Citations: ICFR

No citations match the current filters.
FireFighter Time Limits
Mapping
Reference: 08.03.08.07 C02d
FireFighter access is granted only for the minimum necessary period required to perform the activity.
FireFighter Governance
Mapping
Reference: 08.03.08.07 C02e
Controllers and Owners of FireFighter accounts are reviewed annually to ensure proper oversight.
FireFighter Request Access
Mapping
Reference: 08.03.08.07 C02f
Access to request FireFighter accounts is restricted to authorized personnel only.
FireFighter Account Assessment
Mapping
Reference: 08.03.08.07 C02g
FireFighter accounts are regularly assessed for validity and continued necessity.
Leaver Deactivation
Mapping
Reference: 08.03.08.08 C01a
User accounts are deactivated within five working days after the individual is marked as a leaver in the identity system.
IAM Interface Monitoring
Mapping
Reference: 08.03.08.08 C01b
The interface between target systems and the Identity & Access Management (CIDM) system is continuously monitored for errors.
Late Deactivation Monitoring
Mapping
Reference: 08.03.08.08 C01c
Any activity performed after a contract termination date must be discovered and escalated for assessment.
Job Change Review
Mapping
Reference: 08.03.08.09 C01a
Access entitlements for users who change job responsibilities are reviewed to ensure they are appropriate for the new role.
Security Baselines (Passwords)
Mapping
Reference: 08.03.08.11 C01a
Minimum Security Baselines (MSBs) for password settings are defined and implemented.
Password Monitoring
Mapping
Reference: 08.03.08.11 C01b
System password configuration deviations from the SAP Security Baseline are automatically monitored and addressed.
Security Exceptions
Mapping
Reference: 08.03.08.11 C01c
Exceptions to security baselines must be documented, time-bound, and approved by the IT security governance body.
Generic Account Security
Mapping
Reference: 08.03.08.12 C01a
Access to generic account credentials must be maintained in a controlled environment (e.g., LAAM Safe) and strictly limited.
Generic Account Review
Mapping
Reference: 08.03.08.12 C01b
Access to generic account login credentials is reviewed at least annually to ensure continued validity.
Generic Account Governance
Mapping
Reference: 08.03.08.12 C02a
Generic accounts are periodically reviewed to ensure they are registered in the IAM tool and have an active owner.
Generic Account Inventory
Mapping
Reference: 08.03.08.12 C03a
Completeness of the generic account inventory is ensured by reconciling IAM records against the target system.
Change Description
Mapping
Reference: 08.03.09.01 C01a
Every change record must include an appropriate description of the change being implemented.
ITSM Reconciliation
Mapping
Reference: 08.03.09.01 C01b
System changes must be reconcilable with corresponding records in the ITSM solution.
Change Impact Assessment
Mapping
Reference: 08.03.09.02 C01a
A formal impact assessment is performed and documented for every change.
Code Review
Mapping
Reference: 08.03.09.02 C02a
For relevant changes, a formal code review is performed and documented.
Change Testing
Mapping
Reference: 08.03.09.03 C01a
Changes are adequately tested based on their criticality and potential impact.
Pre-Production Testing
Mapping
Reference: 08.03.09.03 C01b
All changes are tested in a non-production environment prior to being implemented in production.
Change Approval
Mapping
Reference: 08.03.09.04 C01a
Changes must be approved by the appropriate level of management as per the defined process.
Production Migration Approval
Mapping
Reference: 08.03.09.04 C01b
Changes are moved to production only after all relevant approvals have been obtained.
Change SoD
Mapping
Reference: 08.03.09.04 C01c
Segregation of Duties rules are followed during the change approval and implementation process.
Change Management Access
Mapping
Reference: 08.03.09.04 C01d
Roles with critical access to the change management system are strictly restricted.
Emergency Change Approval
Mapping
Reference: 08.03.09.05 C01a
Emergency changes require approval by management or a delegate, including functional owners.
Post-Emergency Documentation
Mapping
Reference: 08.03.09.05 C01b
Documentation and testing for emergency changes must be updated retrospectively within 10 working days.
Emergency Justification
Mapping
Reference: 08.03.09.05 C01c
The justification for using the emergency change process must be confirmed within 10 working days.
Direct Production Changes
Mapping
Reference: 08.03.09.06 C01a
Scenarios for direct changes in production are clearly defined and exceptions are followed up.
System Locking/Unlocking
Mapping
Reference: 08.03.09.06 C01b
Approvals for unlocking systems for direct changes are documented, and systems are locked immediately after completion.
Vendor Update Assessment
Mapping
Reference: 08.03.09.07 C01a
Software updates and release notes from vendors are assessed for impact before implementation.
Infrastructure Baselines
Mapping
Reference: 08.03.11.01 C01a
Minimum Security Baselines (MSBs) are defined and implemented for infrastructure components.
Configuration Monitoring
Mapping
Reference: 08.03.11.01 C01b
Deviations from infrastructure security baselines are periodically monitored and addressed based on criticality.
Infrastructure Exceptions
Mapping
Reference: 08.03.11.01 C01c
Exceptions to infrastructure security baselines must be documented and approved by the security governance body.
Audit Log Protection
Mapping
Reference: 08.03.11.02 C01a
Access to edit or delete the security audit logs is strictly prohibited.
Audit Log Config Restriction
Mapping
Reference: 08.03.11.02 C01b
Access to modify the configuration of audit logs is restricted to authorized personnel only.
Audit Log Retention
Mapping
Reference: 08.03.11.02 C02a
Critical events are recorded in the security audit log and stored for a minimum of two years.
Audit Log Completeness
Mapping
Reference: 08.03.11.02 C03a
Security audit logs must be active and monitored for completeness (no missing critical entries).
Audit Log Event Review
Mapping
Reference: 08.03.11.02 C03b
Events recorded in the security audit logs are reviewed and assessed for potential security risks.
Monitoring Inventory
Mapping
Reference: 08.03.12.01 C01a
An inventory of technical objects that require active monitoring is maintained and updated.
Interface/Process Monitoring
Mapping
Reference: 08.03.12.01 C02a
Automated processes and interfaces are monitored to identify critical errors or downtime in a timely manner.
Incident Resolution
Mapping
Reference: 08.03.12.01 C03a
IT support personnel follow up on and address critical errors or unexpected downtimes in a timely manner.
Security Patch Review
Mapping
Reference: 08.03.12.02 C01a
Security notifications and upgrades from vendors are regularly reviewed to identify required patches.
Security Patch Assessment
Mapping
Reference: 08.03.12.02 C01b
Security patches are assessed for impact and documented before being implemented in the environment.
Patch Exceptions
Mapping
Reference: 08.03.12.02 C01c
Exceptions for not applying critical security patches must be documented and approved by the governance body.
SoD Risk Review
Mapping
Reference: AC01a
Access requests undergo a review by role approvers and SoD champions to manage Segregation of Duties risks.
SoD Dashboard Monitoring
Mapping
Reference: AC01b
The SoD Dashboard is regularly monitored, and conflicts are addressed within defined timelines.
Mitigated Risk Review
Mapping
Reference: AC01c
Periodic reviews of users with mitigated SoD risks are conducted to ensure controls remain effective.
Custom Transaction Evaluation
Mapping
Reference: AC02a
New and custom transaction codes are evaluated to ensure they do not introduce SoD risks.
Role Assessment
Mapping
Reference: AC02b
New and existing roles are assessed to prevent SoD risks and ensure no prohibited actions are permissible.
SOC 1 Review
Mapping
Reference: TP01a
Vendor SOC 1 Type 2 reports are reviewed on time, and all Complementary User Entity Controls (CUECs) are identified and implemented.
Graph Explorer