IT General Controls (SOX)

CONTROL ID LAYER CATEGORY RISK DESCRIPTION
APP-01 Application Change Management Changes to application systems or programs that are not properly tested may introduce errors, software defects, or vulnerabilities into the production environment. Application changes are tested in a non-production environment prior to production implementation, and evidence of testing sign-off is documented and retained.
APP-02 Application Change Management Unauthorized configuration or code changes to application systems may result in errors, defects, or vulnerabilities being introduced into the production environment. Configuration and Code Changes to critical applications are formally reviewed and approved by authorized management prior to deployment into the production environment.
APP-03 Application Change Management Inadequate restriction or unmonitored administrative overrides of production environment settings may allow unauthorized, untested, or direct changes to code and configurations, leading to system instability, security vulnerabilities, or data corruption SAP production clients and core system settings are configured to prohibit direct changes to programs and configurations. Any temporary openings or overrides of production client settings are formally logged, monitored, and approved by management.
APP-04 Application Access to Programs and Data Failure to properly configure, secure, and enforce authentication mechanisms (SSO and password parameters) may lead to unauthorized access, credential compromise, or privilege escalation, potentially resulting in unauthorized modifications, data leakage, or corruption within the application environment Single Sign-On (SSO) is enabled and utilized as the primary authentication mechanism for the majority of users (evidenced by external user mappings in RSUSR300), while fallback password authentication is governed by the application layer and configured to enforce appropriate parameters (complexity, history, minimum length, expiration, and lockout per company policy, verified via RSPARAM
APP-05 Application Access to Programs and Data Inadequate restriction of user access or failure to enforce the principle of least privilege may result in users obtaining unauthorized access to sensitive application functions or data, leading to inappropriate modifications, data breaches, or fraudulent activity. SAP user security role assignments are reviewed and approved by authorized management via automated GRC workflows or documented ticketing systems prior to provisioning
APP-06 Application Access to Programs and Data Lack of periodic management review of application user access rights may result in users retaining excessive or inappropriate access to critical IT and business functions that is not commensurate with their job responsibilities. Management performs a periodic review of end-user sensitive access to applications using a defined ruleset (e.g., SAP GRC) to identify, evaluate, and remove inappropriate or critical risk exposures (such as critical IT or business functions).
APP-07 Application Access to Programs and Data Terminated users may retain access to critical applications and data, resulting in unauthorized or fraudulent transactions, inaccurate financial reporting, or loss of data User termination records are processed in the HR system in a timely manner to initiate automated de-provisioning through the identity provider. Network and directory account deactivation automatically revokes primary authentication access, which is supplemented by automated scripts that systematically lock or expire downstream SAP user accounts.
APP-08 Application Access to Programs and Data Failure to enforce SoD controls during the access provisioning process may allow users to obtain conflicting access rights (e.g., ability to create and approve transactions, or initiate and approve changes), resulting in inadequate segregation of duties, unauthorized transactions, fraudulent activity, or circumvention of critical controls. Access request workflows in SAP GRC are configured to perform automated Segregation of Duties (SoD) checks against a defined ruleset, with flagged conflicts requiring authorized management approval prior to provisioning.
APP-09 Application Access to Programs and Data Inadequate SAP basis hardening may enable unauthorized system access, privilege escalation, uncontrolled production modifications, and bypass of critical controls, resulting in system compromise or unauthorized changes. SAP basis security settings are configured to enforce a hardened security posture in production environments, including: (1) standard/default system IDs (e.g., SAP*) are locked and default passwords are changed; (2) privileged profiles (e.g., SAP_ALL, SAP_NEW) are not assigned to end-users; (3) the production client is configured to prevent direct configuration changes, with all administrative modifications formally logged and monitored; and (4) password policies enforce minimum complexity requirements and system authorization checks are enforced for all transactions
APP-10 Application Computer Operations Loss of financial data or inability to recover audit trails in a timely manner may prevent transaction substantiation, fraud detection, and regulatory compliance. Data backup is performed on a periodic basis.
APP-11 Application Computer Operations Untested backups may fail to recover financial data in a timely manner during actual data loss events, preventing substantiation of transactions and audit compliance. The Company tests its financial backups and transaction audit logs at least annually through documented backup and restoration testing, with results reviewed and retained by IT management."
APP-12 Application Computer Operations Failure to timely detect and remediate critical SAP batch job failures may result in incomplete transaction posting, inaccurate period-end balances, or unexecuted payments, leading to inaccurate financial reporting and compromised data integrity Critical SAP batch jobs are monitored via SAP Solution Manager with automated alerts to notify job owners of failures. Failed jobs are investigated and remediated the same business day, with results documented and reviewed by management.
DB-01 Database Access to Programs and Data Failure to enforce strong password parameters at the HANA database layer may result in unauthorized database access, enabling direct data manipulation, fraud, or circumvention of application controls HANA database user accounts are configured to enforce password parameters (complexity, history, minimum length, expiration, lockout) per company policy, verified via HANA Cockpit or HANA Studio.
DB-02 Database Access to Programs and Data Inadequate HANA audit logging and review may result in undetected unauthorized database activities, enabling fraud, data manipulation, and circumvention of application controls without forensic evidence. SAP HANA audit policies are enabled and configured to record sensitive user activities within audit logs. Audit logs are retained per company policy and reviewed by IT management to identify unauthorized activities.
DB-03 Database Access to Programs and Data Failure to restrict and control HANA SYSTEM account access may result in unauthorized use of a privileged shared account, preventing accountability for database modifications, enabling undetected fraud, direct data manipulation, and circumvention of application controls and segregation of duties. The SAP HANA SYSTEM account is disabled in production. Temporary access requires advance approval with documented justification. All SYSTEM account activity is logged via HANA audit policies, and the account is locked upon completion of use
DB-04 Database Access to Programs and Data Failure to periodically review and remediate HANA database user access may result in users retaining excessive or inappropriate database privileges, enabling unauthorized direct data access, modifications, and bypass of application controls, leading to undetected fraud or data corruption Management performs a periodic review of HANA database user access to verify users have only necessary privileges for their roles. Inappropriate or excessive access is removed and findings documented and retained
OS-01 Operating System Access to Programs and Data Inadequate OS-level password enforcement may result in unauthorized operating system access, enabling privilege escalation, unauthorized modifications to SAP/HANA infrastructure, and circumvention of application-level controls The operating system layer is configured to require passwords based on appropriate parameters (complexity, history, minimum length, expiration, lockout, etc.), which are enforced per company policy
OS-02 Operating System Access to Programs and Data Failure to periodically review and remediate operating system access may result in inappropriate or excessive OS-level privileges granted to users, enabling unauthorized system modifications, database access, or circumvention of application controls, leading to system compromise or data corruption Management performs a periodic review of operating system user accounts and privilege assignments to verify access is limited to authorized personnel only and that elevated privileges (e.g., sudo, root) are restricted to database and system administrators. Inappropriate access is remediated and findings documented.