governance, risk, and compliance controls governor...

Download Governance, Risk, and Compliance Controls Governor User¢â‚¬â„¢s Guide: Change Control in Preventive Controls

Post on 03-Jul-2020

0 views

Category:

Documents

0 download

Embed Size (px)

TRANSCRIPT

  • Governance, Risk, and Compliance Controls Governor

    Preventive Controls Governor Change Control User’s Guide

    Software Version 7.2.2.3

  • Preventive Controls Governor: Change Control User’s Guide Part No. AG004-7223A Copyright © 2007, 2008, Oracle Corporation and/or its affiliates. All rights reserved. The Programs (which include both the software and the documentation) contain proprietary information; they are provided under a license agreement containing restrictions on use and disclosure and are also protected by copyright, patent, and other intellectual and industrial property laws. Reverse engineering, disassembly, or decompilation of the Programs, except to the extent required to obtain interoperability with other independently created software or as specified by law, is prohibited. The information contained in this document is subject to change without notice. If you find any problems in the documentation, please report them to us in writing. This document is not warranted to be error-free. Except as may be expressly permitted in your license agree- ment for these Programs, no part of these Programs may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose. If the Programs are delivered to the United States Government or anyone licensing or using the Programs on behalf of the United States Government, the following notice is applicable.

    U.S. GOVERNMENT RIGHTS Programs, software, databases, and related documentation and technical data delivered to U.S. Government customers are “commercial computer software” or “commercial technical data” pursuant to the applicable Federal Acquisition Regulation and agency-specific supple- mental regulations. As such, use, duplication, disclosure, modification, and adaptation of the Programs, including documentation and technical data, shall be subject to the licensing restric- tions set forth in the applicable Oracle license agreement, and, to the extent applicable, the additional rights set forth in FAR 52.227-19, Commercial Computer Software — Restricted Rights (June 1987). Oracle Corporation, 500 Oracle Parkway, Redwood City, CA 94065. The Programs are not intended for use in any nuclear, aviation, mass transit, medical or other inherently dangerous applications. It shall be the licensee’s responsibility to take all appropriate fail-safe, backup, redundancy and other measures to ensure the safe use of such applications if the Programs are used for such purposes, and we disclaim liability for any damages caused by such use of the Programs. The Programs may provide links to Web sites and access to content, products, and services from third parties. Oracle is not responsible for the availability of, or any content provided on, third-party Web sites. You bear all risks associated with the use of such content. If you choose to purchase any products or services from a third party, the relationship is directly between you and the third party. Oracle is not responsible for: (a) the quality of third-party products or services; or (b) fulfilling any of the terms of the agreement with the third party, including delivery of products or services and warranty obligations related to purchased products or services. Oracle is not responsible for any loss or damage of any sort that you may incur from dealing with any third party. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners. The license for this program includes a limited use license for the Internal Control Manager program. Such limited use license means that the Internal Controls program shall only be used for financial compliance or IT governance related operations.

  • User’s Guide: Change Control in Preventive Controls Governor 7.2.2.3 iii

    Contents

    Introduction....................................................................................1

    Change Control and the GRC Controls Suite .............................................................2 Before You Start...............................................................................................................2

    Creating Control Rules Manually ..................................................5

    Starting the Change Control Wizard .............................................................................5 Finding Control Rules .....................................................................................................6 Creating Control Rules ....................................................................................................7

    Selecting a Block of Controllable Fields ................................................................7 Creating Control Rules for Fields in the Selected Block .....................................8 Using the Translations Tab to Select Record Identifiers.................................. 10 Creating Reason Codes.......................................................................................... 11 Finishing the Control-Rule Generation .............................................................. 12

    Defining Subscribers for Control Rules .................................................................... 13 Filter Type Considerations.................................................................................... 14 More Subscriber Fields.......................................................................................... 15 Profiles and Data Subscribers............................................................................... 15

  • Contents

    iv User’s Guide: Change Control in Preventive Controls Governor 7.2.2.3

    Uploading or Migrating Control Rules .......................................17

    Uploading Rules from a Content Spreadsheet ..........................................................18 Migrating Control Rules................................................................................................19

    Applying Changes to Controlled Fields......................................21

    Audit ................................................................................................................................21 Reason Code or Approval ............................................................................................21

    Change Control with WVR Enabled ...................................................................22 Change Control with WVR Disabled...................................................................23 Completing the Approval Process........................................................................23

    Reports..........................................................................................25

    Exporting a Report........................................................................................................26 Other Report Features ..................................................................................................26 The Data Source Parameter .........................................................................................26 Approver Performance Report....................................................................................27 Change History Report .................................................................................................27 Control Listing Report ..................................................................................................28

    Creating Workflow Roles .............................................................31

    Using the Event Tracker...............................................................33

  • User’s Guide: Change Control in Preventive Controls Governor 7.2.2.3 1

    Chapter 1

    Introduction

    Within Preventive Controls Governor, a Change Control application applies change control to Oracle E-Business Suite form fields. It can apply any of three “control types,” which subject field-value changes to increasing degrees of review:

    • Audit: Changes to fields are tracked, and a history of those changes is presented in reports. This control type allows users to make changes freely.

    • Reason Code: Field changes are once again tracked, and their history presented in reports. Moreover, a user who changes the value of a field must enter a reason code and may send notification of the change to another person or role (if a recipient of the notification has been specified). Approval is not required for the change to be made.

    • Approval: Field changes are once again tracked, and their history presented in reports. When a user changes the value of a field, she must once again give a reason for the change, but her action also sends a request for approval to a specified person or role. The change must be approved or rejected, and the requesting user must acknowledge an approval. A change is implemented only when it is approved and acknowledged.

    Rules — one for each field — implement these controls. You can use a form called the Change Control Wizard to view these rules or to create them manually. As an alternative to creating individual rules, you can upload already-created rules from a “content spreadsheet,” and then use the Wizard to confirm that they have been up-

  • Chapter 1: Introduction

    2 User’s Guide: Change Control in Preventive Controls Governor 7.2.2.3

    loaded correctly. The spreadsheet includes more than 1,500 change-control objects that you can tailor to your organization’s needs.

    Moreover, you can create “subscribers

Recommended

View more >