Top Banner
MIS 5121: Exam 3 – Review Sheet Edward Beaver [email protected] ff
21

MIS 5121: Exam 3 – Review Sheet Edward Beaver [email protected] ff.

Dec 18, 2015

Download

Documents

Noah Griffith
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

MIS 5121: Exam 3 – Review Sheet

Edward [email protected]

ff

Page 2: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

ISC framework in the ERP environment- Entity level controls

- Automated application controls- Manual and semi-automated business process controls

- Authorizations and access protection (confidentiality, integrity)- IT General controls (change management, operation, security)

- Automated testing and monitoring of business processes, KPIs, etc.

• ___________• ___________• ___________• ___________• ___________Errors & Fraud

• ___________• ___________• ___________• ___________• ___________

Risks

Contain

Minimized by

…___________ __________

______ __ _____

_____ ______ ______

_______________ _ __

Business Processes

Balance Sheet P & L Notes

Arise through Must be observed / achieved in

FDA etc. Performance & Policies

Other Reg’s Organization’s Objectives & PoliciesExternal Financial Reporting regulations

Assertions

______ ___ _______

Valu

e / B

enefi

ts

Page 3: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Marketing / SalesCustomers

Suppliers

Supply Chain

Finance / HR

Procurement at GBI

Payment

Page 4: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Procure to Pay Process• Common Risks

– – – – – – –

• Common Controls– – – – – – –

Page 5: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Marketing / SalesCustomers

Suppliers

Supply Chain

Finance / HR

Order to Cash at GBI

Page 6: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Order to Cash Process• Common Risks

– – – – – – –

• Common Controls– – – – – – –

Page 7: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Environment Favorable to FraudFramework for spotting high-risk situations

Fraud

____

____

__

____________

________ /

_________

Fraud Triangle

• _________________________ (____________________ _________)

_____________________ _____________________

• ________________________ (____________________ _________)

_____________________ _____________________ _____________________ _____________________

• ______________________ (____________________ _________)

_____________________ _____________________

Page 8: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Inventory: Record Accuracy• Does ______________-- Match __________________

Check:– _______________– _______________– _______________

Physical Counting Cycle Counting

Page 9: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Typical SAP Landscape

Development System

Type of Users:---

Type of Work:---

Quality-Assurance System

Type of Users:---

Type of Work:---

Production System

Type of Users:---

Type of Work:---

Page 10: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Client Dependent vs. Independent

Dev 100Master (Gold)

- ________ Data

- ________ Data

- ________ Data

Dev 110Dev Test

- …

- ….

- ….

Dev 180Data Conversion

- …

- ….

- ….

Dev 900Sandbox

- …

- ….

- ….

Client Independent _____________ > Repository Objects (Client Independent Config _____________ - _____________, _____________ _____________ - _____________ _____________ > _____________

Client DependentSystem/Instance

Page 11: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

SAP Change Management• SAP Transports are: ____________________________________________

They Contain: _________________________________________________

SAP Change Management Recommendations

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

Page 12: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

System (Server) / Client Parameters• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

Page 13: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Table Security

Tables are Integral part of SAP Application Different Types of Tables

_________________ _________________ _________________ _________________

SAP is customized using thousands of ____________ tables through the _________________ (SPRO)

Page 14: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Table and Information Security

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

• Risk: _____________________________________________

Control: _____________________________________________

Page 15: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Program & Development Security• Good Development Practices

– _________________________________________

– _________________________________________

– _________________________________________

– _________________________________________

• Control Concerns: Development, Data Dictionary

– _________________________________________

– _________________________________________

– _________________________________________

– _________________________________________

Page 16: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Powerful ID’s and Profiles• List few SAP Supplied Powerful ID’s and Profiles that need ‘caged’

– _________________________________________

– _________________________________________

– _________________________________________

• Risks and Control Recommendations for Powerful ID’s / Profiles

– Risk: _____________________________________________

Control: _____________________________________________

– Risk: _____________________________________________

Control: _____________________________________________

– Risk: _____________________________________________

Control: _____________________________________________

Page 17: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Firefighter / Emergency User• Valid Scenarios, Situations for Firefighter Use

– _________________________________________

– _________________________________________

– _________________________________________

– _________________________________________

• Key differences of Firefighter vs. Regular ECC access: – Audit of reason and transactions used– Emergency vs. routine use

• Firefighter Best Practices

– _________________________________________

– _________________________________________

– _________________________________________

– _________________________________________

Page 18: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

GRC & Other SAP Module Security• GRC (G___________, R____, & C__________________ Module

• Beyond ERP / ECC and GRC: What is another SAP module

– What is another SAP module: _________________________________________

– What does the module do: _______________________________________

______________________________________________________________

– How is Security Administered: ____________________________________

______________________________________________________________

GRC v 10.0 Module Function / Reason for Being

Page 19: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Segregation of Duties

19

Goal: __________________Definition

‘__________________________________’Person who ______________ should not be the person who ______________ .

An Individual should only have 1 of following Responsibilities / Privileges:

A_____________R_____________C_____________

Page 20: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Finance• Common Risks– – – – –

• Common Controls– – – – –

Page 21: MIS 5121: Exam 3 – Review Sheet Edward Beaver Edward.Beaver@temple.edu ff.

Inventory Control• Common Risks– – – – –

• Common Controls– – – – –