SAP GRC Implementation Process
SAP GRC Implementation process Top-down approach, where it starts by defining security requirements up front during the blueprint phase. 1. Define SOD policies and Ruleset design The first step is to work with the business process owners (BPO’s), functional leads to identify the business processes and applications in-scope of the SAP project and finalizing the SoD policies and risk ratings (Critical, High, Medium, and low). Critical Risk represents significant impact to company operations. Risk cannot be mitigated, it requires remediation. Examples are Hight Risk represents financial risk and causes loss or theft. Risk may be mitigated with proper management level report or it may require remediation. Medium Risk represents medium profit and loss impact and disrupts an operational process. The risk can be mitigated with a management level report. Low risk can be mitigated The definitions vary from company to company. Once the SoD policies and risks are defined, SAP standard...