IBM Apptio

Apptio

A place for Apptio product users to learn, connect, share and grow together.


#Aspera
#Apptio
#Automation
#FinOps
#Apptio
#ITAutomation
 View Only
  • 1.  SOX or No SOX

    Posted 03/14/17 01:38 PM

    Regarding Apptio Cost Transparency (CT) exclusively, does your company apply SOX controls? If yes, why and to what degree?

     

    My opinion...

     

    All authenticated users found in the Identity Access Managment (IAM) system should be permitted, at minimum, View Only (or its equivalent) role access.

     

    If necessary, when Apptio CT has matured enough to expand access beyond the core TBM Team, Finance Partners, C Suite and directs, and Budget Owners (including their proxies)...policies should be put into place to define roles and how a person is granted a role. This was proven unnecessary at a past employer 10x's as large as where I'm at now. Hence, why I start out with "if necessary". ;-)

     

    I am not in favor of managing users' access exclusively via Apptio CT or Frontdoor when there is an IAM system in production.

     

    I don’t regard Apptio CT as a “financial system” subject to SOX for these reasons:

     

    1. It does not record financial transactions
    2. It is not a source system for reports published to the Street
    3. It does not perform financial/accounting data entry
    4. It does not affect the accounting system of record
    5. It does not perform budget/forecasting data entry
    6. It does not affect the budget/forecasting system of record
    7. Any changes to a system of record would require a person to work with / contact a qualified person (eg Accounting, Finance Partner, HR, etc) to initiate change via established governed processes.

     

    And, Apptio CT does not perform data entry of HR, PIM, Clarity, etc related information. Yes, it does provide persons with configuration abilities to revise values to present the data onto its reports, but the key is source systems of record are unchanged and cannot be changed via Apptio CT.

     

    This has been a lingering concern of mine for years, so I'm naturally eager to see/hear from others on the subject.

     

    Lastly, I'm not saying my approach or opinions are right. I'm just tossing them out there for validation and to get the conversation started. ;-)









    #CostingStandard(CT-Foundation)


  • 2.  Re: SOX or No SOX
    Best Answer

    Posted 03/14/17 07:06 PM

    I agree with your approach, CT is not a financial system. SOX applies to many of the sources of record that CT uses, but in my opinion these are not applicable to CT. This opinion has been backed over the years by multiple stakeholders (including auditors) in different companies. 

     

    On a separate note. Each company might want to apply custom risk management policies to CT. Access controls is one that comes to mind. In my current environment it is very important that we enable access controls. There are multiple reasons to justify these. No right or wrong answer. 


    #CostingStandard(CT-Foundation)


  • 3.  Re: SOX or No SOX

    Posted 03/14/17 09:10 PM

    Excellent discussion! @Andre Harmon@Tiffany Holland@Keith Okello


    #CostingStandard(CT-Foundation)


  • 4.  Re: SOX or No SOX

    Posted 03/15/17 01:32 PM

    Great question Matt:  Although your argument above regarding SOX compliance may be justified not to follow specific user access rules, there are other regulations at stake ... at least maybe industry specific regulations.

     

    In healthcare, HIPAA drives a much stronger regulation than SOX, with regards to access of information.   Since our services often show costs as it relates to member care services (although member information (PHI) isn't included in reports), there is a strong opinion that this type of cost transparency should not be available to everyone.

     

    In addition, there are insider SEC type regulations that would argue against access to core financial data, which exists as the foundation to our cost transparency models. 

     

    I don't necessarily agree with this approach, however, there tends to be an over reaction to regulation in Healthcare compared to some other industry verticals. (And this is quite varied among types of Healthcare providers as well)

     

    I would much rather control who has access to our CT system in these conditions, versus creating multiple access roles for reporting ... to prevent certain types of access of information.   Although this is the easier approach, this now limits the ability to be fully transparent.


    #CostingStandard(CT-Foundation)


  • 5.  Re: SOX or No SOX

    Posted 03/15/17 02:29 PM

    So far...it seems we agree CT does not qualify for SOX regulations/oversight, but should be subjected to risk management, access, and/or data governance controls.

     

    I also agree with @John Jarvis it's better to restrict access to CT when a certain threshold of sensitive/private data is reported on versus creating multiple roles.


    #CostingStandard(CT-Foundation)


  • 6.  Re: SOX or No SOX

    Posted 03/16/17 04:20 PM

    I am also in agreement. If you were setting up a direct link to feed your GL or another accounting system, then it would be different. However, in my previous role as a customer and my experience with customers I've never seen considered  a SOX regulated system.


    #CostingStandard(CT-Foundation)