fhs
Volume 7, Number 8 -- February 27, 2007

Approva Automates Compliance Efforts with BizRights

Published: February 27, 2007

by Alex Woodie

When it comes to ensuring that certain regulatory controls have been implemented in your ERP system, it's one thing if Joe from accounting gives the "thumbs up" sign while grabbing a cup of coffee, and quite another when the approval stems from a regimented process originating from outside the company. Auditors, in particular, would really rather have an external process, such as the one implemented by Approva's BizRights program, which actually is the remediation system used by two of the Big 4 accounting firms.

The Sarbanes-Oxley Act has been a tremendously disrupting influence on IT shops over the last few years. IT managers have had to take long, hard looks at how they implement security on their back end servers and the applications that run on them. They've been forced to institute systems that track every time people or other applications touch financial data and applications, and to segregate user duties to reduce the opportunity to commit fraud.

While Approva was already in the works when the Enron and WorldCom scandals of 2001 hit the news, the company was largely made out of the legislation that followed these notorious events, notably Sarbanes-Oxley. Since then, it has attracted more than 100 customers, mostly Fortune 500 companies running the big tier-one ERP packages, such as SAP R/3, Oracle E-Business, and PeopleSoft Enterprise, which is now owned by Oracle.

Earlier this month, the company announced BizRights version 3.5.2, which introduced support for J.D. Edwards World and EnterpriseOne, once the gold standard for OS/400-based ERP suites, and now Oracle's offering for "small to mid size businesses."

'Get Clean, Stay Clean'

Approva is a Windows-based product designed to help users find the areas of their enterprise applications where they are lacking the audit tracking and segregation of duties functionality required by Sarbanes-Oxley. The software does this by analyzing actual ERP transactions downloaded from the production system into Approva's SQL Server-based database, and then running a range of queries and algorithms against it to root out problems.

"We help you get clean, and then monitor the system on an ongoing basis to keep you clean," says Steve Elliot, Approva's chief technology officer. "You have to build the controls around how they run their business and their security. First you need to get to a clean environment. First you expose issues, then remediate them and track any transaction issues."

BizRights looks for a range of problems, including the potentially fraudulent--such as the contact on the vendor list that has the same address as an employee--to the troublesome--such as the lack of necessary separation around developer duties. In each case, the software suggests ways to help the user resolve the issue.

While some companies are successful at detecting potential Sarbanes-Oxley violations on their own, many companies find the process daunting, according to Elliot. "Segregation of duties is one of the most difficult requirements to deal with, especially with the larger ERP systems," he says. "It's very granular and iterative, and difficult for users to write their own algorithms, and keep up with the changes from version to version. We are experts at that."

Although Approva tailors its software for the big-name ERP systems, BizRights works with practically anything you can throw at it, and is increasingly seeing more mid size ERP applications, such as J.D. Edwards and Lawson. "We work with anything--homegrown, mainframe," Elliot says. "Most of the customers we talk to are so big they don't have just one ERP. Out of all the deals, 80 percent are cross-application."

Some customers are hit with a bit of "shell shock" the first time they run BizRights through the system. "It exposes so many issues they didn't even know were there--thousands and thousand of issues," he says. But once the customer has gotten "clean," the number of violations flagged by BizRights should drop dramatically, and managers will only receive the occasional e-mail alerting them to potential problems.

BizRights Ecosystem

The BizRights ecosystem is healthy and growing at a good clip, according to Elliot. Some of its partners have adapted the product with their own industry-specific content, such as meeting requirements for federal contracting. The company is also seeing increased demand for HIPAA remediation skills, and expertise in handling leases in the oil and gas business.

The product sees a lot of use thanks to KPMG and Ernst & Young, two of the world's Big 4 auditing firms that have adopted BizRights for Sarbanes-Oxley audits. "Whenever they go out and look at ERP systems, they use our software," Elliot says. "It forced us to make our software permanent for our customers but portable for our auditors. We had to get good at solving problems very quickly."

To support these customer engagements, Approva built co-location centers where it uses VMware's software to carve Windows servers into multiple virtual servers, to run pilots for potential BizRights customers. A week or so after downloading a sampling of data into the BizRights data warehouse, customers can begin working with the software to see how it would work with their systems.

BizRights version 3.5.2 is available now. Pricing typically ranges from about $250,000 to $400,000. For more information, visit www.approva.net .



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
PRODATA COMPUTER SERVICES

Visit our new & improved Customer Portal to experience the POWER of RSP!

You can now view, print and PAY your invoice online in our SECURED Customer Portal.

Log in to the customer portal today at DoDBU.com! While there, be sure to join the "Elite" DBU-on-Demand Club FREE for up to 10 days anytime and anywhere.

Join the elite DBU-on-Demand Club!

ProData Computer Services
800.228.6318
www.DoDBU.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the 2007 conference, April 29 – May 3, in Anaheim, California
Computer Keyes:  Rapidly convert *SCS printer files into black and white of full color PDF documents
Patrick Townsend & Associates:  Alliance AES/400 - database field encryption


Books on Sale at the IT Jungle Store: 30 Percent Off for 30 Days

The System i Pocket RPG & RPG IV Guide: List Price, $69.95; Sale Price, $49.00
The iSeries Pocket Database Guide: List Price, $59.00; Sale Price, $41.00
The iSeries Pocket Developers' Guide: List Price, $59.00; Sale Price, $41.00
The iSeries Pocket SQL Guide: List Price, $59.00; Sale Price, $41.00
The iSeries Pocket Query Guide: List Price, $49.00; Sale Price, $34.00
The iSeries Pocket WebFacing Primer: List Price, $39.00; Sale Price, $27.00
Migrating to WebSphere Express for iSeries: List Price, $49.00; Sale Price, $34.00
iSeries Express Web Implementer's Guide: List Price, $59.00; Sale Price, $41.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95; Sale Price, $56.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00; Sale Price, $62.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00; Sale Price, $34.00
WebFacing Application Design and Development Guide: List Price, $55.00; Sale Price, $38.00
Can the AS/400 Survive IBM?: List Price, $49.00; Sale Price, $34.00
The All-Everything Machine: List Price, $29.95; Sale Price, $21.00
Chip Wars: List Price, $29.95; Sale Price, $21.00

 

The Four Hundred
IBM Seeks More CODE/400 Converts with WDSc 7.0

Midrange LUGs Are Changing the Way They Operate

Server Sales Up a Bit in 2006, But Q4 Looks a Bit Weak

As I See It: Disorderly Conduct

The Linux Beacon
Chip Makers Strut Their Stuff at ISSCC

AMD Delivers Faster and Cooler Rev F Opteron Chips

Zend Upgrades Commercial Add-Ons for Its PHP Engine

As I See It: Measuring What Counts

Big Iron
IBM Previews Future z/OS, z/VM Mainframe Operating Systems

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Be Content with Content Assist

The Long and Short of Setting Up Level 40 Security

What Happened to My Backup?

System i PTF Guide
February 10, 2007: Volume 9, Number 6

February 3, 2007: Volume 9, Number 5

January 27, 2007: Volume 9, Number 4

January 20, 2007: Volume 9, Number 3

January 13, 2007: Volume 9, Number 2

January 6, 2007: Volume 9, Number 1

The Windows Observer
Ballmer Casts a Pall on Vista Sales Expectations

Microsoft Posts Free Vista Deployment Tools

Alaska Air Takes Off to SCM with AccuRev

Accruent Fills a Gap in Real Estate Management

The Unix Guardian
HP Adds Entry Itanium Servers, Finally Delivers HP-UX 11i v3

Unix Is Dead? It Isn't Even Sick. . .

Chip Makers Strut Their Stuff at ISSCC

As I See It: Measuring What Counts

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

ProData Computer Services
Aldon
Vision Solutions
Bytware
COMMON



TABLE OF CONTENTS
Approva Automates Compliance Efforts with BizRights

PowerTech Unveils New Password Utility

New BOSaNOVA Appliance Encrypts Tape Backups

S4i Gives DASD-Plus a New GUI

News Briefs and Product Shorts:


DataMirror Unveils Transformation Server 6.0 . . . Antares Finds a Systems Management Star in QSystemMonitor . . . Agilysys Updates Content Management System . . . Rexair Taps Quadrant to Improve Document Processing . . . NGS Updates Business Intelligence for Vormittag . . . BROWNtech Streamlines Access to County Records . . .

Four Hundred Stuff

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement