Prüfung von Software in Cloud-Umgebungen. Marko Hamel Global Internal Audit Services, SAP AG ISACA Mitgliederversammlung, Frankfurt, 11.03.

Ähnliche Dokumente
ALE2011 Berlin. An Unconference for Lean and Agile practitioners

Cook & Chill / Cook & Freeze

Planning Project-Based SAP Service Delivery Projects with SAP Portfolio and Project Management, as a Technical Quality Manager (TQM)

SAP Business ByDesign Feature Pack 2.6. Daniela Stehle, Solution Advisor, SAP Deutschland

Future Fleet. Bijan Rahnema SAP Research September 2011 INTERNAL

Strategische Front End Tools für SAP NetWeaver BW

GHT-Mobility im Überblick aktuell

VDA 4939 Formulare Version 2

SCM Consulting Solutions Stücklistenanalyse 2014

SAP unterwegs. Mobile Anwendungen powered by SAP NetWeaver. Peter Sperk Solution Sales, SAP Österreich

Mobiles Arbeiten mit SAP

Document split in new G/L. Document splitting in new G/L part 4 SAP ERP SAP AG

Global Transport Label - General Motors -

Service Level Reporting SAP Solution Manager 7.1 SAP AG August, 2011

Patch Übersicht für SAP Business One 8.81 PL11. Roll-Out Services Ecosystem & Channels Readiness Februar 2012

Life Cycle Management

Kundenspezifische Wartung. Kundenpräsentation März 2013

BR*TOOLS STUDIO. Markus Maurer SAP AG

Transparenz als Voraussetzung für Verwaltungssteuerung und Rechenschaft

System Monitoring and E2E RCA for hybris with SAP Solution Manager 7.1 SP13

IYOPRO-Workflow mit SAP-Integration November 2012

Customer Influence Program Why do we need a Feedback Agreement? Active Global Support 2012

Externe und interne Vertriebs- und Projektprozesse koordinieren mit SharePoint 2013

SAP HANA Skills Conference WHSKILL September, Walldorf

Neue Wege für Redaktionsleitfäden: Wiki-basierte Documentation Design Patterns

SAP Business ByDesign

SAP Portfolio & Strategie. Lutz Trescher SAP BusinessObjects

CubeServ Reporting Framework. Component: Design Studio Commenting. Release 4.1.1

Neue Funktionen - Highlights

5-1-2 Maintenance Strategy for SAP Core Applications

Customer COE The New Primary Certification Value Offerings for SAP Certified Customer COEs. Active Global Support

Document split in new G/L. Document splitting in new G/L part 2b SAP ERP SAP AG

System Monitoring and E2E RCA for hybris with SAP Solution Manager 7.1/7.2

SAP HANA Skills Conference & SAP HANA Technical Academy WHSKTA: September 2012 Walldorf

Property Tax Report (Program: RAIDJP_TAX) Overview of Process Flow. SAP Japan, Globalization Product Management Japan August, 2012

Mobile Anwendungen für die öffentliche Verwaltung. Peter Sperk, Program Manager Mobility, SAP Österreich

Social media in Public Sector

Karl-Heinz Hess SAP AG

Welcome & Introduction. Hanspeter Groth, Head of Business Development, SAP (Schweiz) AG Human Capital Management New Look and Feel,

Agenda. SAP who are we? What s New in the Draft EU Regulation? Security & Privacy: different topics or is there a correlation?

Document split in new G/L. Document splitting in new G/L part 2a SAP ERP SAP AG

BPMon Trend Analysis SAP Solution Manager 7.1. SAP AG August, 2011

System Monitoring and E2E RCA for hybris with SAP Solution Manager 7.1 SP14

Overview: Interactive Forms in Guided Procedures. Document Version 1.00 November 2005

Das Büro in der Westentasche mit SAP Business ByDesign TM. Sven Feurer, SAP Deutschland AG & Co. KG

50. Roundtable Münchner Unternehmer-Kreis IT

SAP Business One 9.0 PL14 Overview Note SAP Business One 9.0, version for SAP HANA PL14 Overview Note

SAP BusinessObjects Planning and Consolidation Version 10.0 for NetWeaver. Platform Information, Support Pack Dates and Maintenance Dates

Social Business. Ein Konzept für die Zukunft? Daniel Schmid Leiter Sustainability Operations SAP AG. econsense Nachhaltigkeitsstammtisch, Berlin

C1+C2: Online-Umfrage Ihre Analytics Architektur heute und morgen?

SAP Business ByDesign. 58. Roundtable des 19. April 2012

SAP PLM Kernfunktionen und Szenarien. SAP Deutschland AG & Co. KG Mike Felten Line of Business Sales CoE Lead R&D Engineering DACH

Next Generation Smart Items. Dr. Uwe Kubach SAP Corporate Research, SAP AG

Configuration of SAML Holder-of-Key Token for the ABAP Web Service Provider

SAP Runs SAP Der mobile Arbeitsplatz. Oguzhan Genis, Head of Business Development Global IT, SAP AG München,

Web Dynpro Java. SAP NetWeaver CE 7.1 1

SAP Perspective. Orestis Terzidis Director CEC Karlsruhe

Gesundheitsmanagement

AC202. Buchhaltung Customizing II: Sonderhauptbuchvorgänge, Belegvorerfassung, Substitution/ Validierung, Archivierung FI GLIEDERUNG DES KURSES

SEPA. Executive Summary. Elisabeth Jungebloed SAP Deutschland AG & Co. KG 6. November 2009

Heidelberg, Oktober 2017 BE SMARTER TAKE IT TO A NEW LEVEL

Handling Unit Management - Leihgutmietabrechnung -

Lean Manufacturing mit SAP. SAP und Lean - eine vorteilhafte Kombination

XMI Profile for ISO David S. Frankel Lead Standards Architect Model Driven Systems SAP Labs

SAP NetWeaver Enterprise Search 7.0

Verlagsleitercockpit mit SAP Business Intelligence und SAP Enterprise Portal 6.0

SAP Mobile & Web Technologien SAP AG. All rights reserved. 2

An-/Auslaufsteuerung für Vertriebslieferplanprozesse

Logistik- und Versorgungsrisiken erkennen & vermeiden! Systemunterstützes Risikomanagement in der Beschaffungslogistik: Lösungsansätze durch SAP

BI-Kongress 2016 COMBINED THINKING FOR SUCCESS - BI & S/4HANA IN FÜHRUNG GEHEN. S/4HANA: CHANCEN OHNE MEHR RISIKO, ABER MIT ZUSATZPOTENTIAL

Customer Center of Expertise. Getting Started with online Primary CCOE Certification November 15, 2012

SCM601. Prozesse in Logistics Execution GLIEDERUNG DES KURSES. Version der Schulung: 10 Dauer der Schulung: 3 Tage

Infotag SAP MaxDB Begrüßung. Karl-Heinz Hess Senior Vice President SAP Business ByDesign SAP AG

SCM200. Geschäftsprozesse in der Planung (SCM) GLIEDERUNG DES KURSES. Version der Schulung: 10 Dauer der Schulung: 2 Tage

SCM Consulting Solutions. Add-On Tools für: SAP APO

Transferworkshop DIWA-IT am 18. Mai 2010 in Dortmund. HR Productivity & Value Services, SAP AG Heidrun Kleefeld

MOB01. SAP Mobile Platform Grundlagen und Best Practices GLIEDERUNG DES KURSES. Version der Schulung: 10 Dauer der Schulung: 3 Tage

SAP-Wartungsstrategie. Kundenpräsentation März 2013

Business Excellence Days bayme vbm / BME

ITSmobile. Ralph Resech September, 2011

Smart Design Eigene Applikationen effizient und einfach entwickeln

Application Map Release 2005

Treibstoff Cloud Energie für den Mittelstand. Dietmar Meding / Leiter Geschäftsbereich SAP Business ByDesign 18. Mai 2011

Nachhaltigkeitstrategie der SAP

Taking the Mystery Out of 3D!

Vorplanung mit Variantenkonfiguration Vorplanungsstückliste versus merkmalsbasierte Vorplanung

Infotag SAP MaxDB Ausblick. Dr. Knut Hansen SAP AG

SCM605. Verkaufsprozesse in SAP ERP GLIEDERUNG DES KURSES. Version der Schulung: 10 Dauer der Schulung: 5 Tage

Transkript:

Prüfung von Software in Cloud-Umgebungen Marko Hamel Global Internal Audit Services, SAP AG ISACA Mitgliederversammlung, Frankfurt, 11.03.2011

Cloud Computing: Definition Mittels Cloud Computing stellt ein Anbieter IT- Ressourcen über das Internet einer Vielzahl von Kunden, bei nutzungsabhängiger Abrechnung zur Verfügung. Vergl. NIST und Forrester Research 2011 SAP AG. All rights reserved. 2

Cloud Definition nach NIST Netzwerkbasiert Schnell Anpassbar Messbare Servicenutzung Auf Anforderung Zusammenlegung von Ressourcen Software as a Service (SaaS) Platform as a Service (PaS) Infrastructure as a Service (IaaS) Public Private Hybrid Community 2011 SAP AG. All rights reserved. 3

Beispiel 1: US-Regierungseinrichtungen: Apps.gov 2011 SAP AG. All rights reserved. 4

Beispiel 2: SAP: Orchestrierung von Cloudanwendungen Absatzchance pflegen Aktivitäten verwalten Reiseantrag Reisespesen Buchhaltung Auszahlung SAP Sales OnDemand Expense Management OnDemand SAP Business By Design 2011 SAP AG. All rights reserved. 5

Cloud Computing: Herausforderungen 1. Kontrollverlust 2. Vertraulichkeit 3. Datenschutz 4. Integrität 5. Verfügbarkeit 6. Haftungsfragen 2011 SAP AG. All rights reserved. 6

SAP Global Internal Audit Services Konformität mit internen Vorgaben und externen rechtlichen Anforderungen Wirksamkeit: Risiko Management Internes Kontrollsystem Abläufe der Unternehmensführung Wirksamkeit und Wirtschaftlichkeit der betrieblichen Abläufe Zuverlässigkeit der finanziellen Berichterstattung 2011 SAP AG. All rights reserved. 7

SAP Standard Audit Roadmap PLANNING PREPARATION EXECUTION REPORTING FOLLOW-UP 2011 SAP AG. All rights reserved. 8

Risikobereiche: Cloud Computing Organisatorisch Informationssicherheit Compliance / Recht 2011 SAP AG. All rights reserved. 9

Cloud Computing: Top Risiken Verlust der Datenkontrolle Compliance Risiken Datenschutz Übertragung und Speicherung sensitiver Daten Abhängigkeit Cloud Anbieter Isolation der Daten Entfernter Administrationszugriff Datenbereinigung 2011 SAP AG. All rights reserved. 10

Lösungsansätze Einbeziehung Cloud Risiken in unternehmensweites RMS Definition Service Level Agreements (SLAs) Datenschutzvereinbarungen Datensicherheit / Datentransfer Eigentumsrecht Änderungsbedingungen Audit-Recht Definition Prozess zum Umzug der Cloud Anbieters Verschlüsselung der Datenströmen sowie Datenablage Identity Management Vorgaben zur Bereinigung von Datenträgern 2011 SAP AG. All rights reserved. 11

Nutzung des Audit Work Progamm Composers 2011 SAP AG. All rights reserved. 12

Abbildung COBIT auf Prüfplan PRÜFPLAN COBIT 4.1 BEISPIEL Key Scope ITProcess (COBIT Domain) Ensure systems security. (DS) Area under Audit Control Objective Exchange of sensitive data Risks Risk Driver Sensitive information exposed Control Activities Test Procedures Comment Control Practices Test the control design Control Objective Details Apply appropriate application and infrastructure controls Enquire whether and confirm that data transmissions outside the organization require encrypted format prior to transmission Exchange sensitive transaction data only over a trusted path or medium with controls 2011 SAP AG. All rights reserved. 13

Ausblick Cloud wird Wirklichkeit: ~12% des weltweiten Softwaremarktes wird 2011 über Cloud Computing realisiert (Merrill Lynch) 2011 SAP AG. All rights reserved. 14

2011 SAP AG. All rights reserved. 15

Marko Hamel, CISA CRISC Senior Internal IT Auditor SAP AG Dietmar-Hopp-Allee 16 69190 Walldorf Germany

2011 SAP AG. All rights reserved No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation. IBM, DB2, DB2 Universal Database, System i, System i5, System p, System p5, System x, System z, System z10, System z9, z10, z9, iseries, pseries, xseries, zseries, eserver, z/vm, z/os, i5/os, S/390, OS/390, OS/400, AS/400, S/390 Parallel Enterprise Server, PowerVM, Power Architecture, POWER6+, POWER6, POWER5+, POWER5, POWER, OpenPower, PowerPC, BatchPipes, BladeCenter, System Storage, GPFS, HACMP, RETAIN, DB2 Connect, RACF, Redbooks, OS/2, Parallel Sysplex, MVS/ESA, AIX, Intelligent Miner, WebSphere, Netfinity, Tivoli and Informix are trademarks or registered trademarks of IBM Corporation. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. Adobe, the Adobe logo, Acrobat, PostScript, and Reader are either trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation. UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C, World Wide Web Consortium, Massachusetts Institute of Technology. Java is a registered trademark of Sun Microsystems, Inc. JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape. SAP, R/3, SAP NetWeaver, Duet, PartnerEdge, ByDesign, SAP BusinessObjects Explorer, StreamWork, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Business Objects and the Business Objects logo, BusinessObjects, Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and other Business Objects products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Business Objects Software Ltd. Business Objects is an SAP company. Sybase and Adaptive Server, ianywhere, Sybase 365, SQL Anywhere, and other Sybase products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Sybase, Inc. Sybase is an SAP company. All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may vary. The information in this document is proprietary to SAP. No part of this document may be reproduced, copied, or transmitted in any form or for any purpose without the express prior written permission of SAP AG. This document is a preliminary version and not subject to your license agreement or any other agreement with SAP. This document contains only intended strategies, developments, and functionalities of the SAP product and is not intended to be binding upon SAP to any particular course of business, product strategy, and/or development. Please note that this document is subject to change and may be changed by SAP at any time without notice. SAP assumes no responsibility for errors or omissions in this document. SAP does not warrant the accuracy or completeness of the information, text, graphics, links, or other items contained within this material. This document is provided without a warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. SAP shall have no liability for damages of any kind including without limitation direct, special, indirect, or consequential damages that may result from the use of these materials. This limitation shall not apply in cases of intent or gross negligence. The statutory liability for personal injury and defective products is not affected. SAP has no control over the information that you may access through the use of hot links contained in these materials and does not endorse your use of third-party Web pages nor provide any warranty whatsoever relating to third-party Web pages. 2011 SAP AG. All rights reserved. 17