SlideShare ist ein Scribd-Unternehmen logo
1 von 45
Understand




Control        Improve




   Profiling for SAP® Compliance Management
   Access Control and Segregation of Duties
   Understand, Optimize and Control your Business and IT
Subject Matter
Profiling for SAP supporting Security Compliance for SAP®



  1        Profiling for SAP® Application

  2        Access Management and Segregation of Duties

  3        Optimization of Authorizations

  4        Project Support for SAP Blueprints




                          SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  2                     NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP for Compliance and Access Control




           Understand                            “Profiling your SAP® Solution delivers our
                                                 Clients all needed insights to understand,
                                                 improve and control their Business and
                                                 complex SAP® Landscapes.”


Control                 Improve                  Heinz-Jürgen Scherer, CEO TransWare AG




                          SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  3                     NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Standard application with tight SAP® integration, high automation
      and flexible configuration

      PROFILING FOR SAP
      APPLICATION
                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  4                  NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Analysis and the Process for Compliance

            1. Extract                                 2. Define                                                3. Analyze



                                                                                                                         Reports
                   Profiler                                          BI DB                        Analyzer             Dashboards




                                         Predefined set of Risk Rules
                                                                                                   Auditors, IT Security
                                                                                                   Analytic reports and
                                                                                                    dashboards
  Authorizations                        Define Risk Rules                                        Conflicts and potential
  Usage (Transactions,                  Critical activity groups                                  conflicts of Accounts
           Reports, RFC Calls)           Activities conflict matrix                                and/or Roles, Profiles

                                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  5                            NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP Product Components

 Profiling for SAP application customizing for SoD (configuration)
  Definition of Task groups, specifies a set of tasks with identifiers
  Assignments of critical transactions to task groups
  Risk rules combining Task Groups with Financial Risk Values
  Includes best practice for configuration settings
 Analytic Reports (examples)
  Charts plotting risks and SoD issues per e.g. SAP module
  Role Compliance Check: Identifies roles that have SoD conflicts based upon the
  underlying transactions
  User Compliance Check: Identifies SoD conflicts in user’s profile
 SAP Solution Manager integration (optional)

                           SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  6                      NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP® featuring SAP Compliance Management
Technical, Functional and Processual Analysis and Optimization of SAP

TransWare’s reengineering and optimization solution for SAP®, compliance and
  performance assessment and process analysis on any SAP® system or SAP®
  Industry Solution highlights process risks in a system review and will lead to
  minimized project times with corresponding cost reduction.
The solution reveals the quality of the implementation by analyzing transaction logs,
 document types, user authorizations with roles and profiles, SAP® HR info types,
 SAP® customizing and object modifications and other configuration items.
It shows the overall picture of customizing and utilization of the current SAP® system
   with business related KPIs.
Complex ERP systems are potentially susceptible to segregation of duties (SoD)
 issues. By means of Profiling for SAP®, the desired responsibilities of SAP® users
 can be counterchecked against the real usage of SAP®. Reporting of the results can
 be done per job role, so you know what each role entails in terms of process
 activities, SAP® business blueprint process steps, SAP® roles and transactions.

                         SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  7                    NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP® smartly supports the Transition
Phase from As-Is into an optimized SAP® Landscape
           As-Is Landscape                     To-Be Transition                          Optimize Landscape

                 Run SAP                                  ASAP                                        Run SAP
             Process IT Support                    Project Methodology                            Process IT Support


                 Business                                 Process                                      Compliance
               Reengineering                            Management                                     Management
                Understand                              Optimize                                       Control




                                  Access Control and Segregation of Duty


                       Technical                          Functional                            Processual
                       Analysis                            Analysis                              Analysis

                          Profiling for SAP® SoD Compliance
           Profiling for SAP® SoD Compliance is based on the technical, functional
           and processual analysis tool components.

                                   SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  8                              NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Introduction of an cost efficient compliance management

      ACCESS MANAGEMENT AND
      SEGREGATION OF DUTIES
                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  9                  NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Increased Focus on Security and Control


 Corporate scandals and fraud (Enron, Barings Bank, WorldCom, ...)
 Security breaches (UCs, BC, Stanford, ...)
 Regulatory Compliance
       • Sarbanes-Oxley (SOX, EuroSOX)
       • Family Educational Rights and Privacy Act (FERPA)
       • Federal Information Security Management Act of 2002 (FISMA)
       • Gramm-Leach-Bliley Act (GLBA)
       • Health Insurance Portability and Accountability Act (HIPAA)
       • Joint Commission (TJC)




                            SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  10                      NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Security Risks, Security Compliance and Internal Controls

  Are there any   Who has access
                                       Access Control
       SoD
   violations?
                     to sensitive
                   transactions?
                                           Do some users have too much access?
                                           Sufficient access restrictions to private information?
                                       Control for Segregation of Duties (SoD)
                                                Every time a user is added ensure his rights are
                                                 not in conflict with SoD risk rules
                                                A user's profile is amended and the change must
                                                 not cause any SoD conflict
                                                Review of the company SoD requirements on a
                                                 periodic base

“Internal Controls are processes designed by management to provide reasonable
assurance that the Institute will achieve its objectives.”
(From MIT’s Guidelines For Financial Review and Control)


                               SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  11                         NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP® and SAP® Authorizations
                                             Profiling for SAP combines information from
                                             different data sources like SAP usage, user
                                             authorization and SoD configuration with BI
                                             based reporting for a comprehensive security
                                             analysis.

                                             Actions are subject to authorization checks
                                             that are performed before the start of a
                                             program or table maintenance and mandatory
                                             for the SAP applications :
                                             · Starting SAP transactions
                                                   (authorization object S_TCODE)
                                             · Starting reports
                                                  (authorization object S_PROGRAM)
                                             · Calling RFC function modules
                                                   (authorization object S_RFC)
                                             · Table maintenance with generic tools
                                                   (authorization object S_TABU_DIS)

                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  12           NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP® Compliance Management
A Software Solution for SAP Project and Compliance Process Support

  Reduce time and efforts when providing ongoing information to
 internal and external auditors
  Remove access or assign mitigating controls
  Used during implementation of new SAP modules and processes or
  optimizing SAP systems
  Monitoring transaction and data access based on SAP background job
   for 24/7 security and compliance control
  Optionally runs on central SAP Solution Manager to manage complex
   SAP landscapes as a non-invasive solution
  Web based BI solution based on a Business Warehouse for
   Compliance Management

                      SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  13                NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Profiling for SAP® Compliance Application
A solution for compliance management based on standard software

 Profiling is a configurable custom application with integration into SAP that
 ensures all user’s authorizations are compliant with the company’s
 compliance rules

 Useful during all phases of the deployment lifecycle
        Design – Identify roles, build composite roles based upon team requirements
        Implementation – Test and verify SoD compliance of roles
        Production – Ensure compliance of existing users and roles

 Tight integration within SAP to manage complex SAP Landscapes and
  to leverage SAP standards
 Applicable to SAP’s ERP, CRM, SCM and other ECC-based products
 Web based product, non-invasive, non-deployment solution regarding
 SAP production systems
                             SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  14                       NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Set of Risk Rules based on SoD conflicts and critical actions
                       Risk
                     Rules Set                                           Set of Risk Rules for different business
                                                                          domains like FI-GL, MM, SAP Basis,
                                                                          CRM or etc.
              SoD                    Critical                            Define SoD rules and critical actions
              Rule                   Actions
                                                                          and add standard or custom
                                                                          transactions to the rule set
              and
                                                                         Define rules on Functional,
 Function                 Function              Function                  Transactional or the most detailed
                                                                          Authorization-Object level
                                                                         Define critical rules with high financial
Transaction              Transaction          Transaction                 risks or potential security risks
                                                                         Modify predefined configuration with a
                                                                          set of rules for SoD best practice
 Author.-                 Author.-              Author.-
 Object                   Object                Object



                                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
 Page  15                          NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Procedure for the Definition of SoD Risk Rules on a
Functional Level
                             1. Define SoD Functions (logical group of tasks)
              Define
             Functions            Example:
                                                Function A: – Process Sales Order
                                                Function B: – Maintain credits master data
                             2. Assign Transactions to SoD Function
               Assign
                                  Example:
            Transactions                        Function A – V-01, VA01, VA02, …
                                                Function B – FD24, FD32, FD37, …
                             3. Define and Characterize the SoD Functions
                                with Risk Rules
      Define Conflicts            Define a conflict: Function A & Group B
         and Risks                Characterize the conflict with financial risk indicators:
                                               •         High,                Medium,                     Low
                                       Exclude Rules from predefined configuration
                                        as N/A for your organization with a description
                           SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  16                     NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Examples for SoD Activities and Transaction Groups

  Description of Task Groups                                          SAP Transactions
  Group A: Process sales orders
  Create sales order                                                  V-01
  Create sales order                                                  VA01
  Change sales order                                                  VA02

  Group B: Maintain credit master data
  Credit limit changes                                                FD24
  Change customer credit management                                   FD32
  Credit management mass change                                       FD37
  Credit management mass change                                       F.34
  Customers: Reset credit limit                                       F.28
  Credit Limit Data mass change                                       S_ALR_87009999
  Reset Credit Limit for Customers                                    S_ALR_87012220




                                  SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  17                            NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Conflict Matrix
                                                                                                            RISK
                              Separated
      Function                                                           POTENTIAL RISK                     LEVEL
                               Function
                                                                                                          (X, M, H)
                                             User can increase a customer
 Maintain credit           Process sales  credit limit and then process sales
                   AND                                                                                       M
  master data                 orders       orders for that customer leading
                                                 to irrecoverable debt.
    Maintain                                  User can create a fictitious
                           Process sales
contract/schedu AND                         contract and then create sales                                   M
                              orders
ling agreement                               orders against that contract.
                                              User can create a fictitious
   Customer
                           Process sales    customer and create orders for
  master data      AND                                                                                       M
                              orders           delivery to them thereby
  maintenance
                                               misappropriating goods.
                                             User can create/change sales
  Process sales          Process outbound
                   AND                     orders and deliveries to hide the                                 H
     orders                 deliveries
                                              misappropriation of goods.
                                           User can create sales orders and
  Process sales            Maintain sales  maintain pricing, therefore over-
                   AND                                                                                       M
     orders                    deal       charging customers or giving then
                                               unauthorized discounts.


                           SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  18                     NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Critical Transactions and assigned Risks

  Transaction Description                                                           Risk
  FI12        Change House Banks/Bank Accounts                                      Financial Risk


  PA30        Maintain HR Master Data                                               Access HR data

  SCCL        Local Client Copy                                                     System stability &
                                                                                    integrity at risk

  SE11        Data Dictionary Maintenance                                           System stability &
                                                                                    integrity at risk
  PFCG        Role Maintenance                                                      Security Risk


  SM49        Execute OS commands                                                   System stability at risk




                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  19                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Excel to define Risk-Rules for Business-Domains




                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  20           NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Configuration of Rules

      SOD RULES


                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  21                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Rules on Functional Level




                SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  22          NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Conflict Matrix on Functional Level




            X=Financial Risk Exists, M = Medium Risk, H = High Risk

                             SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  23                       NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Critical Combinations on Functional Level with Details




                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  24           NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Rules and SAP® Authorizations

      SAP CONFIGURATION


                      SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  25                NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Roles & Profiles with SoD Transactions included




            Shows Transactions used for SoD rules assigned to Authorization Objects
            Identify all Authorizations Objects with potential risks.




                              SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  26                        NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SoD Conflicts with Risks for specific Composite-Roles




            Also available for specific Single-Roles and Profiles

                        SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  27                  NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Standard or customized profiles and user assignment

      CUSTOMIZED RISKS IN SAP


                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  28                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Potential Risks with Accounts customized in SAP



                                                                                                         ALL = ‘*’ in Authorization

                                                                                                         16 Conflicts for 21 Accounts




                                                                                                          At least one high financial
                                                                                                          risk in 485 conflicts for
                                                                                                          3 user


    X=Financial Risk Exists, M = Medium Risk, H = High Risk
                          SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  29                    NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Actual Risks in Execution of SAP




                 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  30           NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SAP Objects, Usage and Authorizations

      SAP USAGE


                      SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  31                NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SAP Modules, used Transactions and Authoritations




                SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  32          NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Accounts, Authorizations and Transaction Usage




                SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  33          NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
…and many analytic Reports more




               SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  34         NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Benefits
  Using the same kind of tools used by chartered accountants reduces
   service costs for external audit and advisory
  Reduction of project efforts and establishment of SoD compliant
  authorizations from the start
  Fully automated SoD analysis reduces TCO for the ongoing security
   control process
  Auditors and IT security staff work on functional level even for complex
   authorization scenarios
  Avoidance of manual analysis and false positive assessments
  Flexible configuration includes custom “Z” transactions or external
   applications like Portals using BAPI or direct RFC calls
  Easy identification of users with access to sensitive data by internal
   security teams lowers costs of the compliance process

                        SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  35                  NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Slimline authorization management of complex SAP®
      landscapes

      OPTIMIZATION OF
      AUTHORIZATIONS
                      SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  36                NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Slimline your SAP® Authorization Management

     Identify needless access rights by SAP Modules, Accounts, Transactions, …
     Optimize your custom roles by identifying critical roles and access overlap
     Setup segregation of duties by best practice and company compliance




                                                                                                          Assigned Role not
                                                                                                          relevant for execution
                             Example Report:                                                              of the custom “Y”
                                                                                                          YXPROC transaction




                           SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  37                     NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Benefits

 Efficient establishment of a tradeoff between Business Requirements and
  Company Compliance
 Substantial reduction of project efforts in company compliance initiatives
 Simplification of information access to complex SAP data for company
 auditors reduces costs for the compliance process
 Uniformed use of tools by chartered accountants reduces external
  audit and advisory services costs
 Allows the handling of complex SAP landscapes with automatic data
 retrieval and cross-SAP system analytics
 Automatic monitoring of changes of user authorizations given by
 organizational requirements lowers costs for audits and security control



                        SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  38                  NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Being compliant from the beginning

      PROJECT SUPPORT FOR SAP
      BLUEPRINTS
                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  39                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Blueprinting with ASAP and SAP Solution Manager
SAP® Solution Manager (SSM) is the SAP® tool that supports the plan, build
 and run aspects of ERP solutions based on SAP® NetWeaver and covers
 all needs for ITIL-compliant application lifecycle management (ALM).
SAP® describes ALM by the Run SAP® operational support methodology and
 the Accelerate SAP® (ASAP) project methodology. SSM serves as an
   interface between technology and business processes.
For SAP solution development like upgrades or implementations, the SAP
 solution is consistently documented in SSM by the Blueprint that describes
 the business processes and the resulting system configuration.
An important part of the SAP solution development is the configuration of
 organizational structures and optimized business and security compliance
 requirements.
Profiling for SAP® supports this aspect of SAP ALM to lower development
 and maintenance costs and improve process and compliance quality

                         SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  40                   NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SAP Blueprint Procedure for Compliant Authorizations
Support ASAP methodology and SAP Solution Manager Projects

                Define                    Define your functional Task Groups in SAP Solution
               Blueprint                   Manger as Jobs or Org.-Units as End-User-Roles
                                          Setup the Blueprint Process Structure by Business
                                           Process Management Methodology including
                                           organizational assignments to End-User-Roles
                                          Assign Transactions manually or use predefined
            Analyze Access                 Reference Models with T-Codes assigned like the SAP
             Requirements                  Business Process Repository (BPR )
                                          Run Reports to analyze organizational Access
                                           Requirements
                                          Automatically identify standard SAP right roles or
             Define Roles                  profiles supported
            and User Access
                                          Customize Roles (PCFG) and assign users
                                          Run analytic reports for SoD compliance and risk
                                           control

                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  41                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SAP Solution Manager for SAP Blueprints
Optimized user authorizations from project start-up

                                      SAP Blueprint with Masterdata,
                                      Org.-Unit Data, Scenarios,
                                      Processes, Process-Steps,
                                      Transactions and Documentation

                                                                                                              Assign End-User-
                                                                                                              Roles to Process-
                                                                                                              Steps, Master-Data or
                                                                                                              Organizational-Unit
                                                                                                              Data




            Process-Steps with
            Assigned Transactions



                               SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  42                         NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
SAP Solution Manager for SAP Blueprints
Export the Blueprint structure for analytic reporting




                                                                                                           Cross-Reference
                                                                                                           between Objects
                                                                                                           (T-Code, Forms,
                                                                                                           Reports etc) and
                                                                                                           End-User-Roles




       SAP Blueprint Structure (SAP Project)                     Assigned User, Jobs, Org.-Units

                            SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  43                      NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Benefits
 Support of SAP Solution Manager improves the SAP Blueprint
  business process definition in terms of Compliance and Risk Management
 Synchronize organizational structures, functional access requirements,
  business processes and access control for slimline, fine tuned and fully
  SoD compliant SAP authorizations
 Leverage SAP tools, methodologies and best practice by a tight SAP
  integration with a BI based solution that reduces SAP® project planning
  and implementation efforts
 Reduce SAP maintenance efforts by a consistent business process
 and security control documentation
 Ensure compliance through SAP improvements like ERP Enhancement
  Packages and organizational changes
 Define authorizations on functional level and support setup of technical
  roles and profiles.
                       SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  44                 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
Solutions by TransWare




                             TransWare Software Solutions AG
                             Fritz-Wunderlich-Str. 49
                             66869 Kusel
                             Germany

                             Phone: +49-(0)6381-916-0
                             Email: info@transware.de
                             Web: www.transware.de


            All product, service and company names mentioned herein are for identification purposes only and may be
            trademarks or registered trademarks of their respective owners


                                      SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP
Page  45                                NetWeaver® technologies with ASAP, Run SAP and BPM methodologies

Weitere ähnliche Inhalte

Was ist angesagt?

Segregation of Duties
Segregation of DutiesSegregation of Duties
Segregation of DutiesPECB
 
SAP Governance,Risk and Compliance
SAP Governance,Risk and ComplianceSAP Governance,Risk and Compliance
SAP Governance,Risk and ComplianceTLI GrowthSession
 
Grc 10 training
Grc 10 trainingGrc 10 training
Grc 10 trainingsuresh
 
Auditing SOX ITGC Compliance
Auditing SOX ITGC ComplianceAuditing SOX ITGC Compliance
Auditing SOX ITGC Complianceseanpizzy
 
IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOXMahesh Patwardhan
 
Sap grc process control 10.0
Sap grc process control 10.0Sap grc process control 10.0
Sap grc process control 10.0Latha Kamal
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...akquinet enterprise solutions GmbH
 
Sap Security Workshop
Sap Security WorkshopSap Security Workshop
Sap Security Workshoplarrymcc
 
Best Practices for SAP Access Controls | Symmetry™
Best Practices for SAP Access Controls | Symmetry™Best Practices for SAP Access Controls | Symmetry™
Best Practices for SAP Access Controls | Symmetry™Symmetry™
 
SAP Security & GRC Framework
SAP Security & GRC FrameworkSAP Security & GRC Framework
SAP Security & GRC FrameworkHarish Sharma
 
Identity Governance: Not Just For Compliance
Identity Governance: Not Just For ComplianceIdentity Governance: Not Just For Compliance
Identity Governance: Not Just For ComplianceIBM Security
 
Implementing SAP security in 5 steps
Implementing SAP security in 5 stepsImplementing SAP security in 5 steps
Implementing SAP security in 5 stepsERPScan
 
Identity & Access Governance
Identity & Access GovernanceIdentity & Access Governance
Identity & Access GovernanceHorst Walther
 
Iia los angeles sap security presentation
Iia  los angeles  sap security presentation Iia  los angeles  sap security presentation
Iia los angeles sap security presentation hkodali
 
GRC access control access risk management guide
GRC access control   access risk management guideGRC access control   access risk management guide
GRC access control access risk management guideGulzar Ghosh
 

Was ist angesagt? (20)

Ey segregation of_duties
Ey segregation of_dutiesEy segregation of_duties
Ey segregation of_duties
 
Segregation of Duties
Segregation of DutiesSegregation of Duties
Segregation of Duties
 
SAP Governance,Risk and Compliance
SAP Governance,Risk and ComplianceSAP Governance,Risk and Compliance
SAP Governance,Risk and Compliance
 
Grc 10 training
Grc 10 trainingGrc 10 training
Grc 10 training
 
Auditing SOX ITGC Compliance
Auditing SOX ITGC ComplianceAuditing SOX ITGC Compliance
Auditing SOX ITGC Compliance
 
IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOX
 
Sap grc process control 10.0
Sap grc process control 10.0Sap grc process control 10.0
Sap grc process control 10.0
 
SAP grc
SAP grc SAP grc
SAP grc
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
 
Day5 R3 Basis Security
Day5 R3 Basis   SecurityDay5 R3 Basis   Security
Day5 R3 Basis Security
 
Sap Security Workshop
Sap Security WorkshopSap Security Workshop
Sap Security Workshop
 
Best Practices for SAP Access Controls | Symmetry™
Best Practices for SAP Access Controls | Symmetry™Best Practices for SAP Access Controls | Symmetry™
Best Practices for SAP Access Controls | Symmetry™
 
SOX- IT Perspective
SOX- IT PerspectiveSOX- IT Perspective
SOX- IT Perspective
 
SAP Security & GRC Framework
SAP Security & GRC FrameworkSAP Security & GRC Framework
SAP Security & GRC Framework
 
SAP Risk Management
SAP Risk ManagementSAP Risk Management
SAP Risk Management
 
Identity Governance: Not Just For Compliance
Identity Governance: Not Just For ComplianceIdentity Governance: Not Just For Compliance
Identity Governance: Not Just For Compliance
 
Implementing SAP security in 5 steps
Implementing SAP security in 5 stepsImplementing SAP security in 5 steps
Implementing SAP security in 5 steps
 
Identity & Access Governance
Identity & Access GovernanceIdentity & Access Governance
Identity & Access Governance
 
Iia los angeles sap security presentation
Iia  los angeles  sap security presentation Iia  los angeles  sap security presentation
Iia los angeles sap security presentation
 
GRC access control access risk management guide
GRC access control   access risk management guideGRC access control   access risk management guide
GRC access control access risk management guide
 

Andere mochten auch

Automating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and FinancialsAutomating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and FinancialsSmart ERP Solutions, Inc.
 
Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23Smart ERP Solutions, Inc.
 
Segregation of Duties and Continuous Delivery
Segregation of Duties and Continuous DeliverySegregation of Duties and Continuous Delivery
Segregation of Duties and Continuous DeliverySriram Narayanan
 
3 Way Match for Purchasing Professionals
3 Way Match for Purchasing Professionals3 Way Match for Purchasing Professionals
3 Way Match for Purchasing ProfessionalsBill Kohnen
 
Sox Compliance Solution
Sox Compliance SolutionSox Compliance Solution
Sox Compliance Solutionguest586cf0
 
Security & Segregation of Duties for PeopleSoft
Security & Segregation of Duties for PeopleSoftSecurity & Segregation of Duties for PeopleSoft
Security & Segregation of Duties for PeopleSoftSmart ERP Solutions, Inc.
 
SAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM WorkflowsSAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM WorkflowsRohan Andrews
 
Sap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoftSap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoftPennonSoft
 
Custom security effective implementation
Custom security   effective implementationCustom security   effective implementation
Custom security effective implementationlog2srini
 
GRCSing2015_Kumar_Howtoperformasystem
GRCSing2015_Kumar_HowtoperformasystemGRCSing2015_Kumar_Howtoperformasystem
GRCSing2015_Kumar_HowtoperformasystemBarun Kumar
 
Effective Framework for Continuous Auditing
Effective Framework for Continuous AuditingEffective Framework for Continuous Auditing
Effective Framework for Continuous AuditingCaseWare IDEA
 
Fraud in the Non Profit Industry
Fraud in the Non Profit IndustryFraud in the Non Profit Industry
Fraud in the Non Profit IndustryRachelle_1
 
Thieves Within: Preventing Fraud in Small & Medium-Sized Organizations
Thieves Within: Preventing Fraud in Small & Medium-Sized OrganizationsThieves Within: Preventing Fraud in Small & Medium-Sized Organizations
Thieves Within: Preventing Fraud in Small & Medium-Sized OrganizationsAllen, Gibbs & Houlik, L.C.
 
Sox In Telecom Industry
Sox In Telecom IndustrySox In Telecom Industry
Sox In Telecom IndustryMahesh Panchal
 
Po report 5 - Role Conflict
Po report 5 - Role ConflictPo report 5 - Role Conflict
Po report 5 - Role ConflictSyaff Hk
 

Andere mochten auch (18)

Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
Automating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and FinancialsAutomating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and Financials
 
Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23
 
Segregation of Duties and Continuous Delivery
Segregation of Duties and Continuous DeliverySegregation of Duties and Continuous Delivery
Segregation of Duties and Continuous Delivery
 
3 Way Match for Purchasing Professionals
3 Way Match for Purchasing Professionals3 Way Match for Purchasing Professionals
3 Way Match for Purchasing Professionals
 
Sox Compliance Solution
Sox Compliance SolutionSox Compliance Solution
Sox Compliance Solution
 
Security & Segregation of Duties for PeopleSoft
Security & Segregation of Duties for PeopleSoftSecurity & Segregation of Duties for PeopleSoft
Security & Segregation of Duties for PeopleSoft
 
SAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM WorkflowsSAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM Workflows
 
SAP SECURITY GRC
SAP SECURITY GRCSAP SECURITY GRC
SAP SECURITY GRC
 
Sap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoftSap security compliance tools_PennonSoft
Sap security compliance tools_PennonSoft
 
Custom security effective implementation
Custom security   effective implementationCustom security   effective implementation
Custom security effective implementation
 
GRCSing2015_Kumar_Howtoperformasystem
GRCSing2015_Kumar_HowtoperformasystemGRCSing2015_Kumar_Howtoperformasystem
GRCSing2015_Kumar_Howtoperformasystem
 
Effective Framework for Continuous Auditing
Effective Framework for Continuous AuditingEffective Framework for Continuous Auditing
Effective Framework for Continuous Auditing
 
Fraud in the Non Profit Industry
Fraud in the Non Profit IndustryFraud in the Non Profit Industry
Fraud in the Non Profit Industry
 
Thieves Within: Preventing Fraud in Small & Medium-Sized Organizations
Thieves Within: Preventing Fraud in Small & Medium-Sized OrganizationsThieves Within: Preventing Fraud in Small & Medium-Sized Organizations
Thieves Within: Preventing Fraud in Small & Medium-Sized Organizations
 
Casa engl
Casa englCasa engl
Casa engl
 
Sox In Telecom Industry
Sox In Telecom IndustrySox In Telecom Industry
Sox In Telecom Industry
 
Po report 5 - Role Conflict
Po report 5 - Role ConflictPo report 5 - Role Conflict
Po report 5 - Role Conflict
 

Ähnlich wie Profiling for SAP - Compliance Management, Access Control and Segregation of Duties

Profiling for SAP - Analysis and redocumentation of SAP ERP
Profiling for SAP - Analysis and redocumentation of SAP ERPProfiling for SAP - Analysis and redocumentation of SAP ERP
Profiling for SAP - Analysis and redocumentation of SAP ERPTransWare AG
 
BI the Agile Way
BI the Agile WayBI the Agile Way
BI the Agile Waynvvrajesh
 
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...Mingxia Zhang, Ph.D.
 
Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Novell
 
Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Novell
 
SAP Netweaver BPM #SITANK 2011
SAP Netweaver BPM #SITANK 2011SAP Netweaver BPM #SITANK 2011
SAP Netweaver BPM #SITANK 2011Abdulbasit Gulsen
 
Improving SharePoint Business Process Maturity
Improving SharePoint Business Process MaturityImproving SharePoint Business Process Maturity
Improving SharePoint Business Process MaturityOpenText Global 360
 
PSI Corporate Profile
PSI Corporate ProfilePSI Corporate Profile
PSI Corporate Profilemike_vincent
 
Net@Work Client Presentation with Security
Net@Work Client Presentation with Security Net@Work Client Presentation with Security
Net@Work Client Presentation with Security Ray Glass
 
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1Anup Lakra
 
SAP Enterprise Modeling Applications (ARIS)
SAP Enterprise Modeling Applications (ARIS)SAP Enterprise Modeling Applications (ARIS)
SAP Enterprise Modeling Applications (ARIS)Palisade Corporation
 
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex Liviu Claudiu Cismaru
 
Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1frankkulendran
 
KTern.AI-RISE-with-SAP-Summit.pdf
KTern.AI-RISE-with-SAP-Summit.pdfKTern.AI-RISE-with-SAP-Summit.pdf
KTern.AI-RISE-with-SAP-Summit.pdfKTern.AI
 
CCS - Business Intelligence Capabilities
CCS - Business Intelligence CapabilitiesCCS - Business Intelligence Capabilities
CCS - Business Intelligence CapabilitiesCCS Global Tech
 
Overview, SAPExperts.com
Overview, SAPExperts.comOverview, SAPExperts.com
Overview, SAPExperts.comjsmall1976
 
Profile Resume 16031 Prashant Jain
Profile Resume 16031 Prashant JainProfile Resume 16031 Prashant Jain
Profile Resume 16031 Prashant JainPrashant Jain
 

Ähnlich wie Profiling for SAP - Compliance Management, Access Control and Segregation of Duties (20)

Profiling for SAP - Analysis and redocumentation of SAP ERP
Profiling for SAP - Analysis and redocumentation of SAP ERPProfiling for SAP - Analysis and redocumentation of SAP ERP
Profiling for SAP - Analysis and redocumentation of SAP ERP
 
BI the Agile Way
BI the Agile WayBI the Agile Way
BI the Agile Way
 
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...
TeleManagement Forum OSSera Case Study - AIS Thailand Service Manager Present...
 
Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...
 
Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...Implementing Process Controls and Risk Management with Novell Compliance Mana...
Implementing Process Controls and Risk Management with Novell Compliance Mana...
 
SAP Netweaver BPM #SITANK 2011
SAP Netweaver BPM #SITANK 2011SAP Netweaver BPM #SITANK 2011
SAP Netweaver BPM #SITANK 2011
 
Improving SharePoint Business Process Maturity
Improving SharePoint Business Process MaturityImproving SharePoint Business Process Maturity
Improving SharePoint Business Process Maturity
 
PSI Corporate Profile
PSI Corporate ProfilePSI Corporate Profile
PSI Corporate Profile
 
Net@Work Client Presentation with Security
Net@Work Client Presentation with Security Net@Work Client Presentation with Security
Net@Work Client Presentation with Security
 
Rootconf
RootconfRootconf
Rootconf
 
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 
SAP Enterprise Modeling Applications (ARIS)
SAP Enterprise Modeling Applications (ARIS)SAP Enterprise Modeling Applications (ARIS)
SAP Enterprise Modeling Applications (ARIS)
 
Globalnest company profile sap version2
Globalnest company profile sap version2Globalnest company profile sap version2
Globalnest company profile sap version2
 
Globalnest company profile sap
Globalnest company profile sapGlobalnest company profile sap
Globalnest company profile sap
 
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
BAM CEP / Business Activity Monitoring , Complex Event Processingomplex
 
Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1
 
KTern.AI-RISE-with-SAP-Summit.pdf
KTern.AI-RISE-with-SAP-Summit.pdfKTern.AI-RISE-with-SAP-Summit.pdf
KTern.AI-RISE-with-SAP-Summit.pdf
 
CCS - Business Intelligence Capabilities
CCS - Business Intelligence CapabilitiesCCS - Business Intelligence Capabilities
CCS - Business Intelligence Capabilities
 
Overview, SAPExperts.com
Overview, SAPExperts.comOverview, SAPExperts.com
Overview, SAPExperts.com
 
Profile Resume 16031 Prashant Jain
Profile Resume 16031 Prashant JainProfile Resume 16031 Prashant Jain
Profile Resume 16031 Prashant Jain
 

Mehr von TransWare AG

Automated application testing for the telecommunication industry using Framew...
Automated application testing for the telecommunication industry using Framew...Automated application testing for the telecommunication industry using Framew...
Automated application testing for the telecommunication industry using Framew...TransWare AG
 
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...TransWare AG
 
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud Server
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud ServerTM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud Server
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud ServerTransWare AG
 
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...TransWare AG
 
Webinar business process driven requirements and risk testing
Webinar business process driven requirements and risk testingWebinar business process driven requirements and risk testing
Webinar business process driven requirements and risk testingTransWare AG
 
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...TransWare AG
 
How to re-use existing system models to generate test cases
How to re-use existing system models to generate test casesHow to re-use existing system models to generate test cases
How to re-use existing system models to generate test casesTransWare AG
 
Model based testing for Integration and Regression Tests in ERP
Model based testing for Integration and Regression Tests in ERPModel based testing for Integration and Regression Tests in ERP
Model based testing for Integration and Regression Tests in ERPTransWare AG
 

Mehr von TransWare AG (8)

Automated application testing for the telecommunication industry using Framew...
Automated application testing for the telecommunication industry using Framew...Automated application testing for the telecommunication industry using Framew...
Automated application testing for the telecommunication industry using Framew...
 
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...
Katalon Studio integrated with modeling tools like Microsoft Visio, Sparx Sys...
 
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud Server
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud ServerTM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud Server
TM Forum Frameworx 17.5 togehter with Sparx Systems ProCloud Server
 
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...
Webinar [TransWare] TM Forum Frameworx 17.5 for Sparx Systems Enterprise Arch...
 
Webinar business process driven requirements and risk testing
Webinar business process driven requirements and risk testingWebinar business process driven requirements and risk testing
Webinar business process driven requirements and risk testing
 
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...
Availability of Frameworx 17.0 for Microsoft Visio, Sparx Enterprise Architec...
 
How to re-use existing system models to generate test cases
How to re-use existing system models to generate test casesHow to re-use existing system models to generate test cases
How to re-use existing system models to generate test cases
 
Model based testing for Integration and Regression Tests in ERP
Model based testing for Integration and Regression Tests in ERPModel based testing for Integration and Regression Tests in ERP
Model based testing for Integration and Regression Tests in ERP
 

Kürzlich hochgeladen

🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 

Kürzlich hochgeladen (20)

🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 

Profiling for SAP - Compliance Management, Access Control and Segregation of Duties

  • 1. Understand Control Improve Profiling for SAP® Compliance Management Access Control and Segregation of Duties Understand, Optimize and Control your Business and IT
  • 2. Subject Matter Profiling for SAP supporting Security Compliance for SAP® 1 Profiling for SAP® Application 2 Access Management and Segregation of Duties 3 Optimization of Authorizations 4 Project Support for SAP Blueprints SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  2 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 3. Profiling for SAP for Compliance and Access Control Understand “Profiling your SAP® Solution delivers our Clients all needed insights to understand, improve and control their Business and complex SAP® Landscapes.” Control Improve Heinz-Jürgen Scherer, CEO TransWare AG SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  3 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 4. Standard application with tight SAP® integration, high automation and flexible configuration PROFILING FOR SAP APPLICATION SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  4 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 5. SoD Analysis and the Process for Compliance 1. Extract 2. Define 3. Analyze Reports Profiler BI DB Analyzer Dashboards Predefined set of Risk Rules  Auditors, IT Security  Analytic reports and dashboards  Authorizations  Define Risk Rules  Conflicts and potential  Usage (Transactions,  Critical activity groups conflicts of Accounts Reports, RFC Calls)  Activities conflict matrix and/or Roles, Profiles SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  5 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 6. Profiling for SAP Product Components Profiling for SAP application customizing for SoD (configuration)  Definition of Task groups, specifies a set of tasks with identifiers  Assignments of critical transactions to task groups  Risk rules combining Task Groups with Financial Risk Values  Includes best practice for configuration settings Analytic Reports (examples)  Charts plotting risks and SoD issues per e.g. SAP module  Role Compliance Check: Identifies roles that have SoD conflicts based upon the underlying transactions  User Compliance Check: Identifies SoD conflicts in user’s profile SAP Solution Manager integration (optional) SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  6 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 7. Profiling for SAP® featuring SAP Compliance Management Technical, Functional and Processual Analysis and Optimization of SAP TransWare’s reengineering and optimization solution for SAP®, compliance and performance assessment and process analysis on any SAP® system or SAP® Industry Solution highlights process risks in a system review and will lead to minimized project times with corresponding cost reduction. The solution reveals the quality of the implementation by analyzing transaction logs, document types, user authorizations with roles and profiles, SAP® HR info types, SAP® customizing and object modifications and other configuration items. It shows the overall picture of customizing and utilization of the current SAP® system with business related KPIs. Complex ERP systems are potentially susceptible to segregation of duties (SoD) issues. By means of Profiling for SAP®, the desired responsibilities of SAP® users can be counterchecked against the real usage of SAP®. Reporting of the results can be done per job role, so you know what each role entails in terms of process activities, SAP® business blueprint process steps, SAP® roles and transactions. SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  7 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 8. Profiling for SAP® smartly supports the Transition Phase from As-Is into an optimized SAP® Landscape As-Is Landscape To-Be Transition Optimize Landscape Run SAP ASAP Run SAP Process IT Support Project Methodology Process IT Support Business Process Compliance Reengineering Management Management  Understand  Optimize  Control Access Control and Segregation of Duty Technical Functional Processual Analysis Analysis Analysis Profiling for SAP® SoD Compliance Profiling for SAP® SoD Compliance is based on the technical, functional and processual analysis tool components. SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  8 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 9. Introduction of an cost efficient compliance management ACCESS MANAGEMENT AND SEGREGATION OF DUTIES SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  9 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 10. Increased Focus on Security and Control  Corporate scandals and fraud (Enron, Barings Bank, WorldCom, ...)  Security breaches (UCs, BC, Stanford, ...)  Regulatory Compliance • Sarbanes-Oxley (SOX, EuroSOX) • Family Educational Rights and Privacy Act (FERPA) • Federal Information Security Management Act of 2002 (FISMA) • Gramm-Leach-Bliley Act (GLBA) • Health Insurance Portability and Accountability Act (HIPAA) • Joint Commission (TJC) SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  10 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 11. Security Risks, Security Compliance and Internal Controls Are there any Who has access  Access Control SoD violations? to sensitive transactions?  Do some users have too much access?  Sufficient access restrictions to private information?  Control for Segregation of Duties (SoD)  Every time a user is added ensure his rights are not in conflict with SoD risk rules  A user's profile is amended and the change must not cause any SoD conflict  Review of the company SoD requirements on a periodic base “Internal Controls are processes designed by management to provide reasonable assurance that the Institute will achieve its objectives.” (From MIT’s Guidelines For Financial Review and Control) SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  11 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 12. Profiling for SAP® and SAP® Authorizations Profiling for SAP combines information from different data sources like SAP usage, user authorization and SoD configuration with BI based reporting for a comprehensive security analysis. Actions are subject to authorization checks that are performed before the start of a program or table maintenance and mandatory for the SAP applications : · Starting SAP transactions (authorization object S_TCODE) · Starting reports (authorization object S_PROGRAM) · Calling RFC function modules (authorization object S_RFC) · Table maintenance with generic tools (authorization object S_TABU_DIS) SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  12 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 13. Profiling for SAP® Compliance Management A Software Solution for SAP Project and Compliance Process Support  Reduce time and efforts when providing ongoing information to internal and external auditors  Remove access or assign mitigating controls  Used during implementation of new SAP modules and processes or optimizing SAP systems  Monitoring transaction and data access based on SAP background job for 24/7 security and compliance control  Optionally runs on central SAP Solution Manager to manage complex SAP landscapes as a non-invasive solution  Web based BI solution based on a Business Warehouse for Compliance Management SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  13 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 14. Profiling for SAP® Compliance Application A solution for compliance management based on standard software Profiling is a configurable custom application with integration into SAP that ensures all user’s authorizations are compliant with the company’s compliance rules  Useful during all phases of the deployment lifecycle  Design – Identify roles, build composite roles based upon team requirements  Implementation – Test and verify SoD compliance of roles  Production – Ensure compliance of existing users and roles  Tight integration within SAP to manage complex SAP Landscapes and to leverage SAP standards  Applicable to SAP’s ERP, CRM, SCM and other ECC-based products  Web based product, non-invasive, non-deployment solution regarding SAP production systems SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  14 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 15. Set of Risk Rules based on SoD conflicts and critical actions Risk Rules Set  Set of Risk Rules for different business domains like FI-GL, MM, SAP Basis, CRM or etc. SoD Critical  Define SoD rules and critical actions Rule Actions and add standard or custom transactions to the rule set and  Define rules on Functional, Function Function Function Transactional or the most detailed Authorization-Object level  Define critical rules with high financial Transaction Transaction Transaction risks or potential security risks  Modify predefined configuration with a set of rules for SoD best practice Author.- Author.- Author.- Object Object Object SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  15 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 16. Procedure for the Definition of SoD Risk Rules on a Functional Level 1. Define SoD Functions (logical group of tasks) Define Functions  Example:  Function A: – Process Sales Order  Function B: – Maintain credits master data 2. Assign Transactions to SoD Function Assign  Example: Transactions  Function A – V-01, VA01, VA02, …  Function B – FD24, FD32, FD37, … 3. Define and Characterize the SoD Functions with Risk Rules Define Conflicts  Define a conflict: Function A & Group B and Risks  Characterize the conflict with financial risk indicators: • High, Medium, Low  Exclude Rules from predefined configuration as N/A for your organization with a description SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  16 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 17. Examples for SoD Activities and Transaction Groups Description of Task Groups SAP Transactions Group A: Process sales orders Create sales order V-01 Create sales order VA01 Change sales order VA02 Group B: Maintain credit master data Credit limit changes FD24 Change customer credit management FD32 Credit management mass change FD37 Credit management mass change F.34 Customers: Reset credit limit F.28 Credit Limit Data mass change S_ALR_87009999 Reset Credit Limit for Customers S_ALR_87012220 SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  17 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 18. SoD Conflict Matrix RISK Separated Function POTENTIAL RISK LEVEL Function (X, M, H) User can increase a customer Maintain credit Process sales credit limit and then process sales AND M master data orders orders for that customer leading to irrecoverable debt. Maintain User can create a fictitious Process sales contract/schedu AND contract and then create sales M orders ling agreement orders against that contract. User can create a fictitious Customer Process sales customer and create orders for master data AND M orders delivery to them thereby maintenance misappropriating goods. User can create/change sales Process sales Process outbound AND orders and deliveries to hide the H orders deliveries misappropriation of goods. User can create sales orders and Process sales Maintain sales maintain pricing, therefore over- AND M orders deal charging customers or giving then unauthorized discounts. SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  18 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 19. Critical Transactions and assigned Risks Transaction Description Risk FI12 Change House Banks/Bank Accounts Financial Risk PA30 Maintain HR Master Data Access HR data SCCL Local Client Copy System stability & integrity at risk SE11 Data Dictionary Maintenance System stability & integrity at risk PFCG Role Maintenance Security Risk SM49 Execute OS commands System stability at risk SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  19 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 20. Excel to define Risk-Rules for Business-Domains SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  20 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 21. Configuration of Rules SOD RULES SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  21 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 22. SoD Rules on Functional Level SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  22 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 23. SoD Conflict Matrix on Functional Level X=Financial Risk Exists, M = Medium Risk, H = High Risk SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  23 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 24. Critical Combinations on Functional Level with Details SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  24 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 25. SoD Rules and SAP® Authorizations SAP CONFIGURATION SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  25 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 26. Roles & Profiles with SoD Transactions included Shows Transactions used for SoD rules assigned to Authorization Objects Identify all Authorizations Objects with potential risks. SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  26 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 27. SoD Conflicts with Risks for specific Composite-Roles Also available for specific Single-Roles and Profiles SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  27 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 28. Standard or customized profiles and user assignment CUSTOMIZED RISKS IN SAP SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  28 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 29. Potential Risks with Accounts customized in SAP ALL = ‘*’ in Authorization 16 Conflicts for 21 Accounts At least one high financial risk in 485 conflicts for 3 user X=Financial Risk Exists, M = Medium Risk, H = High Risk SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  29 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 30. Actual Risks in Execution of SAP SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  30 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 31. SAP Objects, Usage and Authorizations SAP USAGE SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  31 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 32. SAP Modules, used Transactions and Authoritations SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  32 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 33. Accounts, Authorizations and Transaction Usage SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  33 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 34. …and many analytic Reports more SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  34 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 35. Benefits  Using the same kind of tools used by chartered accountants reduces service costs for external audit and advisory  Reduction of project efforts and establishment of SoD compliant authorizations from the start  Fully automated SoD analysis reduces TCO for the ongoing security control process  Auditors and IT security staff work on functional level even for complex authorization scenarios  Avoidance of manual analysis and false positive assessments  Flexible configuration includes custom “Z” transactions or external applications like Portals using BAPI or direct RFC calls  Easy identification of users with access to sensitive data by internal security teams lowers costs of the compliance process SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  35 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 36. Slimline authorization management of complex SAP® landscapes OPTIMIZATION OF AUTHORIZATIONS SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  36 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 37. Slimline your SAP® Authorization Management  Identify needless access rights by SAP Modules, Accounts, Transactions, …  Optimize your custom roles by identifying critical roles and access overlap  Setup segregation of duties by best practice and company compliance Assigned Role not relevant for execution Example Report: of the custom “Y” YXPROC transaction SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  37 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 38. Benefits  Efficient establishment of a tradeoff between Business Requirements and Company Compliance  Substantial reduction of project efforts in company compliance initiatives  Simplification of information access to complex SAP data for company auditors reduces costs for the compliance process  Uniformed use of tools by chartered accountants reduces external audit and advisory services costs  Allows the handling of complex SAP landscapes with automatic data retrieval and cross-SAP system analytics  Automatic monitoring of changes of user authorizations given by organizational requirements lowers costs for audits and security control SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  38 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 39. Being compliant from the beginning PROJECT SUPPORT FOR SAP BLUEPRINTS SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  39 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 40. Blueprinting with ASAP and SAP Solution Manager SAP® Solution Manager (SSM) is the SAP® tool that supports the plan, build and run aspects of ERP solutions based on SAP® NetWeaver and covers all needs for ITIL-compliant application lifecycle management (ALM). SAP® describes ALM by the Run SAP® operational support methodology and the Accelerate SAP® (ASAP) project methodology. SSM serves as an interface between technology and business processes. For SAP solution development like upgrades or implementations, the SAP solution is consistently documented in SSM by the Blueprint that describes the business processes and the resulting system configuration. An important part of the SAP solution development is the configuration of organizational structures and optimized business and security compliance requirements. Profiling for SAP® supports this aspect of SAP ALM to lower development and maintenance costs and improve process and compliance quality SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  40 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 41. SAP Blueprint Procedure for Compliant Authorizations Support ASAP methodology and SAP Solution Manager Projects Define  Define your functional Task Groups in SAP Solution Blueprint Manger as Jobs or Org.-Units as End-User-Roles  Setup the Blueprint Process Structure by Business Process Management Methodology including organizational assignments to End-User-Roles  Assign Transactions manually or use predefined Analyze Access Reference Models with T-Codes assigned like the SAP Requirements Business Process Repository (BPR )  Run Reports to analyze organizational Access Requirements  Automatically identify standard SAP right roles or Define Roles profiles supported and User Access  Customize Roles (PCFG) and assign users  Run analytic reports for SoD compliance and risk control SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  41 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 42. SAP Solution Manager for SAP Blueprints Optimized user authorizations from project start-up SAP Blueprint with Masterdata, Org.-Unit Data, Scenarios, Processes, Process-Steps, Transactions and Documentation Assign End-User- Roles to Process- Steps, Master-Data or Organizational-Unit Data Process-Steps with Assigned Transactions SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  42 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 43. SAP Solution Manager for SAP Blueprints Export the Blueprint structure for analytic reporting Cross-Reference between Objects (T-Code, Forms, Reports etc) and End-User-Roles SAP Blueprint Structure (SAP Project) Assigned User, Jobs, Org.-Units SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  43 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 44. Benefits  Support of SAP Solution Manager improves the SAP Blueprint business process definition in terms of Compliance and Risk Management  Synchronize organizational structures, functional access requirements, business processes and access control for slimline, fine tuned and fully SoD compliant SAP authorizations  Leverage SAP tools, methodologies and best practice by a tight SAP integration with a BI based solution that reduces SAP® project planning and implementation efforts  Reduce SAP maintenance efforts by a consistent business process and security control documentation  Ensure compliance through SAP improvements like ERP Enhancement Packages and organizational changes  Define authorizations on functional level and support setup of technical roles and profiles. SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  44 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies
  • 45. Solutions by TransWare TransWare Software Solutions AG Fritz-Wunderlich-Str. 49 66869 Kusel Germany Phone: +49-(0)6381-916-0 Email: info@transware.de Web: www.transware.de All product, service and company names mentioned herein are for identification purposes only and may be trademarks or registered trademarks of their respective owners SAP® Services Partner delivering expertise for SAP® Solution Manager and SAP Page  45 NetWeaver® technologies with ASAP, Run SAP and BPM methodologies