Transcription of Regulatory Compliance and Database Management
1 White PaperRegulatory Complianceand DatabaseManagementMarch 2006 IntroductionTop of mind in business executives today is how to meetnew Regulatory Compliance and corporate laws are changing the way companies collect, retain,and manage information. DBAs need to understand whatis happening in the corporate business world and how itwill directly impact their job each new year arrives, it brings with it new challengesfor IT organizations that support business. Whether a newcalendar year with renewed budgets or start of a newquarter, there are sure to be new projects for IT. Almostassured, one of the projects at the top of the list will beone of Regulatory Compliance as the time grows near forcompany executives to again verify Compliance with theSarbanes-Oxley Act (SOX).
2 Section 404 of the SOX Actmandates that executive Management of publicly heldcompanies must evaluate and report on the effectivenessof their internal controls over financial reporting, and haveindependent auditors substantiate the effectiveness of theprocedures and internal controls for financial to New RegulationsAlthough the primary purpose of SOX is to assure corporategovernance standards of financial reporting and auditing,wider interpretation can include IT operational processesthat support a business. Company's executives are nowreaching out to IT to access and provide record of policies,process, and procedures that control access and protect theintegrity of financials systems and business applications,across networks, servers and into databases where thedata is stored.
3 As IT organizations start to address SOX,questions are being raised on how far does it reach, whatis affected, and what should be reviewed and there is guidance available from various sources,there has yet to appear a definitive set of guidelines that is not open to interpretation. Offered only as examples to assist in meeting Compliance , here are five potentialways an organization might fail an upcoming audit if notproperly prepared: No security Management or demonstration of security forsystems of financial record or systems that could affectfinancial systems integrity. Companies must assurethat financial information is safe from unauthorizedoutside or internal influences.
4 Not having documented procedures, records or changes,or auditable demonstration of change managementwhen System, Database , and Network Administratorsmake alterations or updates on systems of financialrecord or those systems that could affect financial systems integrity. Proper change Management mustexist to ensure that software and hardware changes are controlled and recorded. No documented disaster recovery plan or auditableverification of successful plan execution of recoverabilityof systems of financial record. This includes demonstratingrecoverability of financial systems for reasonable businesscontinuance with minor business impact.
5 No matter the size or the complexity of the system, organizationsmust assure recovery within a period of time that ensuresavailability of financial data in a timely manner. Database logging not enabled, logs not secured, noreporting of Database transactions, or demonstration of log audit reporting for financial systems of record or systems that could affect financial systems Database logging and log reporting, it next toimpossible to identify who changed what in the data-base. Database Administration change managementcomparisons should be verified against Database logreports to ensure all Database alterations are recordedand verifiable.
6 Backups or data movement onto disk, tape, or stored atthird-party sites is not secured and tracked. Unsecuredfinancial data can be vulnerable to theft, unauthorizedviewing, or alteration. For instance, a TransportableTablespace of a Database could potentially be moved andreattached to another Database enabling unauthorizedviewing. Database archival, backups, loading andunloading, administration change Management andreporting should be performed and routinely verified to ensure that data is section 404 s requires an external auditor s opinionon the effectiveness of internal controls. For audit, andquarterly certification, companies need to demonstrate whatcontrol changes are implemented to attest to integrity,confidentiality and non-repudiation of financial reporting.
7 Ifprocess controls can be bypassed, executive managementcannot with certainty sign off on the adequacy of controlsfor financial data SOX legislation is relatively new and affects a majority ofcompanies today, the SEC has identified guidelines providedby the Committee of Sponsoring Organizations of theTreadway Commission (COSO) in evaluating internal controls. IT control requirements are most often derived fromSOX regulation internal controls sections 302 and (COSO) does provides a general framework foraccounting internal controls, but not IT specific, organizationscan find IT specific models available within the ControlObjectives for Information and related Technology (COBIT )to assist with SOX Compliance .
8 Created by InformationTechnology Governance Institute (ITGI) , the COBIT Framework provides control objectives focusingon the processes specific to the IT aligns with the general COSO framework withinternal controls consisting of 4 domains, 34 processesand over 225 detailed control objectives aligning with theIT implementation cycle. The Domains are Planning andOrganization, Acquisition and Implementation, Deliveryand Support, and Monitor and Evaluate. A few examplesof the processes defined that address the enterprise dataenvironment are: Acquire and Maintain Application Software Acquire and Maintain Technology Infrastructure Ensure Systems Security Manage the Configuration Manage Problems and Incidents Manage Data Manage OperationsCOBIT key controls and questions assist in measurementand assessment of current processes, process controlobjectives, success criteria for process implementation andmetrics to evaluate and quantifying process help drive IT governance and Compliance byaligning IT decisions with business controls in COBIT include such activities as.
9 Separation of duties Effective change Management Effective change documentation Release Processes Control Processes Resolution ProcessesKey Questions a DBA Should Be Prepared to Answer/DemonstrateBy no means a definitive list or one that assures Compliance ,these sample questions can help ascertain your data anddatabase Management knowledge on the subject matter in preparation for audit. At a minimum, DBAs should bereviewing their practices for Database archival, backups,loading and unloading, administration change managementand reporting. Have data integrity ownership and responsibilities beencommunicated to appropriate data/business ownersand their acceptance of responsibilities?
10 Are key Database systems inventoried, owners identifiedand documented: Number of databases and instances Type and version of the Database software installed Type and version of the underlying operating system Database users and privileges compared with usersystem security Related applications accessing or transacting withthe Database ( , ERP, web, custom) Utilities and tools that can access, manage, orchange the Database or data Organization charts identifying system owners andmaintainers Do you have Change Management in place so you canyou attest to any changes or alterations? Where are the risks to financial data stored in databasesdocumented?