and after
EDI, but in todays spread thin backoffices things do slip by. I don't know
if people have had any interesting solutions to this. I was at a company
where I was dealing with secure data and it was a multi faceted approach,
but it wasn't so much on system controls, because how do you keep the
people from touching what they are supposed to touch. It was more geared
around background checks, keeping other people out, social engineering.
Reminds me of I wonder why alot of banks and doctors offices have workers
computer monitors facing out the window, all you need is to setup a a
telephoto video camera across the street and you can scrape some client
information.
Regards,
-Steve
"Hurd, Richard To:
EDI-L
[SLCUS]" cc:
<[EMAIL PROTECTED]> Subject: RE:
[EDI-L] Sarbanes-Oxley
03/08/2005 09:14 PM
Ah, SOX. Brings back memories.
I was on the IM core team for SOX last year. Not only did I have to put
the
controls in place for EDI, but I was also tasked with documenting and
bringing under compliance EVERY interface within the J&J Consumer
franchise.
Lovely stuff. Got me a nice award at the end of the year, too. Little
statue for my desk, a few bucks in the pocket. But I digress.
"Doing everything to ensure compliance" doesn't mean that the lights have
to
go out. SOX is about auditing and control, not about not doing your work.
For example, we took logical, reasonable precautions. We documented
controls over restricted access to production data files (i.e., no hand
editing allowed; we copy the files to test, make edits, and run jobs to put
them back in production so more than one person knows about it, and there's
an audit trail.) We fill out change request forms if we need to migrate
maps from test to production environment. We had to run tests to show that
unauthorized trading partners would get written to a suspense file, e.g.,
wouldn't process in our system. We implemented a somewhat robust change
control procedure, and we're fleshing it out this year.
But you can't VIEW maps? How are you supposed to get work done? Yes, I
can understand that loading new standards would have to go through change
management; we just upgraded our Gentran:Basic MVS translator to Version
6.2
this past weekend and generated a TON of change requests. Guess who was
the
approver on all of them? Yup. I was muttering under my breath all day at
the guy who implemented the change (and that wasn't me, by the way;
separation of responsibility. The developer can't implement his own
changes, and the approver can't develop or implement...)
However, at the end of the day we successfully waived many of the more
stringent requirements with the following observation: EDI is a gateway
process. It has, however, compensating controls. (That's a big SOX
buzzword.) Most of EDI is not a key control (another SOX buzzword.)
For example, suppose you did have the keys to the candy store and were able
to secretly modify a purchase order in production -- you multiplied the
order quantity by 2 or added $10 to the price. So what? All that would
happen is that it would hit an application system and someone would notice
a
discrepancy. Or the discrepancy wouldn't be noticed and you'd ship twice
as
much to the customer, who would refuse half of it. Or they would notice
that the invoice was out of balance by $10*number-of-items and create a
deduction on their payment.
You can furiously create all the havoc you want in EDI-land, but if your
other systems are in control, then there's darn little you can do to the
EDI
system that is going to gum up the works.
If you need to talk about this more offline, let me know via email and we
can chat. I am rather an expert with this stuff. :) Your people
probably
have a case of the willies when it comes to Sarbanes-Oxley, and I don't
blame them; but SOX compliance isn't as big an issue as they are seeing it
if they've screwed things down so tightly you can't even LOOK at stuff.
Or if people want to talk more about it on-list, that's fine too.
> -----Original Message-----
> From: Ron Paquin [mailto:[EMAIL PROTECTED]
> Sent: Tuesday, March 08, 2005 4:28 PM
> To: [email protected]
> Subject: [EDI-L] Sarbanes-Oxley
>
>
>
>
> Maybe I missed it, and maybe this isn't the appropriate forum, but can
> anyone share the impact Sarbanes-Oxley has had on their day-to-day EDI
> development and implementation lives?
>
> My company has chosen a "do everything to ensure compliance" approach,
> and I just don't have a good feel for what portions, if any, of the
> EDI processes should be affected.
>
> For example, I currently cannot even see maps, etc., in the Production
> environment without special dispensation, and there are several tasks
> related to loading new X12 releases, etc., which I have to have done
> through Change Management.
>
> I guess I'm just interested to get a discussion started on how
> Sarbanes-Oxley is affecting those of you who read this board, because
> it's sure making my life miserable.
>
> Regards,
>
> Ron
[Non-text portions of this message have been removed]
.
Please use the following Message Identifiers as your subject prefix:
<SALES>, <JOBS>, <LIST>, <TECH>, <MISC>, <EVENT>, <OFF-TOPIC>
Access the list online at: http://groups.yahoo.com/group/EDI-L
Yahoo! Groups Links
.
Please use the following Message Identifiers as your subject prefix: <SALES>,
<JOBS>, <LIST>, <TECH>, <MISC>, <EVENT>, <OFF-TOPIC>
Access the list online at: http://groups.yahoo.com/group/EDI-L
Yahoo! Groups Links
<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/EDI-L/
<*> To unsubscribe from this group, send an email to:
[EMAIL PROTECTED]
<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/