Blog - ERP Risk Advisors
327
blog,ajax_fade,page_not_loaded,,qode_grid_1300,footer_responsive_adv,hide_top_bar_on_mobile_header,qode-child-theme-ver-1.0.0,qode-theme-ver-16.7,qode-theme-bridge,wpb-js-composer js-comp-ver-5.5.2,vc_responsive
 

Blog

fresh content added weekly

Two Day Training Class: Auditing Oracle's® Fusion ERP Cloud Application Is your company using Oracle's Fusion / ERP Cloud apps?  Consider joining us for upcoming training from an audit perspective.   Auditing Oracle's® Fusion ERP Cloud Application - ASE151   New York - 13-14-SepSan Francisco  - 8-9-Nov   Details can be found...

CaoSys and ERP Risk Advisors Announce New Accelerated Implementation and Subscription Pricing for their Segregation of Duties Solution, CS*ComplyCaoSys is pleased to announce their leading SoD solution, CS*Comply, for Oracle E-Business Suite is now available with Subscription pricing.  CaoSys has partnered with ERP Risk Advisors...

ERP Risk Advisors at Collaborate 2018_Major AnnouncementsERP Risk Advisors will be presenting again this year at Collaborate 18 in Las Vegas, April 22-26.  At Collaborate we will be announcing and discussing in more detail several major enhancements to our partner network and services as follows:·      ...

ERP Cloud: Risk Management Cloud Certifications and Services***  PRESS RELEASE ***ERP Risk Advisors is pleased to announce a second of our resources is certified on the Financial Reporting Compliance (FRC) module of the Risk Management Cloud.  Donna Curtis was one of the first to attain...

ERP Risk Advisors to present at OAUG's Risk WeekERP Risk Advisors founder and CEO, Jeffrey T. Hare, CPA CIA CISA, will be presenting at OAUG's risk week.  His presentation is titled "ERP Risk Advisors and CaoSys: The Premier GRC Offering for Oracle E-Business Suite"The presentation...

Welcome to 2018!  Big news for ERP Risk Advisors!!!With a new year brings exciting news at ERP Risk Advisors.  Happy New Year! We wish you the best for 2018.First, we are pleased to welcome a new member to our team, Donna Curtis, who will be...

ERP Risk Advisors: Don’t Give Up on Your Advanced Controls InvestmentOracle has announced it will no longer sell their Advanced Controls suite for Oracle E-Business Suite and has ended premier support.  Many organizations have made a substantial investment in the implementation and use of these...

Upcoming ERP Risk Advisors webinars_July 2017You are invited to attend three upcoming webinars taking place over the next couple of weeks as follows:Don’t give up on your Oracle Advanced Controls investment – Tuesday, July 11How to automate controls using CaoSys’ newest features – Wednesday,...

ERP Risk Advisors Announces Oracle Advanced Controls Premier SupportAs most customers are aware Oracle announced an end to the continued development of its Advanced Controls Suite and the end of Premier Support as of September 2016 (See MOS Note: 2143036.1). Oracle has been developing a...

ERP Risk Advisors now support's Oracle Advanced Controls SuiteERP Risk Advisors has hired a new highly-qualified resource that knows Oracle’s Advanced Controls suite very, very well.  We can now bring to our clients the most comprehensive risk-based rules matrix in the market for use with...

Security Standards for Oracle E-Business Suite: DMZ Configuration GuideIn my last blog (see http://jeffreythare.blogspot.com/2017/01/security-standards-for-oracle-e.html) we discussed Oracle’s Secure Configuration Guide (MOS Note 403537.1).  Another critical document that Oracle publishes is their DMZ configuration document (MOS Note 380490.1).  Every step must be meticulously followed or your...

Why Utilities Diagnostics Should NOT Be In Scope for SOX The setting of the Utilities: Diagnostics profile option has been a source of scrutiny for our clients over the past few years.  Some auditors have suggested that access in Production allowed by the setting...

Oracle E-Business Suite: SYSADMIN must have password expiration setThe risks related to SYSADMIN are often misunderstood.  It is a critical account to leave active, yet we find that many organizations don't set the password expiration days because they fear that the account will be locked...

2e2 - maker of Config Snapshot software has forced into bankruptcy in the U.K. Not sure if y'all have been following the potential liquidiation of 2e2 - maker of the Config Snapshot software.  Find out more at:http://www.channelregister.co.uk/Tag/2e2I have yet to hear from my contacts at...

Webinar - SQL Forms in Oracle E-Business Suite - what are they and why should auditors care?When: Thu, Feb 14, 2013 2:00 PM - 3:00 PM ESTDescription:SQL Forms are forms that accept SQL statements (or portions thereof) withing an application form.  Having access to certain...

2013 will be the year folks learn about Oracle's Skeletons in their E-Business Suite Closet...

We are excited to announce that OAUG just published an article I wrote called "Why Implementations Fail, Beyond the Obvious". The article can be downloaded at: http://erpra.net/files/ERPRA_Why_Implementations_Fail_Beyond_the_Obvious_OAUG_Insight.pdf.Please read the article and provide any comments on my blog. Feel free to send me any questions...

In R12 of E-Business Suite, Oracle introduced Multi-Org Access Control (MOAC) to provide users with the ability to view data and process data across operating units. This new functionality is welcome by organizations that process data and want to view data across operating units –...

You Tube channel has all web blogs. Links are also available on our website.Here are the topics for the latest two:-Impact of Responsibilities using a custom application on SLA programs-AR Adjustment Limits System Design FlawRegards,Jeffrey T. Hare, CPA CISA CIAjhare@erpra.netLI profile: http://www.linkedin.com/in/jeffreythare...

Here is the first web-blog I've done. Hopefully today's topic will be of interest to you and future topics will be as well. Today's web blog can be accessed at: http://erpra.net/bestpractices.html.Contact me with any questions or suggestions on future blog topics at jhare@erpra.net.Regards,Jeffrey...

Got a question today about password resets:"I am trying to figure something out. How do we validate that Oracle forces the user to change their password upon first login/admin reset? I thought it was something in the profile options. Thank you for...

Reviewing docs for a client today and ran across this comment in a document "I believe that there are audit reporting requirements to provide evidence of workflow approvals of changes to compensation or position-related edits"Question: Does your company property maintain workflow history for approvals? ...

Great response to Top 10 Fraud Risks in an E-Business Suite Environment. Had some technical difficulties with GoToWebinar (a first for me). Not sure if the full webinar was recorded. Will try to post this our website as well as the slides...

Look at Metalink Note 227010.1. This note is for "Script to check for Default Passwords being used for some common usernames."Why just 'common' usernames? Why not all usernames? Why can't they maintain this document and the related test scripts for all known...