× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Hello,

Genyphyr, could you supply the BMR(s) # for BPCS 4.05 CD?  A couple years ago I 
researched the archives and also posted some questions (making me now part of 
the archives) on this topic...  Anyways, at that time the security BMRs were 
for 6.1.01 and above.  I was able to somewhat use one, but could not change 
object authority on some BPCS security objects; came up w/ a workaround, but 
got pulled off the project...  Now we too are preparing for a SOX audit, so I 
need to revisit...  We have OGS; I will then request the BMR(s) to be sent to 
us...  Thank you in advance.

DeeDee Virgei
Project Leader

Nelson Stud Welding, Inc.       


 -----Original Message-----
From:   bpcs-l-bounces+deedee.virgei=nelsonstud.com@xxxxxxxxxxxx 
[mailto:bpcs-l-bounces+deedee.virgei=nelsonstud.com@xxxxxxxxxxxx]  On Behalf Of 
Genyphyr Novak
Sent:   Wednesday, February 23, 2005 2:53 PM
To:     bpcs-l@xxxxxxxxxxxx
Subject:        Re: [BPCS-L] Sox&BPCS






Hello,

I would like to mention: BPCS does NOT require any user to have *ALLOBJ
authority to run the product. Even when it was recommended to use the SSA
group profile for users enrolled in BPCS this was not true. Nor do we any
longer require or recommend that the user enrolled in BPCS should have an
SSA group profile for any currently supported version of the product
including BPCS 4.05 CD. Be aware that any user can update BPCS data via use
of their PC even if they do not have command line access by use of ODBC
connections - so it is not secure if your AS/400 is linked to your PC
network.

There are BMRs out there (please see the archives for more on this topic)
delivering recompiled KRSO objects so that User Profile *OWNER is used, and
to secure the command line from adopting too much authority. These BMRs
ship with README instructions explaining how to use the recompiled objects,
along with an understanding and use of iSeries security features, in order
to properly protect your BPCS data files.

Thanks,

Genyphyr Novak
SSA GT R&D

message: 2
date: Tue, 22 Feb 2005 14:18:36 -0500
from: Lisa.Abney@xxxxxxxxxxxxxxxxx
subject: Re: [BPCS-L] Sox&BPCS

Danny ...

We passed our first Sarbanes Oxley audit in December with flying colors.
It was a LOT of work, but the work was on the development side ... change
control, developer access to objects, etc.  ... nothing to do with BPCS.
(And we are on 4.05 ... not a particularly current version!)  The only
thing they really questioned about BPCS was the fact that that release
runs with users having all object authority, but once we documented for
them that that was a requirement of the software, and that we control the
risks by the other security features we have in place (users not having
command line access, etc.), that was acceptable.  Is there something in
particular your auditors are questioning, with regards to BPCS?

Lisa D. Abney
Manager Development Support
Sensient Technology
Phone:  (317) 240-1418-- 
This is the SSA's BPCS ERP System (BPCS-L) mailing list
To post a message email: BPCS-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/bpcs-l
or email: BPCS-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/bpcs-l.

Delivered-To: deedee.virgei@xxxxxxxxxxxxxx




As an Amazon Associate we earn from qualifying purchases.

This thread ...


Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.