Download as pdf or txt
Download as pdf or txt
You are on page 1of 16

CIMCON EUC Insight

Discovery/Scanning

© CIMCON Software, LLC


CIMCON Software
• We provide the industry's most comprehensive end-user
“Two-decade history, market
computing controls presence, vision and breadth of
functionality results in its being
the highest rated vendor in this
Our core philosophy is to efficiently find, fix and prevent errors in research.” Marketscope for
Spreadsheet Controls
business critical EUC files and to do this without increasing the burden
of work on the everyday user

• EUC Insight for discovery, inventory management, risk assessment 10 years


and analysis to monitoring, versioning, approvals and security Ranked # 1 for 3 consecutive
Years as ISO years in customer surveys in
the categories of
• Over 20 years experience in helping to reduce the risk from EUCS Certified and “Spreadsheet Compliance
Microsoft Gold Products” and “Sarbanes-
for banks, insurance companies, asset management firms, Oxley Products”.
Partner
government etc.
The Objective?

“We have discovered high risk EUCs throughout the



enterprise, registered them within a central inventory
and have details on each one reflecting our EUC
Policy”

“We have secured the use of these files and


embedded tools to ensure we protect ourselves from
errors, mistakes and fraud.”

© CIMCON Software, LLC


EUC Insight Capabilities

© CIMCON Software, LLC


1a) Fast Discovery: Fast Scan
Find the size of the EUC landscape
• Use Fast scanning to find how many EUCs could be in Information Security Compliance
your network
• Performed by IT sanctioned service
Scan your network drives quickly account with read permissions on the
shared drives
• Report on the number of possible EUC files
on any number of shared drives • Admin User cannot open scanned files,
• Works on-premises or on Cloud they only see the output from the scan

Get basic EUC file metrics • No CIMCON files or executables are


loaded onto your shared drives
• Date/Age
• Size • All data remains “where is, as is”
• File type

It's fast !
• Scans millions of files in an hour

© CIMCON Software, LLC


1b) Enhanced Discovery: Detailed Scan
Identify high risk files
• Use detailed scanning to help find critical EUCs

Selected file scanning


• Enter list of files or folders to be scanned from Excel file
• Will scan those files and linked files if requested

5 Levels of scanning
• Performs a variety of diagnostic tests based on your risk
parameters
• Automated Risk Assessment scoring
• Configurable filtering used to auto-sort large quantities of files
and reduce false positives

Customisable Risk Assessment parameters


• Complexity, Materiality and Errors
• Keywords and VBA code
• User input / Business Risk fields
© CIMCON Software, LLC
1c) Discovery: Scanning Outputs
Automated, consistent risk categorisation
• Risk levels of High/Medium/Low (if not Owner attested)
• List of candidate EUC and non-EUC files

Automatic risk classification/grouping


• Old, complex, large, departmental etc.
• Supports going from 1 million files to 1,000 EUCs

Data Integrity/lineage Mapping


• Find Stale and Broken links, files on local drives, etc.
• Target where to put your auditing effort

Detailed reports / dashboards


• Understand your EUC landscape
• Exception reporting

© CIMCON Software, LLC


Other EUC Insight Modules
2) Inventory: Customisable EUC register
Manual or Automatic loading
• Populate from existing inventory lists
• Update inventory via scanning output
• Manually register file or files

Configurable reporting
• Help your EUC owners and reviewers to keep their EUCs
compliant to your policy
• Automatic reassessment reminders

User Attestation
• Configurable input form to store attestation data
• Designed as per your EUC Policy
• Create your own multipage form, with intelligent controls
and customisable risk matrix

© CIMCON Software, LLC


3) Change Management: Automatic Controls
Controls to match your EUC Policy/Guidelines
• Automatic server based EUC monitoring
• Effortless collection of audit data
• Alerting on changes to high risk EUCs
• Reports delivered to key users only when they need them
• Provides evidence of Control compliance

Prevent unwanted changes


• Granular, cell level controls e.g. formula locking
• Location-based, enhanced information security

Control your change process


• Approve single or multiple changes
• Version approval
• Multi format file comparison
• Fully functional automated Workflow, as designed by you

© CIMCON Software, LLC


3a Control Evidence collection
Efficiently audit and approve changes
• Changes made to controlled EUCs are automatically
recorded when the file is saved

• Selective changes can be reviewed and approved by


appropriate personnel

• Manage the change process by the appropriate workflow


– complete with email tasks and reminders

• Fully customisable audit trail available at any time

• Designed to cut down the false positives – concentrate on


only the important changes

Alerting and file comparison


• Alerting via email for changes to high risk files

• Compare EUC versions to quickly find and approve


changes

© CIMCON Software, LLC


3b Control Security
Lock files
• Controlled files can be locked down when changes are
finished to prevent unwanted changes
• Lock cells, sheets, formulas or files
• Allow or deny access to users
Use Version control
• can be employed to ensure only the correct version of a
file is available to users
• Create your own statuses to match your EUC Policy

Fast evidence
• Audit trail of file use available as evidence

Stay in Excel
• All functionality available directly in Excel

© CIMCON Software, LLC


3c Control Documentation
Attach supporting documents
• Details on how to use the EUC, control evidence etc.
• Links to the relevant documents or bring them into the
CIMCON database
Produce a Controls Report
• Comprehensive Controls report to produce evidence and
other details on an EUC
• Contains details on versions, KPIs, workflows, signoffs,
documentation and much more
Help the EUC owners to comply
• Customisable user Attestation form to collect EUC details
directly from Excel
• Designed to reflect your EUC Policy
• Auto reminders sent to users when review required
• Automatic and/or manual risk assessment

© CIMCON Software, LLC


3d Control Management Information
Report on your EUC Controls
• Internal reporting and drillable dashboards covering all
functionality
• Actionable insight
• Export to Excel or PDF as standard
• Scheduled reporting, focusing on exceptions, to keep
user interaction at a minimum
• Option to create Tableau files
• Export to Qlik, Power BI, Spotfire, Cognos etc.
• Custom dashboard reporting as part of
Implementation

© CIMCON Software, LLC


XL Audit – Excel Diagnostics
• End User software for detailed analysis of high risk
tools/models built in Excel
• Comprehensive functions to find and correct issues
– Embedded ribbon within Excel with lots of simple tools
to spot errors and issues
– Cell, Sheet, Workbook level analysis
– VBA Best practice

• Automated Documentation and Audit worksheet


– Produce documentation of inputs, outputs, formulae and
EUC Details

• Risk assessment & Data linage mapping


– Data flow/lineage (internal and upstream)

• Vehicle that collects self-attestation data

© CIMCON Software, LLC


Contact details
Will Heffernan
wheffernan@cimcon.com
+44(0) 1189 466 1048
400 Thames Valley Park
Reading, Berkshire, UK

© CIMCON Software, LLC

You might also like