Auditoría de SAP y ERPSAP and ERP Audit
Roles, segregación de funciones y configuraciones críticas del ERP.Roles, segregation of duties and critical ERP configurations.
¿Qué es este servicio?What is this service?
Es la auditoría de seguridad del sistema que sostiene la operación: SAP, Oracle, Dynamics o el ERP que sea. Cubre roles y perfiles, segregación de funciones, configuraciones críticas, interfaces con otros sistemas y accesos privilegiados.
A security audit of the system that runs the business: SAP, Oracle, Dynamics or whichever ERP. It covers roles and profiles, segregation of duties, critical configurations, interfaces with other systems and privileged access.
¿Para qué se usa?What is it used for?
Sirve porque el ERP concentra el dinero y el fraude interno vive ahí. El hallazgo típico no es una vulnerabilidad de software sino una combinación de permisos: la misma persona puede crear un proveedor y aprobarle un pago. Eso no lo detecta ningún escáner, hace falta entender el proceso de negocio.
It matters because the ERP concentrates the money and internal fraud lives there. The typical finding is not a software vulnerability but a permission combination: the same person can create a supplier and approve a payment to them. No scanner detects that; it requires understanding the business process.
Qué beneficios traeBenefits it delivers
- Detecta conflictos de segregación de funciones, que son la puerta del fraude interno y el hallazgo estrella de auditoría.
- Encuentra usuarios con perfiles de administración que se dieron para una migración y quedaron para siempre.
- Revisa las interfaces con otros sistemas, que suelen usar cuentas con permisos amplios y contraseñas fijas.
- Da insumos directos a la auditoría financiera, que pregunta por estos mismos controles.
- Detects segregation of duties conflicts, the doorway to internal fraud and the star audit finding.
- Finds users holding administration profiles granted for a migration and never revoked.
- Reviews interfaces with other systems, which usually run on broad-permission accounts with static passwords.
- Feeds directly into the financial audit, which asks about these same controls.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal específica de auditar el ERP en Costa Rica.
- Sí aparece por vía de la auditoría financiera y del control interno: en el sector público, la Ley 8292 obliga a mantener controles sobre los sistemas de información.
- Para entidades supervisadas entra en el marco de gestión de TI del Acuerdo CONASSIF 5-24.
- There is no specific legal obligation to audit the ERP in Costa Rica.
- It arrives through financial audit and internal control: in the public sector, Law 8292 requires maintaining controls over information systems.
- For supervised entities it falls within the IT management framework of CONASSIF Agreement 5-24.
InternacionalInternational
- La segregación de funciones es un control clásico de los marcos de control interno sobre reporte financiero.
- ISO 27001 exige separación de funciones y gestión de accesos privilegiados.
- SOC 2 lo evalúa cuando el ERP soporta el servicio dentro del alcance.
- Segregation of duties is a classic control in internal control frameworks over financial reporting.
- ISO 27001 requires segregation of duties and privileged access management.
- SOC 2 assesses it when the ERP supports the in-scope service.
Requisitos mínimosMinimum requirements
- Acceso de lectura a la configuración de roles, perfiles y asignaciones de usuario.
- Matriz de segregación de funciones del negocio, o disponibilidad para construirla; es el insumo central.
- Un interlocutor funcional además del técnico, porque el riesgo se define en términos de proceso.
- Inventario de interfaces y de las cuentas que las operan.
- Read access to role, profile and user assignment configuration.
- The business segregation of duties matrix, or availability to build it; it is the central input.
- A functional counterpart alongside the technical one, since risk is defined in process terms.
- An inventory of interfaces and the accounts operating them.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de tres a siete semanas según los módulos en alcance y si la matriz de segregación de funciones ya existe. Si hay que construirla, conviene sumar de dos a cuatro semanas: es lo que más tiempo consume, porque exige acordar con el negocio qué combinaciones son incompatibles.
The usual market range runs from three to seven weeks depending on the modules in scope and whether the segregation of duties matrix already exists. If it has to be built, add two to four weeks: it consumes the most time because it requires agreeing with the business which combinations are incompatible.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.