1.Support team access is often excessive
with many organisations using
access profiles that breach traditional
segregation of duties principles;
2.Most organisations do not have defined
segregation of duties policies. Where
segregation of duties principles have
been defined, many organisations have
no preventative or detective controls to
enforce these principles;
3.Oracle does not provide standard
reports to identify actual segregation
of duties conflicts4. Few organisations
have defined their own bespoke reports
to address this issue;
4.Few organisations configure auditing to
capture changes to high risk information,
such as supplier bank account details; and
5.Many organisations have not defined
exception reports to monitor security
exceptions or incidents.
In addition to weaknesses at the application
level, database security is another critical area
which is often overlooked. All information in
Oracle applications is held in an underlying
Oracle database. If the database is not
adequately secured, information can be accessed and modified directly at the database
level, by-passing all application level controls.
Typical database security issues include
the use of generic user accounts, inadequate
password controls and no auditing to monitor
the activity of database administrators.
1.Support team access is often excessivewith many organisations usingaccess profiles that breach traditionalsegregation of duties principles;2.Most organisations do not have definedsegregation of duties policies. Wheresegregation of duties principles havebeen defined, many organisations haveno preventative or detective controls toenforce these principles;3.Oracle does not provide standardreports to identify actual segregationof duties conflicts4. Few organisationshave defined their own bespoke reportsto address this issue;4.Few organisations configure auditing tocapture changes to high risk information,such as supplier bank account details; and5.Many organisations have not definedexception reports to monitor securityexceptions or incidents.In addition to weaknesses at the applicationlevel, database security is another critical areawhich is often overlooked. All information inOracle applications is held in an underlyingOracle database. If the database is notadequately secured, information can be accessed and modified directly at the databaselevel, by-passing all application level controls.Typical database security issues includethe use of generic user accounts, inadequatepassword controls and no auditing to monitorthe activity of database administrators.
การแปล กรุณารอสักครู่..
