Posts

Showing posts with the label SAP GRC AC

SAP GRC Implementation Process

  SAP GRC Implementation process Top-down approach, where it starts by defining security requirements up front during the blueprint phase. 1. Define SOD policies and Ruleset design The first step is to work with the business process owners (BPO’s), functional leads to identify the business processes and applications in-scope of the SAP project and finalizing the SoD policies and risk ratings (Critical, High, Medium, and low). Critical Risk represents significant impact to company operations. Risk cannot be mitigated, it requires remediation. Examples are Hight Risk represents financial risk and causes loss or theft. Risk may be mitigated with proper management level report or it may require remediation. Medium Risk represents medium profit and loss impact and disrupts an operational process. The risk can be mitigated with a management level report.  Low risk can be mitigated The definitions vary from company to company. Once the SoD policies and risks are defined, SAP standard...

SAP GRC Access Controls Questions and Answers

Image
 SAP GRC Access Controls Questions and Answers 1. What is SAP GRC? Governance, Risk and Compliance id the full form of GRC. It provides a solution that enables organizations to maintain regulations and compliance and remove any risks in maintaining organizations key operations. 2. How many modules present in GRC? a. Access Control (AC) b. Process Control (PC) c. Risk Management (RM) d. Environment, Health and Safety (EHS) e. Global Trade Services (GTS) 3. What is the software of GRC Financial compliance? GRCFND_A 4. What is the plugin used for HR backend? GRCPIERP – Used for HR function 5. What is the plugin used for NHR backend? GRCPINW – Used for Non-HR functions 6. What is the periodic process that allows role owner to remove roles from the users? UAR Review 7. Where can you define a mitigating control? a. Mitigating controls workset in Access Control b. Access Control risk analysis result screen c. Central process hierarchy in process control 8. What is the process of  imp...

SAP Security: Role Administration

Image
Role Administration Functions of the role administration is managing roles and managing authorization data. Transaction code PFCG (Profile Generator) is used for maintaining the roles, profiles and authorizations.  The roles are link between the user and authorizations. Basically the authorizations are stored in the system as objects. User menu is assigned to the users with the roles and it is displayed when the user logon the system. Roles contains transactions, reports and web based applications. With the role administration user can create roles and assign to users, change roles, delete roles, derive roles, compare roles and transport roles. In this blog i will be explaining about how to creating single roles in SAP using PFCG transaction code. Basic process of role administration: 1. Prepare a role matrix based on job description. Menu paths and transactions should be determined for each job position and determine the required authorizations like change, display, delete.  ...

SAP GRC Access Controls 12.0: Emergency Access Management (EAM)

Image
  SAP GRC Access Controls 12.0 Emergency Access Management (EAM) SAP GRC Access Control enables organizations to control access, prevent fraud and minimize the time and cost of compliance. The Emergency Access Management (EAM) is one of the module in GRC Access Control. It is implemented in the organizations for managing emergency access. With the EAM, user can request for the emergency access to systems and applications. Role owners/Business process owners can review and approve the emergency access. Security audit can be performed and logs can be monitored with the EAM module. Below are the IDs required for implementing the EAM a. Firefighter: User who require the emergency access b. Firefighter ID: User ID with the emergency/additional access c. Firefighter Owner: User ID responsible for Firefighter ID and assignment for Firefighters and Controllers. d. Firefighter Controller: User ID responsible for reviewing and approving the log files created from firefighting activities. ...