Facebook Twitter LinkedIn

A new Approach for Compliance Management

Combined Session
Tuesday, May 08, 2007 16:30—17:30

KPN’s 'fixed network' division had to prepare for a SOX compliance review as from January 2007. KPN launched various parallel initiatives, including both an identity management improvement programme and a SOX compliance programme. The identity programme aimed at making sure the authorisations in the various applications were appropriate. The SOX compliance programme had as mission to demonstrate that KPN had sufficient control over authorisations in the SOX-material applications. In total, 48 applications were considered SOX-material. These applications spanned a wide range of standard packages such as SAP as well as many in-house developed applications running on a wide variety of platforms.

A team from PwC first performed a pilot with regard to analysing the authorisations in KPN's billing applications. They had to select a tool that was not tied to any particular technology solution. This criteria puts tools such as ACE or Virsa's compliance calibrator out of the question, since they only handle SAP. KPN has a whole range of systems, and they preferred a single tool capable of addressing them all. For this reason, Eurekify’s Sage product was selected. The NIST’s RBAC model (role based access control) was used as a unification mechanism across the various applications. The Sage ‘business process rule’ feature was used to capture business controls such as segregation of duty.

As the pilot was considered successful, the team continued and implemented SOX-based ‘business process rules’ for all 48 SOX-material applications. This was done in approximately three months. The SOX ‘business process rules’ are now executed periodically to demonstrate ongoing compliance for KPN.

A new Approach for Compliance Management
Presentation deck
A new Approach for Compliance Management
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Hanco Gerritse
Hanco Gerritse
KPN
Hanco Gerritse ist Leiter Finanzen der internen IT-Abteilung von KPN, die frühere köinglich-niederländische Post & Telefon Gesellschaft . KPN bietet heute Privatkunden und...
Marc Sel
Marc Sel
PwC Belgium
Marc Sel is Director in the “Enterprise Advisory” Department within PricewaterhouseCoopers since 1998. Prior he moved through positions with Texas Instruments, Alcatel and Esso. ...
Subscribe for updates
Please provide your email address