The Preliminary Specification Part CCCXXIX (C&G Part XXVII)
Today we take a look at Oracle Fusion Applications, Governance, Risk & Compliance Suite, Access Controls Governor module. This will be an important element of the Compliance & Governance module in the Preliminary Specification as segregation of duties (SOD) has taken on an heightened importance in the firm. Whether that is as a result of the regulation or from the need for better governance, SOD offers many advantages to the innovative oil and gas producer. Having multiple people involved in the process from beginning to end ensures that no one individual can manipulate resources of the firm for their own benefit. Oracle’s Access Controls Governor module provides this functionality in the following manner.
Oracle notes the following is also part of the Access Controls Governor modules functionality.
Global regulations are driving organizations to improve the transparency and accountability of financial data, processes, and transactions. Controlling, tracking, and reporting on user activity within the application environment are critical components of compliance.
So apparently big brother needs to be watching. And as good as your internal controls may be, there will always be ways in which the system might be “hacked” in ways that were unknown before. Thankfully Oracle’s Access Controls Governor module is automated and implements the policies based on management's understanding. There is also a library of controls that can be implemented that was developed by Oracle in collaboration with leading audit and consulting firms. As with the libraries that were mentioned yesterday, People, Ideas & Objects will maintain a library of these policies for the innovative oil and gas producer. And the system is not just reporting on violations, it is actively stopping and enforcing SOD when they occur based on those policies. And they can be somewhat dynamic and proactive in their enforcement, stating that no user can be involved in more than two steps of a five step process, and disallowing the user to sign on to another process at the time of assignment.
When preparing policies for implementation the Oracle Access Controls Governor provides a tool for simulating the new policies. Using the historical record of user access as the base of information it can run the new policy against that data to determine what the outcome of that new policy will be. Would there be any new violations, and / or false positives etc. Then they can tune the policy based on the feedback that they get from the tool to ensure that it is catching only the desired situations. Saving costly resources in the future.
From a People, Ideas & Objects perspective the Oracle “Governance” applications that we have discussed yesterday and today help to bring 21st Century internal controls to the Preliminary Specification. When we think of the manner in which the industry will operate with large portions of the existing producers overhead being provided by service providers. And those service providers accessing their work through the People, Ideas & Objects Preliminary Specification. Extension of these internal controls to those individuals will be needed as well. The producer will need to know that these controls are effective in their firm, their Joint Operating Committees and the service providers they hire to maintain their firm.
For the industry to successfully provide for the consumers energy demands, it’s necessary to build the systems that identify and support the Joint Operating Committee. Building the Preliminary Specification is the focus of People, Ideas & Objects. Producers are encouraged to contact me in order to support our Revenue Model and begin their participation in these communities. Those individuals that are interested in joining People, Ideas & Objects can join me here and begin building the software necessary for the successful and innovative oil and gas industry.
Please note what Google+ provides us is the opportunity to prove that People, Ideas & Objects are committed to developing this community. That this is user developed software, not change that is driven from the top down. Join me on the People, Ideas & Objects Google+ Circle (private circle, accessible by members only) and begin building the community for the development of the Preliminary Specification.
The Preliminary Specification is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for People, Ideas & Objects products remains at the sole discretion of People, Ideas & Objects.