I know it’s a strange title for my rant this week, but my work life is in such chaos right now, I can’t imagine a better title. Let me give you a little background on what I do for a living. Bottom line, I work for a company who is publically traded on Wall Street. Yes, I do own stock of my own company, and buy as much as I can at a discount until they wise up and decide to fire my stupid ass. Anyways, my job is the keep the auditors happy that review our financial statements that we release to the SEC on a quarterly and yearly schedule. How do I make them happy do you ask? Well, I’m sure someone could think of some snide comment or sexual favor quip, but I digress. My job is to secure our system that runs our business. All of our books are in there, customers, bank records, taxes… pretty much everything that hackers, criminals, and low-lifes would love to get their hands on.
How do I do this is your inquiry? Very carefully, and covering my butt all time. I obtain signatures, approvals, and basically test the crap out of any changes I make in the system to make it more secure. I use tools of course to help me accomplish this, and rely on them heavily to avoid me having to do a lot of manual processes that would have me in the office for 18 hours a day and little time for my family let alone gaming.
Ever heard of an SOD? Is this stuff you lie down where dead grass is to help it grow back? No, SOD is short for Segregation Of Duties. In a nutshell, it’s basically two incompatible business transactions in a computer system that introduces a risk. What is a risk mind you? An example is ability to buy something, and the ability to also receive it. In personal transactions, sure that’s normal. From a business perspective… it’s not. You could buy 10 PCs.. but only receive 9… to take one home for yourself.. and it will take weeks for the company to find out… And you’d be long gone. Another example is having the ability to create a “Vendor” or “Payee” in the corporations’ accounting program.. And also the ability to pay that vendor. So you could make yourself and your home address as the “Payee”, and then cut a check to yourself for thousands of dollars…. Long before the company even finds it at the end of the month or worse… a year later.
Don’t think that these things can’t happen in your company. It happens at MOST of them. It’s just that alot of companies are keeping an eye on this (Thank you Enron, and the SOX act), and are stopping these thieves in their tracks.. I know what you’re thinking… why should I care? Welll, for one if you work for that company, it costs you raises, bonuses, better benefits… and for other companies it results in higher prices, fees, expenses….
Why am I ranting on this? Well, I keep trying to set up security in our system to avoid these types of issues, and they keep changing things… constantly. We are implementing this new system in a month, and we’re still changing stuff… Think of it as changing the blueprint for a house constantly as they are trying to build it. Move this room there, that pipe there, outlet there.. put central vacuuming in… take it out… and so on.
What is to be learned in all of this? When somebody mentions ‘audit’ or ‘SOX’… run in the other direction.
Stay the hell out of a career in IT.