You are on page 1of 23

11i eBS specifications & requirements

A Practical Guide

Nikos Plevris
Principal Service Delivery Manager
Agenda

• 11i PC specifications <Insert Picture Here>

• The multi-tier model


• 11i eBS browser recommendations
• Recommended Browsers & security zones
• Browser security considerations
• 11i eBS AuditTrail practices
• Summary
• Q&A
11i PC specifications

• CPU: Pentium-class III or higher


• RAM: 256Mb or higher
• OS: MS Windows 2000 SP2 or higher
APPLICATION TIER
The multi-tier
Apache
environment Mod_plsql

DATABASE TIER
DESKTOP TIER Jerver

ORACLE_HOME
iAS

ORACLE_HOME
Forms Designer RDBMS

TNS Listener
Web Borwser,
Reports
Jinit
Concurrent RAC
Managers

APPL_TOP
ORACLE_HOME
Tools
11i eBS browser recommendations

• Oracle's certification of the various third party client


operating system and browsers aligns with the
respective vendor's support lifecycle
• MSIE 6.0 & 6.0 SP1 and SP2 are the preferred
browsers for E-Business Suite 11i on MS Windows
clients
• Mozilla Firefox 1.0.x, 1.5.x, Netscape 7.2 are certified
• Currently 'Internet Explorer' is the only browser that
allows you to access multiple instances or multiple
Application Responsibilities concurrently from the
same desktop session, through the use of multiple
browser sessions.
Recommended Browsers & security
zones1
Browser MS Win XP MS Win 2000
version
MSIE 6.0 JInitiator 1.1.8.x JInitiator 1.1.8.x
JInitiator 1.3.1.x JInitiator 1.3.1.x
MSIE 7.0 JInitiator 1.3.1.x Not Supported
Oracle Applications is run through the 'Trusted Sites' zone, with a 'Medium' Security
Setting

Security Zone Usage Default


Internet Web sites not placed in IE 6 - Medium
other zones IE 7 - Medium-high
Local Intranet Web sites on your Medium-low
organization's intranet
Trusted sites Web sites you trust not to IE 6 - Low
damage your computer IE 7 – Medium
Restricted sites Web sites that could High
potentially damage your
computer
Recommended Browsers & security
zones2

Browser MS Win XP MS Win 2000


version
NETSCAPE 7.2 JInitiator 1.3.1.x JInitiator 1.3.1.x
Mozilla 1.7.x (where x is JInitiator 1.3.1.x JInitiator 1.3.1.x
greater than or equal to 5)

Firefox 1.0.4 and later JInitiator 1.3.1.x JInitiator 1.3.1.x

Firefox 1.5 and later JInitiator 1.3.1.x JInitiator 1.3.1.x


Browser security considerations

• Enable Page Refresh


• Shared Desktop Security (multiple users share the same desktop)
• Prevent users to view a previous user browser content by pressing the 'Back'
button on the browser. To fix this issue, please apply Oracle Applications
Framework 11i.FWK.H Patch 3262919  or later and patch 4318900. You must
also set the Applications 11i 'Force Page Refresh' profile option to 'Yes'. 
• it is advisable not to save encrypted pages onto the drive.  To set this option,
go to Tools -> Internet Options -> Advanced tab -> Security settings and tick 'Do
not save encrypted pages to Disk‘ (applicable to MS Explorer)
• Disable Autocomplete in Internet Explorer
• Set HTTP 1.1/Keep Alive Settings
• Java applet-Uncheck the 'Enable Java' option (applicable to
Netscape/Mozilla/Firefox)
11i Audit Trail practices
Tough Questions for Oracle
Applications
• How do you know key
controls are operating
effectively throughout year?
• Can you report on ALL
changes to key controls?
• How do you search for
segregation of duties or
evaluate user access?
• How do you know controls
are same for each business
unit?
• How do you document key
controls within systems?
Why an ERP audit?

• Increased risk
• Higher Levels of Regulation
• Sarbanes Oxley 2002
• Increased adoption of IAS
Sarbanes-Oxley Cycles

YEAR 2, 3, 4…
YEAR 1
Monitor Changes
Document
& Test Controls
Processes, Risks
& Controls Continuous Monitoring
Auditing scope - Best Practices1
• Financial Reporting and Maintenance• Order to Cash
of Accounting Records • Order Entry
• General Ledger • Accounts Receivables
• Cash Management • Inventory
• Accounts Receivable • Human Resource Management and Payroll
• Accounts Payable • Human Resource Mgt. System
• Procure to Pay Business Process • Payroll
• Purchasing • Application Administration (including security
• Accounts Payable
• Inventory
and configuration management)
• Costing • System Administration
• Application Object Library (AOL)
Auditing scope - Best Practices2

Apps modules Apps Codebase

Automated Setups Forms


Documentation Reports
Code

Comparisons Instances Environments


Sets of Books Oracle Versions
Operating Units Code Versions
Versions

Change Monitoring Monitoring


Tracking Reporting Reporting
Alerting Alerting

Migration Application Setups Code Promotion


Examples of Setups

Setup Data Operational Data


• Application Security • Customers
• Document Approvals • Suppliers
• Chart of Accounts • Employees
• Profile Options • Buyers
• Users • Items
• Application Setups • Chart of Account Values
• MRP rules • Category Codes
Example of System Controls

• 3-way matching of PO, Invoice and Receipt


• Document spending limits (authorization of PO)
• Security rules – access to sensitive transactions
• Employee salaries
• Chart of account values
• Financial statement reports (FSGs)
• Price lists
• Inventory attributes
• Action for late delivery of goods
• Inventory stocking rules
• Rules to create tax on sales orders
• Depreciation methods
11i eBS Audit Trail feature

• Apps objects - Change Tracking


• Who?
• What?
• When?
Automatically captures
• Where?
a complete historical
audit trail. Details of
EVERY change.
Internal Controls Manager1
Audit and Review Capability from eBS 11.5.10.x
Internal Controls Manager2
Summary

• Define auditing requirements


• Only audit what needs to be audited
• Implement audit trail
• Create Maintenance and Administration plan
• Secure auditing objects
Q&
A

You might also like