What exactly the auditing team will or should check in my database.

Dear all,
i am using oracle 10g database on windows server 2003 and oracle application server 10g on windows server 2003.
now an internal auditing team is going to audit my database.
i want to know what they will audit so that i do preparation for it.
thanks

i am using oracle 10g database on windows server 2003 and oracle application server 10g on windows server 2003.
now an internal auditing team is going to audit my database.
i want to know what they will audit so that i do preparation for it.
There is no way to know without knowing what type of 'audit' they are going to audit for.
1. access security? who has access to the physical hardware? how is that access managed (granted/revoked/documented)?
2. data security? who has access to the data in the database? how is that access managed? what levels of access are implemented?
3. financial? what controls are in place to monitor/log/track transactions that affect security has been implemented
The biggest step you can take to 'prepare' is to either find, or create, documentation about the system components.
ANYTHING that you tell them that isn't backed up by company approved and documented procedures is a security risk. No competent auditor is simply going to take anyone's word for an issue that is part of an audit.
The next step you can take is to be prepared to DEMONSTRATE that what you describe has, in fact, been implemented.
The third step during the actual audit is DON'T LIE! If you don't know an answer just say so. If a particular feature hasn't been implemented, or you know it has problems, just say so. Remember - anything you say can be EASILY verified if they choose to do so.
Get caught in a lie and you WILL pay the price, one way or the other.
There are reasons management has decided to audit your database. You may, or may not, know what those reasons are. If they are looking to dump you  they are going to dump you no matter how good the audit turns out. But if they are looking for problem areas that need to be corrected this is your opportunity to make them aware of those areas since that can be used to justify getting the money you need to address them.
Got no backup server? That risks losing valuable corporate data and causing problems for users. So document that there is no backup server and the risks involved. That gives you a chance to seek money for a backup server. And so on. Use the audit as an opportunity to make a sales pitch for needing new hardware, software and people to get the job done.

Similar Messages

  • We are upgrading EHP4,What are the scenarios we will check in ECC and APO

    Hi gurus,
    We are upgrading (ECC )EHP4
    What are the scenarios we will check in ECC and APO, kindly tell me gurus.
    Regards
    babu

    Babu,
    We live within a dream. The आत्मन् is real, all else is Illusion. Names are illusion.  If DB49 does not suit you, then call me nameless.
    Before you even release the software into the test environment, you must perform unit testing.  Can every transaction that is used by your company be executed?  Does every userexit/enhancement still perform the same task?  Does every custom report work the same? All interfaces passing the proper data?
    Merely testing the software itself will not give your company any assurance that it will support your business after you go live with it, so after unit testing comes integration testing and user acceptance testing.  You must interview Key business users, and from their input you must develop and execute tests for 'business processes'.  For example, one common business scenario (which contains many business processes), Order to Cash:  Check whether your upgraded systems supports your ability to receive and enter an order, plan the parts, obtain the RM, build the parts ship the order, and book the cash.  Or, another Scenario, Procure to Pay:  Check if you can plan RM parts, create/release PR, create PO, send PO to Vendor, receive PO in stock, pay invoice, close month for accounting purposes.
    These are two major business scenarios in most companies that use ERP.  There are hundreds more that can be tested, If you work for a company that cannot afford to have any disruption in their business, then all activities that are normally done by any business user should be tested.
    On the SCM side, during an ERP update, you have a smaller task (SAP usually does a good job with backward compatibility with their own modules).  BW extractors must be tested.  All integration models must be tested.  All userexits must be tested.  Publishing results/releasing results to ERP must be tested. The list goes on and on depending upon which SCM modules you have implemented.
    Regards,
    DB49

  • HT201250 Hi what is the next system that I should upgrade from Mac OS X 10.6.8? And, should I backup before downloading it?

    Hi what is the next system that I should upgrade from Mac OS X 10.6.8? And, should I backup before downloading it?

    You should backup before installing any new system updates or upgrades. Depending upon what your machine is qualified for you could upgrade to Lion or Mountain Lion.
    Upgrade Paths to Snow Leopard, Lion, and/or Mountain Lion
    You can upgrade to Mountain Lion from Lion or directly from Snow Leopard. Mountain Lion can be downloaded from the Mac App Store for $19.99. To access the App Store you must have Snow Leopard 10.6.6 or later installed.
    Upgrading to Snow Leopard
    You must purchase Snow Leopard through the Apple Store: Mac OS X 10.6 Snow Leopard - Apple Store (U.S.). The price is $19.99 plus tax. You will be sent physical media by mail after placing your order.
    After you install Snow Leopard you will have to download and install the Mac OS X 10.6.8 Update Combo v1.1 to update Snow Leopard to 10.6.8 and give you access to the App Store. Access to the App Store enables you to download Mountain Lion if your computer meets the requirements.
         Snow Leopard General Requirements
           1. Mac computer with an Intel processor
           2. 1GB of memory
           3. 5GB of available disk space
           4. DVD drive for installation
           5. Some features require a compatible Internet service provider;
               fees may apply.
           6. Some features require Apple’s iCloud services; fees and
               terms apply.
    Upgrading to Lion
    If your computer does not meet the requirements to install Mountain Lion, it may still meet the requirements to install Lion.
    You can purchase Lion by contacting Customer Service: Contacting Apple for support and service - this includes international calling numbers. The cost is $19.99 (as it was before) plus tax.  It's a download. You will get an email containing a redemption code that you then use at the Mac App Store to download Lion. Save a copy of that installer to your Downloads folder because the installer deletes itself at the end of the installation.
         Lion System Requirements
           1. Mac computer with an Intel Core 2 Duo, Core i3, Core i5, Core i7,
               or Xeon processor
           2. 2GB of memory
           3. OS X v10.6.6 or later (v10.6.8 recommended)
           4. 7GB of available space
           5. Some features require an Apple ID; terms apply.
    Upgrading to Mountain Lion
    To upgrade to Mountain Lion you must have Snow Leopard 10.6.8 or Lion installed. Purchase and download Mountain Lion from the App Store. Sign in using your Apple ID. Mountain Lion is $19.99 plus tax. The file is quite large, over 4 GBs, so allow some time to download. It would be preferable to use Ethernet because it is nearly four times faster than wireless.
         OS X Mountain Lion - System Requirements
           Macs that can be upgraded to OS X Mountain Lion
             1. iMac (Mid 2007 or newer) - Model Identifier 7,1 or later
             2. MacBook (Late 2008 Aluminum, or Early 2009 or newer) - Model Identifier 5,1 or later
             3. MacBook Pro (Mid/Late 2007 or newer) - Model Identifier 3,1 or later
             4. MacBook Air (Late 2008 or newer) - Model Identifier 2,1 or later
             5. Mac mini (Early 2009 or newer) - Model Identifier 3,1 or later
             6. Mac Pro (Early 2008 or newer) - Model Identifier 3,1 or later
             7. Xserve (Early 2009) - Model Identifier 3,1 or later
    To find the model identifier open System Profiler in the Utilities folder. It's displayed in the panel on the right.
         Are my applications compatible?
             See App Compatibility Table - RoaringApps.
         For a complete How-To introduction from Apple see Upgrade to OS X Mountain Lion.

  • I was trying to send a video via iMessage over wifi, but was only allowed to send a fraction due to the size limit. Does anyone know what exactly the limit is? Thanks!!

    I was trying to send a video via iMessage over wifi, but was only allowed to send a fraction of the video due to the size limit. Does anyone know what exactly the limit is? Thanks!!

    You said:  "I've never tried the restore function in disk utility. Would that be the same as cloning the drive?
    YES!  See the my old instructions below.  What you might try after step 5 is to restart you MBP holding down the Option key.  Select the new HDD icon and see if it boots.  This way you will know that the new HDD is operable.
    Ciao.
    INSTALLING A NEW HDD IN A MB
    1. Make certain that you have backed up all of your important data.
    2. You will need a HDD enclosure.  One with a USB connection will do.  A 9 pin Firewire is better.
    3. Install your new drive in the enclosure and connect it to your MBP.
    4. Open DISK UTILITY>ERASE.  From the left hand column drag the new drive into the 'Name' field.  Make sure that the format is 'Mac OS Extended (Journaled)'.  Click on the 'Erase' button.
    5. Click on the 'Restore' button (on top).  Drag the old drive into the 'Source' field and the new drive into the 'Destination'  field.  Click on the 'Restore' button on the bottom right hand corner.
      Depending upon the amount of data you are transferring, this may take a couple hours or more.  A Firewire will speed up the transfer.  This will result in both drives having identical information on them.
    6. After the data transfer has completed, you may swap the drives.  Start the MBP and you have finished the installation.  The initial boot may take a bit longer than you are accustomed to, but that is normal.
    7. When you are satisfied that the new hard drive if functioning properly, you can erase the old drive and use it for any needs that you may have.

  • What are the general errors will come in data uploading

    Hi Friends,
    What are the general errors will come in data uploading
    Thanks in Advance

    Paul
    It all depends on how we configure the system. Errors may be different for different scenerios like
    User ALEROMOTE Loacked for master data's
    Data Sourcs has to be replicated
    Activation Failures
    Error occures in data Selection Etc.
    Do you have any specific error so that we can work on that.
    Thanks
    Sat

  • What is the application "Agent.app" and should I 'allow' it?

    What is the application "Agent.app" and should I 'allow' it to accept incoming network connections? I've looked at the forums, and all other references talk about apps with titles "___agent.app" (with a suffix to it)...

    Nvm... now I can't figure out how to delete this post...

  • I want my iPhone to be replaced it is in warranty what are the things required will giving it to service centre

    i want my iPhone to be replaced it is in warranty what are the things required will giving it to service centre

    http://support.apple.com/kb/index?page=servicefaq&geo=United_States&product=ipho ne

  • What are the accounts that will hit while doing subcontracting process

    What are the accounts that will hit while doing subcontracting process?

    Hi Raj,
    In Case of Sub contract
    While doing Transfer Posting (Providing material to vendor) in MB1B or ME2O only Material document will be generated. No Accounting Document will be generated.
    While Receiving the Finished / Semifinished material both Material and Accounting documents will get generated and the accounting entries will be as under
    1. Stock Account (finished Account)                             BSX             - Debits    
    2. GR/IR clearing Account                                            WRX           - Credits   
    3. Change in Stock Account                                         BSV           - Credits  
    4. Processing Charges/Sub Contract Charges                FRL            - Debits   
    5. Stock Account (Raw Material)                                   BSX            - Credits  
    6. consumption from stock of material provided to vendor GBB(VBO)  - Debits   
    bye
    Sridhar Thota

  • What is the best app that i should have to store all my apps?

    what is the best app that i should have to organize all my apps?

    There isn't any app that can organize or manage other apps (other than iTunes on your computer itself). The iPad OS itself is the organizer - you can use it to put apps into folders.

  • What are the parts i will need for my ipod since my ipod screen remains completly blank white

    what are the parts i will need for my ipod since my ipod screen remains completly blank white

    - iOS: Not responding or does not turn on
    - Also try DFU mode after try recovery mode
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings
    - If not successful and you can't fully turn the iOS device fully off, let the battery fully drain. After charging for an least an hour try the above again.
    - Try on another computer
    - If still not successful that usually indicates a hardware problem and an appointment at the Genius Bar of an Apple store is in order.
    Apple Retail Store - Genius Bar       

  • What exactly the "recovery disc" does?

    I'm about to reinstall everything on my laptop but would like to know what exactly the "recovery disc" does....
    I presume that it formats the HDD with a clean install of the OS and that all the toshiba apps like disc recorder, VAP etc... are NOT installed and have to be installed afterwards??

    > {quote:title=Jayjay wrote:}{quote}
    > Well, the recovery CD contains a Toshiba image. The Toshiba image is a package and is contains a Windows OS, Toshiba drivers, tools and additional software.
    > Simply said it contains everything what you could find preinstalled on the Toshiba notebook.
    >
    > And Yes; the recovery CD formats the whole HDD (also the partitions) and installs everything again.
    > It sets the notebook back to the factory settings
    so its just the OS packed with toshiba software and drivers - guess i wont have to download all of the toshiba applicaitions just yet then :)

  • What r the conditions that u hav to check for automatic invoice split ( fro

    what r the conditions that u hav to check for automatic invoice split ( from order to proforma invoice)

    You can find out the exact fields which lead to invoice split in the Data VBRK/VBRP field of copy control between the order and the invoice type at item category level.
    Find out this routine.
    Go to VOFM tcode and Data transfer-----Billing documents
    Here you can see the routine. See the code behind this routine. This will give you the exact criteria used for invoice split in your specific case.
    By default,
    It is payer, payment terms, incoterms, Billing date
    Hope this helps.
    Reward if this helps.

  • What are the third party tools available for Encryption in Oracle database?

    Dear All,
    Can you please help me with the below question?
    What are the third party tools available for Encryption in Oracle database? Please let me know if you know their feedback and also licensing/cost information

    Why would you spend money to purchase a third-party tool that will be, almost by definition, less secure than the tools inside the product you already own and paid for?
    http://www.morganslibrary.org/reference/pkgs/dbms_crypto.html
    But were I to have any to recommend one I would not do so without knowing information you seem to consider unimportant such as:
    1. Operating system
    2. Database edition and version
    3. What type of data needs to be secured
    4. What level of security is required

  • For best performance what's the size of an image to be stored in database?

    Hi all,
    can any one tell me..for best performance what's the size of an image to be stored in database?
    is it <256kb  or >256mb?
    when i google  we can store image as varbinary(max) and its limit upto 2GB..
    Can anyone exlain it?
    is it performance wise better..
    thanx in advance..
    lucky

    Your question does not seem apparently meaningful. If you need to store a 5MB image in the database, you store a 5MB image, not a 200 KB image or a 200 MB image. Business needs always trumph performance.
    Not surprisingly, the larger the image the more resources it takes to read and write it.
    What is a meaningful question is whether you should use the FILESTREAM feature or not. The cut-off limit here is usually given as 1MB. That is, if your images typically exceeds 1MB you should use FILESTREAM and access the data through Win32
    API. If your images are generally below this size, you should stick to regular T-SQL.
    Erland Sommarskog, SQL Server MVP, [email protected]

  • What are the basic element of Base configuration of an oracle Database ?

    What are the basic element of Base configuration of an oracle Database ?

    889543 wrote:
    What are the basic element of Base configuration of an oracle Database ?check this link
    http://www.dbnest.com/entry/194/
    and if you want to configure oracle installation click below link .
    http://download.oracle.com/docs/cd/B19306_01/server.102/b14196/install002.htm
    --neeraj                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               

Maybe you are looking for

  • Is there any way to actually get a tech on a chat or phone call?

    I have been trying to find out why I can't download the latest version of Adobe Acrobat, and I just seem to be caught in an endless cycle. Every time I think I am going to get a contact number, I just get sent back to the beginning. Is anyone else ha

  • How do you make the Reflection of an Image go Closer to the Image itself?

    Hello there, I have been working with the reflections on an image or a video, but have a problem and no ideas on the web how to fix this. I am trying to put the reflection of a video that I have uploaded, closer to the video itself. When I play it, t

  • EVENTS : Arranging Photos in an Event Manually

    I have imported about 8000 photos and they are sorted in separate events. I would like to re-arrange the order of some of the photos in the events manually but when I try to do this via "sort photos", the manual option is greyed out and it won't let

  • Output Control - KOMPBV3

    Hello I created a new routine where I'm doing some validations, if they are meet then the message output will be available, the problem is that it is not working when the invoice is being created (VF01) because one validations is taking data from the

  • Can't import hourlong clip - how to edit down?

    I was going to import an hour long clip but apparently I can't import anything over 10 minutes. So, how do I edit the video into manageable segments without having to forkout for Final Cut Pro as recommended on the pop up? I only want a bit of sharew