|
As a publicly traded company, C & D Technologies has been greatly impacted by Sarbanes-Oxley (SOX) regulations – especially their lean IT department. They knew that in order to comply with the regulations they were going to need more efficient user management, monitoring, and reporting.
C & D Technologies uses the AS/400 and System i5 platform to run their MAPICS[ERP] system for financial data because the platform doesn’t require a lot of maintenance. But with only one system operations manager, plus a programmer analyst acting as a back-up operator, the company wasn’t in compliance. SOX auditors insist on a separation of duties and a credible paper trail. An IT audit raised a red flag that the back-up system operator had unlimited access and change rights to objects on the production system.
The IT department needed a solution that would enable the programmer analyst to continue working efficiently as the back-up operator, while reducing the number of powerful profiles. In addition, they needed to provide the documentation and audit trail required for SOX compliance.
|