PRISM Access: SOX Audit
Annual SOX Audit
Background
In compliance with the Sarbanes Oxley Act of 2002, the Office of the Controller conducts its annual review of system access granted to employees for PRISM applications (excluding Pitt Worx, Concur, and PantherExpress responsibilities). This review of system privileges helps to ensure access controls are based on two generally accepted standards of practice – “segregation of duties” and “least privilege”. It is understood that departments may have compensating controls in place to mitigate increased risks due to a lack of segregation of duties. Access privileges should be based on the least amount of system access needed to complete job responsibilities.
Only deletions submitted through this review will be processed. All other changes should be made through the normal PRISM access process. Refer to the PRISM WEB page at PRISM for instructions.
Audit Process
The process is for review and submission is separated into three parts:
Generating the employee list and their responsibilities for the corresponding RC
Reviewing the responsibilities and marking changes(if necessary)
Completing the Docusign attestation
Generating the employee list
To gain access to the information for your RC, use the link below to access the Tableau dashboard for the PRISM responsibilities and follow the instructions to download:
Filter to view the RC you are looking for by selecting it the Responsibility center dropdown
The default view is none to have the dashboard be a clean slate anytime it would be accessed
Click the green “download to Excel” button in the top right of the dashboard
Select Employee List-PRISM SOX
Three options will be available but the “info” and “employee count” are not needed
You can either download this as an excel file or a csv. The excel document will group all responsibilities for each user, not displaying duplicate information for each line. The csv file will have every line fully filled out with the user’s name and information for each responsibility they currently have.
Reviewing Responsibilities
You will be using the downloaded excel document to review and mark up any changes that need to be made. Once you have downloaded the document, create a column titled DELETE as the rightmost column. If any PRISM access (responsibility) should be deleted, please indicate by marking an X in the last column titled “DELETE”.
Completing the Docusign attestation
Below is the link to the Docusign attestation that you need to complete to finalize the SOX process:
The Excel file with changes must be attached in the Docusign if the options “Reviewed single RC with changes” or “Reviewed multiple RCs with one or more needing changes” are selected. Attaching the Excel file for your RC is only necessary if there are changes being made to any access.
If you responsible for reviewing multiple RCs and there are not any that require changes to be made, you can select the “Reviewed RC(s) with no changes” option. You are not required to submit an excel file with the attestation if no changes are necessary.