13.07.2015 Views

6\VWHP $GPLQLVWUDWLRQ 0DGH (DV\

6\VWHP $GPLQLVWUDWLRQ 0DGH (DV\

6\VWHP $GPLQLVWUDWLRQ 0DGH (DV\

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 12: User AdministrationRecommended Policies and ProceduresGroupHuman resourcesExternal auditorsITSenior managementEmployee’s managerResponsibilityLegal or personnel mattersInternal control issues related to financialauditProcedures to terminate network accessPolicy approval“Handover” or training period for theemployee’s replacementTo manage terminated employees: The user’s manager or HR should send a form or e-mail indicating that the employee isleaving. The user’s ID should be locked and the user assigned to the user group “term” forterminated.If the user’s ID is not required as a template: The activity groups assigned to the user should be deleted.(use transaction SU01, under the Activity Group tab, delete the activity groups). The security profiles assigned to the user should be deleted(use transaction SU01 and under the Task profile and Profile tabs, delete the profiles). Check Background Jobs (transaction SM37) for jobs scheduled under that user ID.The jobs will fail when the user ID is locked or deleted. If the user leaves one job for another and needs to maintain access for handover, thishandover should be documented.The duration of the handover access must be defined and the expiration (Valid to) dateentered in the R/3 System. All temporary employees or consultants should have expiration (Valid to) dates on theiruser IDs.Similar to banks, there should be a “secret word” that users could use to verify theiridentity over the phone. This word would be used when the user needs their passwordreset or their user ID unlocked. But, realize that others can “overhear” this secret wordand render it useless.12–4Release 4.6A/B

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!