Audit preparation

 6 Replies
 0 Subscribed to this topic
 27 Subscribed to this forum
Sort:
Author
Messages
wintergreen
Veteran Member
Posts: 93
Veteran Member

    We have audit coming up next month.  This is my first year, so I have no idea what kind of information I need to prepare for auditing? Any help will be much appreciated. Thanks!  

    MattD
    Veteran Member
    Posts: 94
    Veteran Member
      What kind of information are you in charge of collecting? Security, server specific info, etc, or all the above. We just finished our audit so I should be able to provide some information on the topic.

      Matthew
      wintergreen
      Veteran Member
      Posts: 93
      Veteran Member
        Matthew, thanks for your response. I'm the only person in charge Lawson. So, it will be all topics covered in Lawson. Security, server maintenance, interface programs....etc.. Thank you!
        MattD
        Veteran Member
        Posts: 94
        Veteran Member
          No problem. I'll try to cover everything but there is a lot so I can't make any promises.

          First off Security
          - List of all current Lawson users.
          - If using the HR Suite
          --List of all Current Employees.
          --List of all terminated Employees.
          -List of system administrators or individuals with Lawson Admin Access.
          -Password Setup.

          We usually have to provide documentation on our change process. For instance who has to approve access to the Lawson, and where that information is documented. We also are asked to provide documentation on our last internal security audit.

          On the server side:
          The main item we are asked to document are changes. This is something new we implemented due to an audit comment. We now collect info on all changes to the server and documents with approvals on making those changes. We actually created a script that collects the changes made weekly. It doesn't collect all changes but as many as possible. This may not be required but we do provide it.

          Hope this helps. If I can think of anything else I will let you know.

          Matthew
          Adam Jacobson
          Veteran Member
          Posts: 69
          Veteran Member
            If you'd like, I have the list i received from a major audit firm.
            This was not a Sarbox quality audit - but I'm guessing that if you're the only lawson person, you don't have public company issues.
            I can send it to you - it's in excel
            adam@redthree.com
            wintergreen
            Veteran Member
            Posts: 93
            Veteran Member
              Thank you Matthew. I have a question about the LAUA security. Is there a report that I can list all the user's security profiles? It seems that I have to print out one by one in the LID... Is this required?
              MattD
              Veteran Member
              Posts: 94
              Veteran Member
                I don't believe we every had to print the whole security profile. The name of the security class was sufficient. Then if there were questions about a specific security class we addressed those on an as needed basis.

                Let me know if there is anything else I can do to help.

                Matthew