SOD issue? Client home grown application is control via Windows folder structure. Development happens in a power builder. That file is moved to the development folder (that only developer has access to). This can then be moved to the Test folder (developer and migratory have access to). Once tested it can be moved to production (live application) folder (only migrators with access). This overwrites all the files and in the production folder with the new files…

like
Posting as :
works at
You are currently posting as works at

However there is a windows admin group that controls the access to these folders and that group has full access to all 3 folders (that cannot be removed). They have no knowledge of the application and they are part of the windows admin team, but how can you appropriately test this.

Maybe look for compensating controls such as a user access review to shown the users who have access to the admin group have ongoing authorization and look to see if logging is enabled. Ideally admin CRUD Logs should be feeding into a SIEM. The windows security logs should also feed into the SIEM. If there is no SIEM there should be some ongoing review of audit logs at a defined frequency

Test what? you already determimed that this admin group grants its members full access to the 3 folders

Review the control objective of the control you're trying to test first

Related Posts

Hi

i wish to join foreign Banks like WELLS FARGO, BANK OF AMERICA, JP MORGAN ,HSBC,WESTERN UNION,

i have banking experiance about 6+ yrs .

Anyone could help me please

like

Why do project managers get off on fire drills? Like literally laugh about it. I find it pretty f’d up since the creatives are the ones actually making the work and having to race to get it done. Also, in the case, the “fire drill” was their fault.

like

I was brought on a project to assist procurement and ap with their transition to new erp. However, I see many issues that get brought up to me in meetings around more strategy based work or process changes that are not in scope for my project. How would you go about trying to help in these areas without stepping on toes or interfering with other internal stakeholders. Part of me feels like the new erp system is causing more issues and you can make a bigger difference through people/process Chang

like

Is Deloitte Strategy US now branded as Monitor Deloitte? Or is it S&A?

like

Kearney folks: What’s the typical turnaround time from final interview to offer/rejection?

like

Looking to make a move into Advisory/Consulting.

I have an Audit and Data Automation/Visualization background (was formerly a PwC Digital Accelerator). Any advice?

like

5 years of experience and I have brought very good results in Lead Generation and E-commerce with Digital Marketing.

I am skilled in SEO, Paid Ads, WordPress Website Development, Analytics mainly Performance marketing.

In e-commerce I have brought good conversion rate just by improving the ui/ux of the site.

How much do you think I can be paid in Navi Mumbai?

Context : I started from a startup agency and currently working in a Big well known agency.

like

What is the standard billing for a surgical PA? 20% of what the MD is billing? Does anyone know?

like

Any dermatology research opportunities?

like

What is the quickest and most efficient way to digitize all of my papers from pre-covid life?

like

Are most new houses being built with induction cooktop? What has everyone experience been like? I personally had non compatible cookware with induction cooktop and wondering if I should just buy a new cooktop (electric, gas etc).. Other reason is that I read that it's also not healthy due to electromagnetic waves?

like

GS: 383 really?

YOE -5.9
CCTC -18+3VP + 20% Promotion in oct22
Location - Gurgaon (UP Hometown)

Paypal, Chennai- 19.5+2 JB+2 VP+4L rsu

LTI, Pune - 28+2.6VP

Please help me choose.

like

I keep giving staff more chances to do simple tasks and work on improving his soft and technical skills and he is KILLING ME

like

Anyone know what is the job n responsibility of application owner in mumbai

I saw 2 posts earlier about the show "Ultimatum" on Netflix. Can't pass up trashy TV and started watching. Just finished episode 3 and loving it! Considering cancelling tonight's plans so that I can binge the rest of the season before bed.

Spoiler alert, stop reading if you care
.
.
.
.
.
.
.
.
.
WTF was with Nate's proposal?

like

Hi sharks,
How to book cab for Capgemini return to office. Any app or portal?

like

Additional Posts in Risk Assurance

What’s your worst experience with a senior? (As an associate)

Anyone hiring for entry level risk compliance roles?

like

When is busy season over for the SOX side of stuff? Please tell it doesn’t go past 12/31.

funny

What aspects would you look at when interviewing a person for a Manager position?

like

Identifying a common process, what does this even mean 😩 please help.

like

What’s the salary range for IT Audit Seniors in the Seattle market?

like

How do you all keep up with trends in risk and internal audit?

like

Is anyone here in KPMG’s CRM Risk practice? If so do you know if they are still hiring??

like

Does business Process Internal Audit or IT Internal Audit make more?

like

I’m getting put up for manager a year early. I have PPMD ,SM, and M support. Pretty much support from all the key individuals on my team and in my service line. Since it is a year early if i don’t get promoted this round I know it’ll come mid year but I do expect a good salary increase still without the promo. If I don’t get the promo nor a salary increase that I’m okay with, how do I let my partner know that I will begin to entertain outside offers? some of which have offered the manager role.

like

Currently in Risk Assurance but have the opportunity to transfer into Deals & Strategy. Which one is better for a career long term?

like

What makes more money IT Audit or IT GRC?

like

Are the exit opportunities better in Internal Audit/Business Process than IT Audit? All I hear is how awful IT Audit is but don’t hear as much complaining from the business side

like

Be honest, do you see yourself staying in the game to make partner?

likehelpful

What’s a good out from RA? Thinking about moving away from audit/accounting

like

If anyone is looking for a referral as an experienced hire to the PwC DAT (Digital Assurance & Transparency - formerly Risk Assurance) practice let me know and would be happy to refer you. We are actively looking to hire.

like

How do you apply design factors to IT Audits. Just overheard someone explain 'level of aggregation' for IT Security policies by describing how many people have access to it. Why is this a thing???

like

I have an interview coming up for internal audit manager. Currently in external audit. When asked about my experience in ERM - what would you say Is transferable skills that I can leverage in my answer?

like

Has an tested roles for SAP through productive test simulation within production? Is there any risk doing this as the test is in production?

like

Tried to jump to a big 4 as a senior 2 in risk assurance . SF market - offered 93k base and 15k bonus. Is this worth?

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal