Example: stock market

Regulatory Compliance and Database Management

White PaperRegulatory Complianceand DatabaseManagementMarch 2006 IntroductionTop of mind in business executives today is how to meetnew Regulatory Compliance and corporate laws are changing the way companies collect, retain,and manage information. DBAs need to understand whatis happening in the corporate business world and how itwill directly impact their job each new year arrives, it brings with it new challengesfor IT organizations that support business. Whether a newcalendar year with renewed budgets or start of a newquarter, there are sure to be new projects for IT. Almostassured, one of the projects at the top of the list will beone of Regulatory Compliance as the time grows near forcompany executives to again verify Compliance with theSarbanes-Oxley Act (SOX). Section 404 of the SOX Actmandates that executive Management of publicly heldcompanies must evaluate and report on the effectivenessof their internal controls over financial reporting, and haveindependent auditors substantiate the effectiveness of theprocedures and internal controls for financial to New RegulationsAlthough the primary purpose of SOX is to assure corporategovernance standards of financial reporting and auditing,wider interpretation can include IT operational processesthat support a business.

Introduction Top of mind in business executives today is how to meet new regulatory compliance and corporate governance. New laws are …

Tags:

  Database, Management, Regulatory, Compliance, Regulatory compliance and database management

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Regulatory Compliance and Database Management

1 White PaperRegulatory Complianceand DatabaseManagementMarch 2006 IntroductionTop of mind in business executives today is how to meetnew Regulatory Compliance and corporate laws are changing the way companies collect, retain,and manage information. DBAs need to understand whatis happening in the corporate business world and how itwill directly impact their job each new year arrives, it brings with it new challengesfor IT organizations that support business. Whether a newcalendar year with renewed budgets or start of a newquarter, there are sure to be new projects for IT. Almostassured, one of the projects at the top of the list will beone of Regulatory Compliance as the time grows near forcompany executives to again verify Compliance with theSarbanes-Oxley Act (SOX). Section 404 of the SOX Actmandates that executive Management of publicly heldcompanies must evaluate and report on the effectivenessof their internal controls over financial reporting, and haveindependent auditors substantiate the effectiveness of theprocedures and internal controls for financial to New RegulationsAlthough the primary purpose of SOX is to assure corporategovernance standards of financial reporting and auditing,wider interpretation can include IT operational processesthat support a business.

2 Company's executives are nowreaching out to IT to access and provide record of policies,process, and procedures that control access and protect theintegrity of financials systems and business applications,across networks, servers and into databases where thedata is stored. As IT organizations start to address SOX,questions are being raised on how far does it reach, whatis affected, and what should be reviewed and there is guidance available from various sources,there has yet to appear a definitive set of guidelines that is not open to interpretation. Offered only as examples to assist in meeting Compliance , here are five potentialways an organization might fail an upcoming audit if notproperly prepared: No security Management or demonstration of security forsystems of financial record or systems that could affectfinancial systems integrity. Companies must assurethat financial information is safe from unauthorizedoutside or internal influences.

3 Not having documented procedures, records or changes,or auditable demonstration of change managementwhen System, Database , and Network Administratorsmake alterations or updates on systems of financialrecord or those systems that could affect financial systems integrity. Proper change Management mustexist to ensure that software and hardware changes are controlled and recorded. No documented disaster recovery plan or auditableverification of successful plan execution of recoverabilityof systems of financial record. This includes demonstratingrecoverability of financial systems for reasonable businesscontinuance with minor business impact. No matter the size or the complexity of the system, organizationsmust assure recovery within a period of time that ensuresavailability of financial data in a timely manner. Database logging not enabled, logs not secured, noreporting of Database transactions, or demonstration of log audit reporting for financial systems of record or systems that could affect financial systems Database logging and log reporting, it next toimpossible to identify who changed what in the data-base.

4 Database Administration change managementcomparisons should be verified against Database logreports to ensure all Database alterations are recordedand verifiable. Backups or data movement onto disk, tape, or stored atthird-party sites is not secured and tracked. Unsecuredfinancial data can be vulnerable to theft, unauthorizedviewing, or alteration. For instance, a TransportableTablespace of a Database could potentially be moved andreattached to another Database enabling unauthorizedviewing. Database archival, backups, loading andunloading, administration change Management andreporting should be performed and routinely verified to ensure that data is section 404 s requires an external auditor s opinionon the effectiveness of internal controls. For audit, andquarterly certification, companies need to demonstrate whatcontrol changes are implemented to attest to integrity,confidentiality and non-repudiation of financial reporting.

5 Ifprocess controls can be bypassed, executive managementcannot with certainty sign off on the adequacy of controlsfor financial data SOX legislation is relatively new and affects a majority ofcompanies today, the SEC has identified guidelines providedby the Committee of Sponsoring Organizations of theTreadway Commission (COSO) in evaluating internal controls. IT control requirements are most often derived fromSOX regulation internal controls sections 302 and (COSO) does provides a general framework foraccounting internal controls, but not IT specific, organizationscan find IT specific models available within the ControlObjectives for Information and related Technology (COBIT )to assist with SOX Compliance . Created by InformationTechnology Governance Institute (ITGI) , the COBIT Framework provides control objectives focusingon the processes specific to the IT aligns with the general COSO framework withinternal controls consisting of 4 domains, 34 processesand over 225 detailed control objectives aligning with theIT implementation cycle.

6 The Domains are Planning andOrganization, Acquisition and Implementation, Deliveryand Support, and Monitor and Evaluate. A few examplesof the processes defined that address the enterprise dataenvironment are: Acquire and Maintain Application Software Acquire and Maintain Technology Infrastructure Ensure Systems Security Manage the Configuration Manage Problems and Incidents Manage Data Manage OperationsCOBIT key controls and questions assist in measurementand assessment of current processes, process controlobjectives, success criteria for process implementation andmetrics to evaluate and quantifying process help drive IT governance and Compliance byaligning IT decisions with business controls in COBIT include such activities as: Separation of duties Effective change Management Effective change documentation Release Processes Control Processes Resolution ProcessesKey Questions a DBA Should Be Prepared to Answer/DemonstrateBy no means a definitive list or one that assures Compliance ,these sample questions can help ascertain your data anddatabase Management knowledge on the subject matter in preparation for audit.

7 At a minimum, DBAs should bereviewing their practices for Database archival, backups,loading and unloading, administration change managementand reporting. Have data integrity ownership and responsibilities beencommunicated to appropriate data/business ownersand their acceptance of responsibilities? Are key Database systems inventoried, owners identifiedand documented: Number of databases and instances Type and version of the Database software installed Type and version of the underlying operating system Database users and privileges compared with usersystem security Related applications accessing or transacting withthe Database ( , ERP, web, custom) Utilities and tools that can access, manage, orchange the Database or data Organization charts identifying system owners andmaintainers Do you have Change Management in place so you canyou attest to any changes or alterations?

8 Where are the risks to financial data stored in databasesdocumented? How often are they reviewed and updated? Is the data that is extracted, archived, or backed up,properly secured and tracked? How are division of roles and responsibilities (segregation of duties) setup so that it prevents aDatabase Administrator (DBA) from unauthorized data viewing, alterations, or deletions? What are the Database Management process controls?Where are they documented for review? What monitoringand reporting do you have in place? Can you demonstratethis (pick randomly) one to me now? When was the last time the Database Managementcontrol methods were tested, gaps identified and controls improved? Do you understand and accept the responsibility regardinginternal controls for the databases you manage?Before your executive Management signoffs on SOX, whatprocesses has your IT department put in place to preventauthorized users from accessing, altering, accidentally or deliberately deleting data that could result in incorrectfinancial reporting?

9 Are you prepared when an auditorasks, "where are your documented processes and can you demonstrate them"? Are those processes just what ittakes to pass an initial audit, or industry standard practiceslike COBIT that are repeatable and supportable whenresources move on to other roles or depart the company?If not, then now is the time to kick-off a project to havethem For AuditAuditors are seeking validation that the DBMS maintainsaccurate and reliable data, control of objects and data is by authorized users only, and proper backup and datarestoration is provided. Organizations need to have controlsto ensure that qualified DBAs:3 Are responsible for ensuring Database retains financialdata integrity and are accountable if a Database is compromised Track and approve all Database modifications and manage the security of the Database by the properroles and access Management Validate Database backup and recovery of the largest ofdatabases within a reasonable time to meet businesscontinuance audit preparation for a best practice review or audit, DBAsshould:1.

10 Perform active discovery daily and maintain an inventoryof all financial system databases, databases with whichthey exchange data, and databases objects associated with financial data2. Establish and document repeatable best practices fordatabase change Management : for managing objectpermissions, schema changes, roles and privileges to eliminate risk of unauthorized viewing, altering, or copying of data3. Ensure protection of Database transaction logs fromalteration and deletion, perform Database log audit validation of databases changes and implement proactive log analysis and rapid corrective action and when unauthorized changes occur4. Conduct Database backups or exports, and routinelyverify data is secured and can demonstrate recoverabilitywithin reasonable period of time for business continuanceFor those companies with large and complex databases oreven a number of different Database types, the four taskslisted above could quickly overcome data or databaseadministration staff if performed manually.


Related search queries