Perhaps the most important control organizations implement is the control related to the review and approval of journal entries. Most organizations using ERP Cloud...
Organizations are implementing new SaaS ERP systems to modernize their enterprise. Traditional cybersecurity risks are being outsourced to the software provider, yet certain cybersecurity risks still need to be addressed by management.
Managing identity has become one of the most critical elements of enterprise security in today’s complex digital environment. As businesses adopt more SaaS ERP systems, identity and access controls are no longer merely a compliance checkbox; they are also the new security perimeter. Management’s challenge lies in ensuring that the right people have access to the right systems and activities within those systems and that identities are properly secured.
Protecting the modern enterprise includes:
Traditionally, auditors focus on Segregation of Duties by separating conflicting duties in financially significant activities. For example, ensuring one person cannot create and approve payments. What began as a compliance demand following Sarbanes–Oxley, has now also become a security consideration due to the complexity of today’s systems. However, most compliance programs only look at SoD and do not fully consider the concept of least privilege access or what we refer to as Sensitive Access risks.
When new SaaS ERP systems are implemented, management needs to address:
CISOs and CIOs often assume all cybersecurity risks are covered by the software provider. However, certain risks at the application tier are management’s responsibility including:
Following are role design / access control risks that management commonly overlook:
All these risks underpin the criticality of implementing only fully customized roles as we address in this article.
Moving from an on-prem system where management gets to choose when to do upgrades to SaaS ERP systems is a significant paradigm shift we address in this article. With on-prem systems management can put off upgrades for years. SaaS ERP systems typically apply upgrades either 2x or 4x a year. While management benefits from the new features being introduced they don’t always consider that new features and changes to existing features need to be identified and managed. With each patch / release new features are added into seeded or partially customized roles.
When system implementers develop their scope, most projects are bid and won assuming the use of (mostly) seeded (vendor provided) roles. Only the astute and experienced management team understand that seeded roles are built for ease of implementation but not fit for long-term use. Seeded roles are oversimplified and generally have too much access. Some seeded roles have inherent Segregation of Duties. Because most projects don’t properly customize roles, the perpetual patch cycle means risks are consistently introduced.
This means management needs a mature security program to identify these changes. This includes having a managed service partner like ERP Risk Advisors to or a Access Control software that can be used with each patch / release.
Strong identity governance ensures least privilege, and SoD controls doesn’t just happen. Strong identity governance requires resources and commitment from leadership. When executives understand the value of these controls, they are more likely to provide the necessary budget and support for building a secure environment. Securing executive support helps ensure your identity governance efforts are properly resourced and aligned with broader business objectives.
To get started, you need visibility into your existing identity and access controls landscape.
In our experience most ERP software organizations provide over-provisioned seeded roles, and most System Integrators do not know how to refine and reduce risk in those roles. Without a mature risk advisory and cybersecurity partner, it is unlikely that the implementation was done in a secure and compliant manner.
ERP Risk Advisors is uniquely qualified to address cybersecurity risks, help implement automated controls, address SoD risks, build roles based on the principle of least privilege, , enhance access reviews, and effectively manage movers, joiners, and leavers. Contact us here to set up a meeting with us so we can help your organization’s security and controls program move from a Crawl to a Walk to a Run.
Additional Resources:
Perhaps the most important control organizations implement is the control related to the review and approval of journal entries. Most organizations using ERP Cloud...
Perhaps the most important control organizations implement is the control related to the review and approval of journal entries. Most organizations using ERP Cloud...