Audit escape.

Question: Hello Guys, I have a serious issue. Though we have process where we should not create a test Id in prodcution without proper approvals. I have created one as there were too many screens on my ssytem. It was a silly mistake, but seriousone. I have deleted the user Id immediately. But what ca i do so that it can be removed from change documents. Is there any way i can come out of these situation.

Answer:
Let me get this straight...

You are asking us how to circumvent the security and audit systems, so that no one can detect that you have breached company policy, is that correct?

Indeed you do have a serious situation.

Sorry but I will not assist you in this matter.
_________________
Sandi
~~~~

Apparently Father Christmas, the Easter Bunny, the Tooth Fairy and Star Wars aren't real

Tuly kiwi.

Answer:
"Oh what a web we weave when first we begin to deceive."

Face it like a man. What did you really do with the test user? Do you really think you can eliminate all the traces?
_________________
bwSecurity

Answer:
I made a similar silly mistake before by assigning myself a busness process all role very briefly in Production, thinking I was doing it in QA system.

Just admit to the mistake and provided you didn't make any changes (which you should be able to prove) your managers and the auditors should be fine with it. Do not try to erase your steps - this is far more idiotic and serious a mistake than your first.

Answer:
If it was a straight-forward blunder and the id did no 'work' in Prod. then you should cover yourself by e-mailing the system owner/security approver detailing the circumstances - and keep a copy for the auditors.
_________________
Best Regards
Bazza

Answer:
Unless your auditors are very thorough & test a large selection of the controls then you should be fine. Trying to cover your tracks could constitute fraud so fess up & take it like a professional who has made a mistake

Answer:
Yes i actually mailed the process owner as saying it as mistake.And it was taken fine to my relief. Because i have deleted user in just few seconds with no activity done as soon as i realised. Because it was taken seriously last time in some other case, i felt the same questions would arise. But in my case the creation and deletion was done in same minute, it wasn't taken seriously. Thank you guys.

Answer:
Actually you can remove the data using SAP facilities and more than likely the audit will not know what to look for... But owning up to the best answer.

Look at the SU8x seiries of tcodes, they let you ARCHIVE and DELETE the history of user maintenance.
_________________
John A. Jarboe

Answer:
five months before I created and deleted one test user ID in production .
I am not able to trace why I did that .Now SoX auditors are asking an explanation for it ...Wht to do ?I don't have any trace why I created it .

What happens in these cases .What can be the worst case.pls share ur experiences ..

No comments:

topics