Citations: ICFR
No citations match the current filters.
FireFighter Time Limits
Mapping
Reference: 08.03.08.07 C02d
FireFighter access is granted only for the minimum necessary period required to perform the activity.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
FireFighter Governance
Mapping
Reference: 08.03.08.07 C02e
Controllers and Owners of FireFighter accounts are reviewed annually to ensure proper oversight.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
FireFighter Request Access
Mapping
Reference: 08.03.08.07 C02f
Access to request FireFighter accounts is restricted to authorized personnel only.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
FireFighter Account Assessment
Mapping
Reference: 08.03.08.07 C02g
FireFighter accounts are regularly assessed for validity and continued necessity.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Leaver Deactivation
Mapping
Reference: 08.03.08.08 C01a
User accounts are deactivated within five working days after the individual is marked as a leaver in the identity system.
Authority Document
Mapped Control Objectives (1)
IAM Interface Monitoring
Mapping
Reference: 08.03.08.08 C01b
The interface between target systems and the Identity & Access Management (CIDM) system is continuously monitored for errors.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Late Deactivation Monitoring
Mapping
Reference: 08.03.08.08 C01c
Any activity performed after a contract termination date must be discovered and escalated for assessment.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Job Change Review
Mapping
Reference: 08.03.08.09 C01a
Access entitlements for users who change job responsibilities are reviewed to ensure they are appropriate for the new role.
Authority Document
Mapped Control Objectives (1)
Security Baselines (Passwords)
Mapping
Reference: 08.03.08.11 C01a
Minimum Security Baselines (MSBs) for password settings are defined and implemented.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Password Monitoring
Mapping
Reference: 08.03.08.11 C01b
System password configuration deviations from the SAP Security Baseline are automatically monitored and addressed.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Security Exceptions
Mapping
Reference: 08.03.08.11 C01c
Exceptions to security baselines must be documented, time-bound, and approved by the IT security governance body.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Generic Account Security
Mapping
Reference: 08.03.08.12 C01a
Access to generic account credentials must be maintained in a controlled environment (e.g., LAAM Safe) and strictly limited.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Generic Account Review
Mapping
Reference: 08.03.08.12 C01b
Access to generic account login credentials is reviewed at least annually to ensure continued validity.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Generic Account Governance
Mapping
Reference: 08.03.08.12 C02a
Generic accounts are periodically reviewed to ensure they are registered in the IAM tool and have an active owner.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Generic Account Inventory
Mapping
Reference: 08.03.08.12 C03a
Completeness of the generic account inventory is ensured by reconciling IAM records against the target system.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Change Description
Mapping
Reference: 08.03.09.01 C01a
Every change record must include an appropriate description of the change being implemented.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
ITSM Reconciliation
Mapping
Reference: 08.03.09.01 C01b
System changes must be reconcilable with corresponding records in the ITSM solution.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (2)
Change Impact Assessment
Mapping
Reference: 08.03.09.02 C01a
A formal impact assessment is performed and documented for every change.
Authority Document
Mapped Control Objectives (1)
Code Review
Mapping
Reference: 08.03.09.02 C02a
For relevant changes, a formal code review is performed and documented.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Change Testing
Mapping
Reference: 08.03.09.03 C01a
Changes are adequately tested based on their criticality and potential impact.
Authority Document
Mapped Control Objectives (1)
Pre-Production Testing
Mapping
Reference: 08.03.09.03 C01b
All changes are tested in a non-production environment prior to being implemented in production.
Authority Document
Mapped Control Objectives (1)
Change Approval
Mapping
Reference: 08.03.09.04 C01a
Changes must be approved by the appropriate level of management as per the defined process.
Authority Document
Mapped Control Objectives (1)
Production Migration Approval
Mapping
Reference: 08.03.09.04 C01b
Changes are moved to production only after all relevant approvals have been obtained.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Change SoD
Mapping
Reference: 08.03.09.04 C01c
Segregation of Duties rules are followed during the change approval and implementation process.
Authority Document
Mapped Control Objectives (1)
Change Management Access
Mapping
Reference: 08.03.09.04 C01d
Roles with critical access to the change management system are strictly restricted.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Emergency Change Approval
Mapping
Reference: 08.03.09.05 C01a
Emergency changes require approval by management or a delegate, including functional owners.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Post-Emergency Documentation
Mapping
Reference: 08.03.09.05 C01b
Documentation and testing for emergency changes must be updated retrospectively within 10 working days.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Emergency Justification
Mapping
Reference: 08.03.09.05 C01c
The justification for using the emergency change process must be confirmed within 10 working days.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Direct Production Changes
Mapping
Reference: 08.03.09.06 C01a
Scenarios for direct changes in production are clearly defined and exceptions are followed up.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
System Locking/Unlocking
Mapping
Reference: 08.03.09.06 C01b
Approvals for unlocking systems for direct changes are documented, and systems are locked immediately after completion.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Vendor Update Assessment
Mapping
Reference: 08.03.09.07 C01a
Software updates and release notes from vendors are assessed for impact before implementation.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Infrastructure Baselines
Mapping
Reference: 08.03.11.01 C01a
Minimum Security Baselines (MSBs) are defined and implemented for infrastructure components.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Configuration Monitoring
Mapping
Reference: 08.03.11.01 C01b
Deviations from infrastructure security baselines are periodically monitored and addressed based on criticality.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (2)
Infrastructure Exceptions
Mapping
Reference: 08.03.11.01 C01c
Exceptions to infrastructure security baselines must be documented and approved by the security governance body.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Audit Log Protection
Mapping
Reference: 08.03.11.02 C01a
Access to edit or delete the security audit logs is strictly prohibited.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Audit Log Config Restriction
Mapping
Reference: 08.03.11.02 C01b
Access to modify the configuration of audit logs is restricted to authorized personnel only.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Audit Log Retention
Mapping
Reference: 08.03.11.02 C02a
Critical events are recorded in the security audit log and stored for a minimum of two years.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Audit Log Completeness
Mapping
Reference: 08.03.11.02 C03a
Security audit logs must be active and monitored for completeness (no missing critical entries).
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Audit Log Event Review
Mapping
Reference: 08.03.11.02 C03b
Events recorded in the security audit logs are reviewed and assessed for potential security risks.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Monitoring Inventory
Mapping
Reference: 08.03.12.01 C01a
An inventory of technical objects that require active monitoring is maintained and updated.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Interface/Process Monitoring
Mapping
Reference: 08.03.12.01 C02a
Automated processes and interfaces are monitored to identify critical errors or downtime in a timely manner.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Incident Resolution
Mapping
Reference: 08.03.12.01 C03a
IT support personnel follow up on and address critical errors or unexpected downtimes in a timely manner.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Security Patch Review
Mapping
Reference: 08.03.12.02 C01a
Security notifications and upgrades from vendors are regularly reviewed to identify required patches.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Security Patch Assessment
Mapping
Reference: 08.03.12.02 C01b
Security patches are assessed for impact and documented before being implemented in the environment.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Patch Exceptions
Mapping
Reference: 08.03.12.02 C01c
Exceptions for not applying critical security patches must be documented and approved by the governance body.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
SoD Risk Review
Mapping
Reference: AC01a
Access requests undergo a review by role approvers and SoD champions to manage Segregation of Duties risks.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
SoD Dashboard Monitoring
Mapping
Reference: AC01b
The SoD Dashboard is regularly monitored, and conflicts are addressed within defined timelines.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Mitigated Risk Review
Mapping
Reference: AC01c
Periodic reviews of users with mitigated SoD risks are conducted to ensure controls remain effective.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Custom Transaction Evaluation
Mapping
Reference: AC02a
New and custom transaction codes are evaluated to ensure they do not introduce SoD risks.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
Role Assessment
Mapping
Reference: AC02b
New and existing roles are assessed to prevent SoD risks and ensure no prohibited actions are permissible.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)
SOC 1 Review
Mapping
Reference: TP01a
Vendor SOC 1 Type 2 reports are reviewed on time, and all Complementary User Entity Controls (CUECs) are identified and implemented.
Authority Document
Mapped Control Objectives (1)
Mapped Processes (1)