.

Thursday, April 30, 2015

Supply Chain Management and Advanced Planning Systems


One of the most prominent applications of optimization in today’s business world is using advanced planning in supply chain management (SCM). In short, SCM refers to coordinating material, information and financial flows in a company’s value chain including business partners such as suppliers, contract manufacturers, distributors, and customers. In the following chapter we give a concise introduction to the SCM and supply chain planning terms and concepts sufficient for the following context of optimization applied to supply chain problems and introduction of the SAP APO software. For a more thorough treatment of SCM and advanced planning see the ample literature on this topic; Stadtler and Kilger (2004, [92]) is an excellent reference.

1.1 Supply Chain Planning – a Brief Introduction The term supply chain management was introduced by the business consul- tants Oliver and Webber in the early 1980’s (see Oliver and Webber, 1992, [75]) and since then a wide variety of definitions depending on individual’s point of view has been created. We will stick to our short and broad defini- tion as it is sufficient for the purpose of this book.

SCM is a business economics term and the involved tasks and processes as well as solution methodologies are classified in a business-oriented way. To someone with a mathematically oriented science background this may appear less exact and precise than desired. Therefore there is an arbitrary large potential for misunderstandings and conflict when dealing with mathematical issues such as optimization in SCM. We see it as a primary target for this book to help build a bridge between business administration and economics on the one hand and the exact sciences on the other hand. The basic advise in this context is to agree on some sort of communication quality standards ensuring that precise definitions are used and that it is checked whether all participants involved in the communication mean and understand the same when using certain terms.

As manifold as the definitions of SCM are the attempts to model processes
and concepts of actually doing supply chain management in a standardized
way. The Supply-Chain Council, a non-profit organization formed as an in-
dependent consortium in 1996, standardizes supply chain terminology and
processes in the widely accepted and adopted Supply-Chain Operations Ref-
erence (SCORR ) model. The Supply-Chain Council focuses on practitioners
rather than academia and comprises several hundred members, the majority
of which are companies and organizations applying SCM and the SCOR prin-
ciples to their business. The SCOR model aims at improving supply chain
processes and structures to serve customers’ needs as well as possible. There-
fore it takes into account processes and transactions from the “supplier’s sup-
plier” to the “customer’s customer” enabling supply chain evaluations from
different aspects – from within and outside the company. The model is di-
vided into four hierarchical levels dealing with process types, process categories,
process elements, and, finally, implementation. None of these four hierarchical
levels touches solution methodologies such as mathematical methods or opti-
mization techniques, however. In each level predefined best practice building
blocks are available which can be used to model supply chain processes in an
easily reconfigurable way. Figure 1.1 shows the SCOR model’s level one with
the five elementary management processes plan, source, make, deliver, and
return. In each of the process types there is potential for optimization such
as in long-term capacity planning, production planning, detailed scheduling,
or vehicle routing. Kallrath (2002, [51]) discusses this in more detail. The

other levels of the SCOR model provide a deeper level of detail; level two, for
instance, distinguishes between 30 process categories covering planning, exe-
cuting, and enabling. One of the biggest benefits of using a standard model
like SCOR is introducing a standard terminology enabling efficient communi-
cation between the parties involved in implementing a supply chain strategy.
The Supply-Chain Council has created a glossary that defines more than 300
terms and metrics allowing standardized performance benchmarking of a given
supply chain.
Diving a bit deeper into the four processes source, make, deliver, and return
we have to distinguish between planning the future events in the supply chain
and dealing with current events and tasks. The earlier is widely called sup-
ply chain planning (SCP), the latter supply chain execution (SCE) or supply
chain operations. Examples of SCP are strategic and tactical planning such as
network design, network or master planning, production planning, transporta-
tion planning and routing, demand forecasting, and so on; examples for SCE
include event tracking (for instance, in transportation), warehouse operations,
transportation load consolidation, shop floor control in manufacturing execu-
tion, etc. From the nature of these tasks it is quite straightforward to see that
on the one hand SCP typically is done once in a while in order to get results
that remain valid between instances of executing the SCP process, and SCE
on the other hand is in some sense “always online” because it has to be ready
to trigger and execute certain actions in response to real-world events. Master
planning as a typical SCP process, for instance, is – depending on the type
of industry and particular business – done once a day, once a week or even
less frequently and results in a rough-cut plan that allocates resources in the
production network to certain activities that work towards fulfilling customer
demands. Due to the fact that these plans typically affect multiple locations
and hence involve not only communication with electronic systems, but also
a certain amount of human interaction before they are actually executed, it
is not feasible to execute them continually.
1
Optimization as a solution technology for supply chain problems, at least on the tactical planning level, is “offline”, too. It takes a snapshot of the business data of interest, optimizes according to a well-defined model, and writes the results back to the business data repository (which usually is some sort of transactional business software system such as SAP R/3 or mySAP ERP). Often, performance, process, and problem localization requirements chase optimization away from SCE tasks: for most companies it is undesirable to re-calculate all delivery routes in the case of one delivery truck out of many dozen being involved in a traffic accident, for example. A more desirable scenario in this case would probably be to apply some local, rules-based algorithm that might suggest to extend the 

This, of course, is an oversimplification. There are more facts to be taken into
account such as machine setup times for certain production processes that make product changes expensive. A good master planning algorithm takes this into account.

tour of another truck or to rent an additional vehicle serving the remaining
customers from safety stock. Optimization will be successful in this area if
the model is thoroughly designed to match the specific businesses, but this
usually rules out commercial, preconfigured optimization applications.

1.1.2 Supply Chain Planning and Advanced Planning Systems
A step towards formalizing and defining SCP in a more concise way than we
just did has been taken by Rohde et al. (2000, [79]) who define the supply
chain planning matrix classifying SCP tasks by planning horizon and supply
chain process. In Fig. 1.2 we give a version of the SCP matrix; note the
similarity of the processes along the x-axis with the SCOR process types
source, make, and deliver. The vertical axis in the SCP matrix corresponds
to the time horizon affected by the corresponding planning processes and also
gives an idea about how frequently the planning activities are performed.
Although the SCP matrix is not completely adopted in the literature and has
some structural drawbacks (cf. Tempelmeier, 2001, [96]), we will use it as a
tool displaying SCM functionality “at one glance” – without asking questions
like “Why does MRP belong to procurement?” or “Does demand planning
really belong to supply chain planning?”. With the exception of stand-alone
Material Requirements Planning (MRP) we see the functional modules of the
SCP matrix in software systems called advanced planning systems (APS):

Strategic Network Planning plans and coordinates strategic supply
chain processes creating suggestions for network design, cooperative supplier
contracts, distribution structures, manufacturing programs, etc. Decisions
made based upon this module are strategic and thus long-term in nature
and consequently cannot be undone or changed without considerable finan-
cial impact. The underlying data of such decision processes are mostly not in
the transactional business software but in archives such as data warehouses.
This leads to most companies setting up strategic network planning projects
using in-house or external consultants with customized mathematical software
tools independently of their enterprise business software.
Demand Planning takes a supporting role to the planning processes
by generating forecasted demand figures that are fed into the other planning
modules. Its functionality is based on statistical methods, on “collaboration”
between business partners such as key customers or distributors that can
help estimate future demand, and on data analysis methods such as “what-if
analyses”, aggregation/disaggregation, etc.
Master Planning creates feasible mid-term production plans synchro-
nizing the material flow along the supply chain and ensuring efficient resource
utilization in procurement, production, warehousing, and distribution. Usu-
ally this is a centrally executed process because its outcome affects the whole
supply chain and respects interdependencies of different supply chain parts
such as production facilities being able to manufacture the same product.
Master planning depends on input data obtained from network design, de-
mand planning, and cost data from all parts of the supply chain – these costs
are used to decide between options in procurement, production, and trans-
portation of goods. Depending on the complexity of the supply chain and its
processes master planning is often restricted to consider bottleneck materials
and/or resources or aggregated production processes.
Available- and Capable-to-Promise (ATP/CTP) help in order pro-
mising. When a customer order for a specific product comes in, ATP checks
quantities in stock and planned receipts (from procurement and production)
across the entire supply chain to determine a delivery date for the order. Op-
tionally, CTP can create production orders for the required product, which
involves changing and adapting production plans according to incoming cus-
tomer orders and available resource capacity.
Production Planning and Scheduling creates detailed, short-term
production plans for individual production areas (e.g., plants) based on the
results from master planning. The tasks can be divided into lot sizing, resource
utilization planning and detailed scheduling. Similar to master planning, the
goal is a feasible plan that respects resource and material constraints, but here
we look at only one production area in all detail, i.e., without aggregating or
restricting processes as in master planning. The detailed production plan is
passed on to manufacturing execution / shop floor control systems and hence
leaves the classical domain of APS.
Distribution and Transportation Planning determines which quan-
tities of goods are transported via which routes in the supply chain at what
times. Distribution planning deals with transportation quantities and stock
levels in connection with customer deliveries considering stock and transport
capacities whereas transportation planning performs routing and load plan-
ning determining cost effective and timely deliveries.
1.1.3 Advanced Planning Systems and Optimization
APS supplement the existing optimization programming libraries and pure
optimization engines with “ready-to-use” applications covering certain SCM
processes. Almost all major business software providers offer an APS as part
of their application suite covering the processes described above to a larger or
smaller extent. They typically divide their software into modules covering one
or more of the SCP matrix elements; often enough the quality of this coverage
is dependent on the industry – good functionality for production planning in
the process industry does not necessarily imply that the respective APS is
well-suited for discrete manufacturing such as high tech. In a complete SCM
solution these modules have to work together in an integrated way which sets
high standards for implementing and running those APS solutions. Often it
is most beneficial to use the APS and the ERP system from the same vendor
to take advantage of native system integration technologies.
Optimization techniques are applicable in the areas of Strategic Network
Planning, Master Planning, Production Planning and Scheduling, and Dis-
tribution and Transportation Planning. The remaining areas are typically
tackled with statistics (Demand Planning), rules-based algorithms (sales or-
der promising, ATP/CTP), or transactional and/or rules-based processing
(MRP). Commercially available APS that make use of optimization usually
offer comprehensive, but predefined mathematical models for one or more of
these application areas. We see those commercial APS as an augmentation to
the programming libraries, pure optimization engines, e.g., Xpress-MP TM and CPLEX.



Wednesday, April 29, 2015

CISA Exam Question Bank Mock 1 of 10 (Latest)

1. Disabling which of the following would make wireless local area networks MORE secure against unauthorized access?

Select an answer:
A.  MAC (Media Access Control) address filtering

B.  WPA (Wi-Fi Protected Access Protocol)

C.  LEAP (Lightweight Extensible Authentication Protocol)

D.  SSID (service set identifier) broadcasting


Answer is D

Disabling SSID broadcasting adds security by making it more difficult for unauthorized users to find the name of the access point. Disabling MAC address filtering would reduce security. Using MAC filtering makes it more difficult to access a WLAN, because it would be necessary to catch traffic and forge the MAC address. Disabling WPA reduces security. Using WPA adds security by encrypting the traffic. Disabling LEAP reduces security. Using LEAP adds security by encrypting the wireless traffic.


2. Which of the following is the BEST reason to implement a policy which addresses secondary employment for IT employees?

Select an answer:
A.  To ensure that employees are not misusing corporate resources

B.  To prevent conflicts of interest

C.  To prevent employee performance issues

D.  To prevent theft of IT assets


Answer is B

The best reason to implement and enforce a policy governing secondary employment is to prevent conflicts of interest. Conflicts of interest could result in serious risk such as fraud, theft of intellectual property or other improprieties. The other options are not correct because issues such as the misuse of corporate resources, poor performance and theft of IT assets are not as severe as the possible ramifications of a conflict of interest.


3. An IS auditor has been assigned to review an organization's information security policy. Which of the following issues represents the HIGHEST potential risk?

Select an answer:
A.  The policy has not been updated in more than one year.

B.  The policy includes no revision history.

C.  The policy is approved by the security administrator.

D.  The company does not have an information security policy committee.


Answer is C

The information security policy should have an owner who has approved management responsibility for the development, review and evaluation of the security policy. The position of security administrator is typically a staff-level position (not management), and therefore would not have the authority to approve the policy. Without proper management approval, enforcing the policy may be problematic, leading to compliance or security issues. While the information security policy should be updated on a regular basis, the specific time period may vary based on the organization. Although reviewing policies annually is a best practice, the policy could be updated less frequently and still be relevant and effective. An outdated policy is still enforceable, whereas a policy without proper approval is not enforceable. The lack of a revision history with respect to the IS policy document is an issue, but not as significant as not having it approved by management. An IS policy committee is not required to develop and enforce a good information security policy. The policy could be written by one person, as long as the person who approves the policy has the proper authority and knowledge to review and approve the policy. Although a policy committee drawn from across the company is a best practice and may help write better policies, a good policy can be written by a single person, and the lack of a committee is not a problem by itself.


4. An IS auditor is reviewing IT projects for a large company and wants to determine whether the IT projects undertaken in a given year are those which have been assigned the highest priority by the business and which will generate the greatest business value. Which of the following would be MOST relevant?

Select an answer:

A.  A capability maturity model (CMM)

B.  Portfolio management

C.  Configuration management

D.  Project management body of knowledge (PMBOK)


Answer is B

Portfolio management is designed to assist in the definition, prioritization, approval and running of a set of projects within a given organization. These tools offer data capture, workflow and scenario planning functionality, which can help identify the optimum set of projects (from the full set of ideas) to take forward within a given budget. A CMM would not help determine the optimum portfolio of capital projects since it is a means of assessing the relative maturity of the IT processes within an organization: running from Level 0 (Incomplete—Processes are not implemented or fail to achieve their purpose) to Level 5 (Optimizing—Metrics are defined and measured, and continuous improvement techniques are in place). A configuration management database (which stores the configuration details for an organization's IT systems) is an important tool for IT service delivery and, in particular, change management. It may provide information that would influence the prioritization of projects, but is not designed for that purpose. PMBOK is a methodology for the management and delivery of projects. It offers no specific guidance or assistance in optimizing a project portfolio.


5. An IS auditor has been assigned to review IT structures and activities recently outsourced to various providers. Which of the following should the IS auditor determine FIRST?

Select an answer:

A.  An audit clause is present in all contracts.

B.  The service level agreement (SLA) of each contract is substantiated by appropriate key performance indicators (KPIs).

C.  The contractual warranties of the providers support the business needs of the organization.

D.  At contract termination, support is guaranteed by each outsourcer for new outsourcers.

Answer is C

 The complexity of IT structures matched by the complexity and interplay of responsibilities and warranties may affect or void the effectiveness of those warranties and the reasonable certainty that the business needs will be met. All other choices are important, but not as potentially dangerous as the interplay of the diverse and critical areas of the contractual responsibilities of the outsourcers.







Tuesday, April 28, 2015

Roles and Responsibilities in IT Governance


IT Strategy Committee
It is one of the best practices to have an IT Strategy Committee. This committee should not only provide advice on strategy, but also focus on IT's value, risk and performance.

IT Balance Scorecard (BSC)
IT Balance Scorecard (BSC) is process management evaluation technique used in IT governance. The application of the BSC to IT follows a three layered structure to address for perspectives. 


Mission 
  • Deliver economic, effective and efficient IT applications and services
  • Obtain good value from IT investments.
  • Create oppertunities to prepare for future challenges.
Strategies
  • Creating superior applications and operations
  • Develop user partnerships and better customer services.
  • Increase services levels and pricing structures
  • Control IT expenses
  • Provide new business capabailities and other value to IT projects 
  • Training of the IT Staff
Measures
  • Providing a balanced set of metrics used for IT decisions.


Audit Role in IT Governance

IT should be governed by best practices that ensure an organization's information and related technology support enterprises business objectives. 


  • By today standards, IT is an intrinsic part of business and not considered as a seperate department. 
  • How IT is applied within an organization will have an immense effect on whether the organization meets its objectives or not. 
Auditing plays a key role in making IT successful for an organization. One of the main goal of audit is to give recommendations to improve the quality and effectiveness of IT. 

An audit can also monitor compliance and make sure that IT is in compliance. Reporting on IT governance invovles auditing at the highest level in the organization which can cross departmental boundries. 

An audit should be defined by the clear scope of work to be done with a clear definition of the functional areas and its issues.

Auditors should remain objective and independent, and if this cannot be taken care of internally , a third party independent auditor can be hired. 

The IS Auditor should assess the followings:
  • The alignment of the IS function to the organization's objectives.
  • If the performance objectives are being achieved.
  • Compliance to regulatory laws and requirements.
  • Control Enviroment of the organization.
  • Inherent risks within the IS enviroment.
  • The IT investment or expenditure. 

IT Governance

IT Governance

Corporate Governance 
Corporate governance should promote ethical issues and decision making practices within an organization. 

Corporate Governance can be defined "the system by which business corporations are directed and controlled"


Image result for corporate governance
Corporate Governance is set of responsibilities and practices to: 

  • Provide Strategic Direction
  • Ensuring that goals are achievable
  • Risks are properly addressed
  • Organisational Resources are Properly utlized 
The framework of corporate governance should:
  • be established to manage reports on risks
  • require that there is  an internal control system that monitors risks.
  • be a platform for the protection of stakeholders by dividing responsibilities to the Board of Directors.
  • Corporate Governance can help strike a balance between the objectives of exploiting available oppertunities to business value while also keeping within the limits of regulatory requirements.
Corporate Governance Framework is expanding into different countries where goal is to reduce inaccurate financial reporting while giving greater transparency and accountability.

IT Governance
IT Governance is part of overall Corporate Governance that should address how IT is applied inside the organization. It importance is increased because:

- Organizations are now more relying on IT
- One of the key objective of IT Governance is to align business and IT in order to increase business value. 



IT Governance focus on delivering secure and reliable information that is critical to success of the organization. The other benefit of IT governance is that the delivery of this information achives the successes of being more economical, efficient and effective. 

There are two major issues that IT Governance Focuses on:


  1. - Strategic Alignment of IT with the Business
  2. - Embedding accountability into enterprise


IT Monitoring and Assurance Practices for Board and Senior Management


  • It is important that all stakeholders, which would include the board and senior managment provide input into the decision making process about IT governance.
  • IT Governance is not just a good management practices and a framework of IT controls, but it is a management system that is about stewardship of the IT resources on behalf of the stakeholders.
  • Governance should be focused on delivering value and measuring performance. 
  • IT Governance can be considered as the shared management.
  • It ensures alignment of IT with the organization's objectives.
  • It should enable an enterprise to exploit new oppertunities and maximise benefits. 
  • IT governance framwork should be aligned with accepted best practices. 

IT Governance Framework

Following are key requisites of an IT Governance Framework:
  • IT resource management: Focuses on the inventory of the resources as well as the risks involved in those resources.
  • Performance Measurement: Ensures that IT resources are performing as expected as well as, delivering benefit to the organization.
  • Compliance Management: Ensures that IT processes are as per all applicable regulations. 

IT Governance focuses on:
  • Risk Management: Making sure that all are aware of the risks involved with IT, as well as knowing the organization acceptance of risk.
  • Resource Management: Having the right investment in the propoer management of the Critical IT Resources which would include the infrastructure and its people.
  • Performance Measurement: A strategy to track and monitor projects, resource usage, process performance and delivery.

Some Important IT Governance Frameworks:

    • COBIT: It was developed by ISACA to support. IT Governance best practices to provide guidance to organizations. 
    • ISO / IEC  27001: A series of standards and best practices to provide guidance to organizations. 
    • ITIL: IT Infrastructure Liabrary (ITIL) is a detailed framework with handson information on how to achieve successful service management of IT.
    • ISO / IEC 38500: It gives a framework for effective IT Governance for those of the highest level of management to understand and fulfill their legal and regulatory obligations. 

Information Security Governance 

Security is focused around three areas which are confidentiality, integrity and availability. 

Security is no longer bound to to the boundries of the organization due to the large growth of technologies such as cloud computing. Protection of information is key component of information security. 

The task of providing the necessary protection for information resources must now be raised to a broad level activity as well as other governance functions.

Benefits of good Information Security Governance are:
  • Providing assurance of policy and standard compliance.
  • Providing a structure and framework to optimize limited security awareness

Tuesday, April 29, 2014

Defining Chart of Account in SAP

A chart of accounts (COA) is a financial organizational tool that provides a complete listing of every account in an accounting system. An account is a unique record for each type of asset, liability, equity, revenue and expense.

A COA, which lists the names of the accounts that a company has identified and made available for recording transactions in its general ledger, establishes the level of detail tracked in a record-keeping system. Typically, a COA contains the accounts’ names, brief descriptions and identification codes.

In practice, the COA serves as the foundation for a company’s financial record keeping system. It provides a logical structure that facilitates the addition of new accounts and deletion of old accounts.

Within the COA, accounts will be typically listed in order of their appearance in the financial statements. Typically, Balance sheet accounts are listed first followed by the income statement accounts.

Definition
This is a list of all G/L accounts used by one or several company codes.

For each G/L account, the chart of accounts contains the account number, account name, and the information that controls how an account functions and how a G/L account is created in a company code.

Use

You have to assign a chart of accounts to each company code. This chart of accounts is the operating chart of accounts and is used for the daily postings in this company code.

You have the following options when using multiple company codes:

You can use the same chart of accounts for all company codes
If the company codes all have the same requirements for the chart of accounts set up, assign all of the individual company codes to the same chart of accounts. This could be the case if all company codes are in the same country.

In addition to the operating chart of accounts, you can use two additional charts of accounts
If the individual company codes need different charts of accounts, you can assign up to two charts of accounts in addition to the operating chart of accounts. This could be the case if company codes lie in multiple countries.

Note

The use of different charts of accounts has no effect on the balance sheet and
profit and loss statement. When creating the balance sheet or the profit and loss statement, you can choose whether to balance the company codes which use different charts of accounts together or separately.

Structure

Charts of accounts can have three different functions in the system:

Operating chart of accounts

The operating chart of accounts contains the G/L accounts that you use for posting in your company code during daily activities. Financial Accounting and Controlling both use this chart of accounts.

You have to assign an operating chart of accounts to a company code.

Group chart of accounts

The group chart of accounts contains the G/L accounts that are used by the entire corporate group. This allows the company to provide reports for the entire corporate group.
The assigning of an corporate group chart of accounts to a company code is optional.

Country-specific chart of accounts

The country-specific chart of accounts contains the G/L accounts needed to meet the country's legal requirements. This allows you to provide statements for the country's legal requirements.
The assigning of an country-specific chart of accounts to a company code is optional.

Integration

The operating chart of accounts is shared by Financial Accounting as well as Controlling. The accounts in a chart of accounts can be both expense or revenue accounts in Financial Accounting and cost or revenue elements in cost/revenue accounting. You can find additional information on this subject under