complementary solutions for lawson s3 monitoring and auditing for lawson s3 november 2013 presented...
TRANSCRIPT
ComplementarySolutions for Lawson S3
MONITORING AND AUDITINGFOR LAWSON S3
November 2013Presented by Dan Kinsey
AGENDA
o KINSEY OVERVIEW
o SOLUTIONS
o ACTIVITY MONITOR
o TRANSACTION AUDITING
o LIVE DEMO
ComplementarySolutions for Lawson S3
COMPLEMENTARY SOLUTIONS FOR LAWSON S3
• Founded in 1983 by Dan and Brad Kinsey, Kinsey has provided software sales, implementation, support and development for over 30 years.
• Infor-Lawson reseller and implementation partner since 1997
• Infor-Lawson Certified Systems Integration Partner
• Infor-Lawson Complementary Software Partner
• Infor-Lawson’s “Go to” Reseller/Implementer for Public Sector
• Provided product and services to over 120 Lawson customers
• 2 time Partner of the Year
OUR BACKGROUND
MONITORING AND AUDITING LAWSON S3
LAUA Security Auditing
Activity Monitor
Transaction Auditing
LAUA Segregation of Duties (SoD)
LS9 Segregation of Duties (SoD)
LS9 Auditing
LAUA Security Reporting
LS9 Reporting
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR (Listener)
Purpose: Monitors all user activity in Lawson S3 applications for audit control and performance measuring.
Target Audience: Internal & External Auditors, Security administrators, Department managers.
Technology: Utilizes WebSphere in real-time to update activity in MySQL, MSSQL or Oracle.
Reporting: Browser UI for creating and viewing reports; Excel pivot tables; Security Dashboard for metadata.
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR (Listener)
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
Real Time Continuous User Activity MonitoringoPortal ActivityoSmart Office ActivityoMS Add-in ActivityoFirst/Last Screen UsedoTotal Screens UsedoTotal Transactions ProcessedoScreen Usage DetailoScreen Access RestrictionsoMultiple Reporting MethodsoTransaction Auditing Optional Interface
ACTIVITY MONITOR
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR
Use MS Excel to view all summary activity by user-form, by user-system code or to create performance graphs.
Drill on any cell to see the detail.
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR
•Real-Time Portal, Smart Office, MS Add-in Monitoring
•Current and Historical Activity
•Reports Delivered through your Browser or Microsoft Excel
•Includes User, Form, Function Code, Date, Time, Form Keys
•Optional Restriction Scheduling
•Optional Interface to Transaction Auditing Data
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING
Purpose: Transaction auditing provides the ability to track who has changed or viewed any information in Lawson’s S3 applications and indentify the user and data affected.
Target Audience: Internal & External Auditors, Security administrators, Department managers
Technology: Utilizes WebSphere in real-time to update activity in MySQL, MSSQL or Oracle.
Reporting: Browser UI for creating and viewing reports; HTML output; exportable to MS Excel or PDF
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING - SETUPAudit DefinitionsoProduct LineoUser NameoScreen NameoFunction CodeoIP AddressoTime RangeoRetention Policies
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING - SETUP
COMPLEMENTARY SOLUTIONS FOR LAWSON S3
TRANSACTION AUDITING - REPORTING
Audit DataoProduct LineoUser ID associated with the transaction oOrigination System IP addressoProduct LineoScreen nameoFunction CodeoReason CodeoTransaction DateoTransaction KeysoField NamesoField Values (Before & After)
COMPLEMENTARY SOLUTIONS FOR LAWSON S3
TRANSACTION AUDITING – REPORT CRITERIA
COMPLEMENTARY SOLUTIONS FOR LAWSON S3
TRANSACTION AUDITING – REPORTING
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING – HR/PAYROLL EXAMPLES
Employees and managers can enter education and certification information in to Self Service but there is no audit. The HR staff needs to verify that the employee really received the education, skill, etc.
Forms to audit: PA20.1 EducationPA21.1 CompetenciesPA22.1 Certification
Provide the ability to audit changes made to time records that come in from a workforce management system such as Kronos or Workbrain. This would include an deletions to time records.
Forms to audit: PR35.1 Time Entry
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING – FINANCE EXAMPLES
In GL when setting up the company there is an option to allow JE’s to be Unposted and Unreleased prior to closing the month. If you do this there is no evidence the JE ever existed.
Forms to audit GL45.1 provides the option to Unpost & UnreleaseGL40.1 provides the option to delete the entry
Along the same lines you can open a closed GL period for back posting which also has no audit trail.
Forms to audit GL10.1 CompanyGL10.2 Backposting Control
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING – FINANCE EXAMPLES
In Cash Ledger there are no audits for any cash transaction entry which can include Deposits, Transfers and Bank Transactions including Payment Entry. This lets you enter a payee without having a vendor to create a check.
Forms to audit CB10 DepositsCB15 TransfersCB20 Bank TransactionsCB55 Payment Entry
Also in Cash Book would be Bank Transaction Adjustments which is used to reconcile payments, set them as void, stop payment, etc.
Form to audit CB80 Bank Transaction Adjustment
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
TRANSACTION AUDITING – CONTROL EXAMPLES
Transactions for a specific group of users (i.e. Internal Lawson Support Group)
All Lawson set-up forms
Time based transactions
Transaction originating from a specific IP Address
Healthcare Patient’s name is on a requisitionEmployees are also patients
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ACTIVITY MONITOR vs. TRANSACTION AUDITING
Feature AM TAUser ID Yes YesIP Address Yes YesDate/Time Yes YesProduct Line Yes YesApplication Yes YesForm ID Yes YesFunction Code Yes YesKeys Yes YesReport Writer Yes YesMS Excel Output Yes YesManager Restrictions Yes NoField Level Data No YesBefore and After Changes No YesReport Scheduling No YesLicensing Restrictions No Yes
COMPLEMENTARY SOLUTIONS FOR LAWSON S3MONITORING AND AUDITING LAWSON S3
ComplementarySolutions for Lawson S3
WEBCAST PROMOTIONEnter in to a Proof of Concept agreement prior to March 1, 2014 and receive a no-obligation 30 day trial version.
• Non-Production Environment (DEV/TEST)• Product will be billed upon acceptance of trial• Requires 2 days of remote installation services to be billed upon acceptance of trial• Requires a virtual server to be provided by customer• Available for Portal and Microsoft Add-in transactions• Promotion not available for hosted applications• Trial period must begin no later than July 1, 2014
ComplementarySolutions for Lawson S3
CONTACTGuy HensonKinsey & Kinsey, Inc26. N Park BoulevardGlen Ellyn, Illinois [email protected] us at: www.kinsey.com