2007 Jan 22 5:37 AM
Hi experts,
Can any one please expand SOX and SOD for me and tell me what it is? Im new to SAP man.
Regards
Ashok
Hi experts,
Can any one please expand SOX and SOD for me and tell me what it is? Im new to SAP man.
Regards
Ashok
2007 Jan 22 6:19 AM
Hi,
Sarbanes Oxley is a US law passed in 2002 to strengthen Corporate Governance and restore investor confidence.Sarbanes Oxley Act was sponsored by US Senator Paul Sarbanes and US Representative Michael Oxley.. Sarbanes-Oxley (or more popularly Sarbanes Oxley) law passed in response to a number of major corporate and accounting scandals involving prominent companies in the United States. These scandals resulted in a loss of public trust in accounting and reporting practices. Sarbanes Oxley legislation is wide ranging and establishes new or enhanced standards for all US public company boards, management, and public accounting firms.
The passing into law of the Sarbanes-Oxley Act of 2002 regulates how financial data must be handled and protected in all publicly held corporations.
SOD stands for seggrigation of duties.Basically you need to understand what is SOD. If you want to know little bit of information go to the standard SAP roles copy to Z or Y roles check out each role and transactions to have initial idea.
Regarding SAP Authorization you find the details in the following link.
<b>http://help.sap.com/saphelp_nw04s/helpdata/en/52/671285439b11d1896f0000e8322d00/content.htm</b>
<b>http://help.sap.com/saphelp_47x200/helpdata/en/52/671126439b11d1896f0000e8322d00/frameset.htm</b>
This is very small bit of information to share to start. There is very long way to understand each business area.
i hope it will help you.
kiran kumar.v
2007 Jan 22 6:00 PM
HI Ashok,
Check this link..
http://www.sapsecurityonline.com/sox_sod/sod_matrix.htm
Its shd help u in gwetting a starting touch on SOD.
Also as explained below, the SOX can be explained as below..
Source :SapsecurityOnline.com
-
Sarbanes-Oxley has become the ad hoc standard for financial transparency, trust, and corporate accountability. While mandatory for all publicly-owned companies, Sarbanes-Oxley is also becoming a best practice for all types of companies who wish to identify with good governance practices.
A significant amount of attention is currently focused on Section 302 (Disclosure) and Section 404 (Internal Controls). Sarbanes-Oxley Sections 302 and 404 are designed to ensure information required to be disclosed is initiated, processed, recorded, and reported, and that management has assessed the effectiveness of internal controls regarding the reliability of financial reporting.
CEOs and CFOs of public companies must:
Certify that they have reviewed financial statements and each annual or quarterly report.
Certify that each such report fairly represents the company's financial condition.
Certify that they have established and are maintaining internal controls
Ensure the effectiveness of such internal controls every quarter.
Address significant changes in internal controls or other factors that could significantly affect such controls.
Identify corrective actions taken regarding deficiencies/weaknesses in controls.
Disclose any significant deficiencies in internal controls and/or any fraud involving persons with a significant role in upholding such controls
Hope it Helps.
Br,
Sri
Award points for helpful answers
2007 Dec 21 10:32 AM
Here is the "free" definition of SoD: http://en.wikipedia.org/wiki/Segregation_of_duties