Saltar al contenido
02 · Auditoría02 · Auditing

Auditoría de SAP y ERPSAP and ERP Audit

Roles, segregación de funciones y configuraciones críticas del ERP.Roles, segregation of duties and critical ERP configurations.

SAP · Oracle · DynamicsSAP · Oracle · Dynamics 2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

¿Qué es este servicio?What is this service?

Es la auditoría de seguridad del sistema que sostiene la operación: SAP, Oracle, Dynamics o el ERP que sea. Cubre roles y perfiles, segregación de funciones, configuraciones críticas, interfaces con otros sistemas y accesos privilegiados.

A security audit of the system that runs the business: SAP, Oracle, Dynamics or whichever ERP. It covers roles and profiles, segregation of duties, critical configurations, interfaces with other systems and privileged access.

¿Para qué se usa?What is it used for?

Sirve porque el ERP concentra el dinero y el fraude interno vive ahí. El hallazgo típico no es una vulnerabilidad de software sino una combinación de permisos: la misma persona puede crear un proveedor y aprobarle un pago. Eso no lo detecta ningún escáner, hace falta entender el proceso de negocio.

It matters because the ERP concentrates the money and internal fraud lives there. The typical finding is not a software vulnerability but a permission combination: the same person can create a supplier and approve a payment to them. No scanner detects that; it requires understanding the business process.

Qué beneficios traeBenefits it delivers

  • Detecta conflictos de segregación de funciones, que son la puerta del fraude interno y el hallazgo estrella de auditoría.
  • Encuentra usuarios con perfiles de administración que se dieron para una migración y quedaron para siempre.
  • Revisa las interfaces con otros sistemas, que suelen usar cuentas con permisos amplios y contraseñas fijas.
  • Da insumos directos a la auditoría financiera, que pregunta por estos mismos controles.
  • Detects segregation of duties conflicts, the doorway to internal fraud and the star audit finding.
  • Finds users holding administration profiles granted for a migration and never revoked.
  • Reviews interfaces with other systems, which usually run on broad-permission accounts with static passwords.
  • Feeds directly into the financial audit, which asks about these same controls.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal específica de auditar el ERP en Costa Rica.
  • Sí aparece por vía de la auditoría financiera y del control interno: en el sector público, la Ley 8292 obliga a mantener controles sobre los sistemas de información.
  • Para entidades supervisadas entra en el marco de gestión de TI del Acuerdo CONASSIF 5-24.
  • There is no specific legal obligation to audit the ERP in Costa Rica.
  • It arrives through financial audit and internal control: in the public sector, Law 8292 requires maintaining controls over information systems.
  • For supervised entities it falls within the IT management framework of CONASSIF Agreement 5-24.

InternacionalInternational

  • La segregación de funciones es un control clásico de los marcos de control interno sobre reporte financiero.
  • ISO 27001 exige separación de funciones y gestión de accesos privilegiados.
  • SOC 2 lo evalúa cuando el ERP soporta el servicio dentro del alcance.
  • Segregation of duties is a classic control in internal control frameworks over financial reporting.
  • ISO 27001 requires segregation of duties and privileged access management.
  • SOC 2 assesses it when the ERP supports the in-scope service.

Requisitos mínimosMinimum requirements

  • Acceso de lectura a la configuración de roles, perfiles y asignaciones de usuario.
  • Matriz de segregación de funciones del negocio, o disponibilidad para construirla; es el insumo central.
  • Un interlocutor funcional además del técnico, porque el riesgo se define en términos de proceso.
  • Inventario de interfaces y de las cuentas que las operan.
  • Read access to role, profile and user assignment configuration.
  • The business segregation of duties matrix, or availability to build it; it is the central input.
  • A functional counterpart alongside the technical one, since risk is defined in process terms.
  • An inventory of interfaces and the accounts operating them.

Plazo típico de entregaTypical delivery time

3 a 7 semanas 3 to 7 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de tres a siete semanas según los módulos en alcance y si la matriz de segregación de funciones ya existe. Si hay que construirla, conviene sumar de dos a cuatro semanas: es lo que más tiempo consume, porque exige acordar con el negocio qué combinaciones son incompatibles.

The usual market range runs from three to seven weeks depending on the modules in scope and whether the segregation of duties matrix already exists. If it has to be built, add two to four weeks: it consumes the most time because it requires agreeing with the business which combinations are incompatible.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

ERPERP
Sistema de planificación de recursos empresariales: concentra finanzas, compras, inventario y nómina. Enterprise resource planning system: it concentrates finance, procurement, inventory and payroll.
SoDSoD
Segregación de funciones: ninguna persona debe controlar todas las etapas de una operación sensible. Segregation of duties: no single person should control every stage of a sensitive operation.
PerfilProfile
Conjunto de permisos que se asigna a un usuario según su puesto. A set of permissions assigned to a user according to their role.
Usuario genéricoGeneric account
Cuenta compartida por varias personas. Rompe la trazabilidad y es hallazgo seguro en auditoría. An account shared by several people. It breaks traceability and is a guaranteed audit finding.
PentestPentest
Prueba de intrusión: se ataca el sistema con autorización previa y por escrito, para encontrar lo que encontraría un atacante real. Penetration test: the system is attacked with prior written authorisation, to find what a real attacker would find.
RoERoE
Reglas de compromiso: el documento que define qué se puede atacar, cuándo, con qué técnicas y a quién avisar. Rules of Engagement: the document defining what may be attacked, when, with which techniques and who to notify.
MITRE ATT&CKMITRE ATT&CK
Base de conocimiento pública de tácticas y técnicas usadas por atacantes reales. Public knowledge base of tactics and techniques used by real attackers.