A Maturity Model for Segregation of Duties in Standard Business Software
Autor: | Jan Omland, Niels Müller-Wickop, Nick Gehrke |
---|---|
Přispěvatelé: | Business & Finance Consulting Services [Düsseldorf] (BFCS), Nordakademie [Elmshorn], Fakultät für Wirtschafts- und Sozialwissenschaften (WiSo), Universität Hamburg (UHH), Markus Nüttgens, Andreas Gadatsch, Karlheinz Kautz, Ingrid Schirmer, Nadine Blinn, TC 8, WG 8.6 |
Jazyk: | angličtina |
Rok vydání: | 2011 |
Předmět: |
Process management
Knowledge management COBIT Business process business.industry Separation of duties Authorization/Access Controls [SHS.INFO]Humanities and Social Sciences/Library and information sciences Business software Authorization Process Segregation of Duties Information Technology Infrastructure Library Capability Maturity Model Rule Set [INFO]Computer Science [cs] Service Integration Maturity Model SoD business Maturity Model Capability Maturity Model Integration |
Zdroj: | IFIP Advances in Information and Communication Technology Governance and Sustainability in Information Systems: Managing the Transfer and Diffusion of IT (Working conference) Governance and Sustainability in Information Systems: Managing the Transfer and Diffusion of IT (Working conference), Sep 2011, Hamburg, Germany. pp.288-294, ⟨10.1007/978-3-642-24148-2_20⟩ Governance and Sustainability in Information Systems. Managing the Transfer and Diffusion of IT ISBN: 9783642241475 Governance and Sustainability in Information Systems |
DOI: | 10.1007/978-3-642-24148-2_20⟩ |
Popis: | Part 6: Research in Progress and Practice; International audience; Maturity models are widespread used in several domains ranging from business processes to complete management frameworks like CMMI, ITIL or Cobit. In the paper on hand we develop a detailed maturity model for the management of segregation of duties in ERP systems. Our model includes several aspects starting with simple access rights management of individual systems and leading to comprehensive organizational aspects of multiple systems environments. Applying this model, organizations are enabled to improve compliance regarding access rights using a step by step approach. The approach described can also be used to assess existing segregation of duties processes of an organization in order to reveal further improvement opportunities. |
Databáze: | OpenAIRE |
Externí odkaz: |