Meeta,

We have had to get rather inventive for the same reasons (SOX).

We are controlling it from the OS level (ie; can't clear it if you don't
have write access).  We have multiple environments.  The production
environment is locked down.  The development and staging environments allow
us full access to develop, test and manipulate data.  We are using  a
product called Remedy to document the changes and change control approvals.
We have a process in place that will implement the changes that can only be
run by certain individuals.

In the event (daily) that we need to make changes in the production
environment, we make a 'FIRECALL' to a dedicated support group that will
give us access.

These processes have been in place for a little while.  Auditors come in
March.

Vance Alspach
J & L Industrial Supply




                      Stu Glancy
                      <[EMAIL PROTECTED]        To:
u2-users@listserver.u2ug.org
                      es.com>                        cc:
                      Sent by:                       Subject:  Re: [U2] [UV]
SOX Compliance and Universe
                      [EMAIL PROTECTED]
                      er.u2ug.org

                      01/27/2005 11:34 AM

                      Please respond to
                      u2-users






You can user "R"emote VOC entries on sensitve commands to excute a
security programs to allow or track access.

Meeta Advani wrote:

>Hi all,
>
>The company I work for, Mothers Work Inc., is a publicly held company,
>traded on NASDAQ.  As a result, we are obliged to comply with the
>Sarbanes-Oxley Act.  I'm sure others of you are in the same position.
>We run our business on a DG-UX machine with Universe 9.411.
>
>The guidance we have been given is that we need to put stronger access
>controls on programmers, track programmer actions, make sure that
>sensitive commands at TCL such as DELETE, CLEAR-FILE, and
>DELETE/FILE/etc. within ED are locked down to a certain extent.
>
>Although we normally do all of our programming in-house, in this case we
>are interested in finding out if there is already a product out there
>(or code that is used internally at some other company) that
>accomplishes this, and works as a wraparound.
>
>If anyone has insight on this or other comments about SOX and the MV
>world, I'd like to hear how you are dealing with this situation.
>
>Thanks,
>Meeta Advani
>
>===============================
>Meeta Advani
>Programmer/Analyst
>Mothers Work, Inc.
>[EMAIL PROTECTED]

[demime 1.01d removed an attachment of type image/gif which had a name of 
graycol.gif]

[demime 1.01d removed an attachment of type image/gif which had a name of 
ecblank.gif]

[demime 1.01d removed an attachment of type image/gif which had a name of 
pic13650.gif]
-------
u2-users mailing list
u2-users@listserver.u2ug.org
To unsubscribe please visit http://listserver.u2ug.org/

Reply via email to