SAP grc

7,226 views

Published on

GRC

Published in: Education
1 Comment
1 Like
Statistics
Notes
  • Thank you sir,I recently came across your blog and have been reading along. nice explanationWe are providing online training on & for more info sap sd online training
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
No Downloads
Views
Total views
7,226
On SlideShare
0
From Embeds
0
Number of Embeds
21
Actions
Shares
0
Downloads
381
Comments
1
Likes
1
Embeds 0
No embeds

No notes for slide

SAP grc

  1. 1. Governance, Risk & Compliance SAP Live and Local Webcast Tour ‘08 5 June, 2008 [email_address]
  2. 2. Fragmentation Managing with confidence is difficult in an increasingly complex world Board of Directors Finance Legal Sales Contracts HR Controller IT Policy Mgmt. Audit & Compliance Treasury Australia U.S.A Japan U.K. France China Germany India Compliance Compliance Compliance Compliance Compliance Governance Compliance Risk Mgmt. Governance Risk Mgmt. Risk Mgmt. Governance Risk Mgmt. Risk Mgmt. Risk Mgmt. Governance Security Proj. Mgmt. Doc. Mgmt. Contracts Planning Customers ERP Production Billing ASX Principle 7 CLERP 9 Credit Risk Human Capital Risk Segregation of duties SOX ROHS WEEE Project Risk Compliance Risk Mgmt. Governance
  3. 3. Integrated GRC Forward looking organizations are seeking a unified approach to GRC Australia U.S. A. Japan U.K. France China Germany India Compliance Compliance Compliance Compliance Compliance Governance Compliance Risk Mgmt. Governance Risk Mgmt. Risk Mgmt. Governance Risk Mgmt. Risk Mgmt. Risk Mgmt. Governance Compliance Risk Mgmt. Governance Security Proj. Mgmt. Doc. Mgmt. Contracts Planning Customers ERP Production Billing Board of Directors Finance Legal Sales Contracts HR Controller IT Policy Mgmt. Audit & Compliance Treasury ASX Principle 7 CLERP 9 Credit Risk Human Capital Risk SOX ROHS WEEE Project Risk Segregation Of Duties
  4. 4. SAP Solutions for GRC A unified solution for GRC management <ul><li>Transparency to balanced global risk profile </li></ul><ul><li>Standardization on common GRC content and rules </li></ul><ul><li>Automates and embeds GRC into business processes </li></ul>Business Process Platform Cross-Industry GRC Risk Management Risk Management Business Applications Compliance & Controls Industry-Specific GRC GRC Repository Environment Access Control Global Trade Process Control Life Sciences High Tech Chemicals Oil & Gas Banking Business Process
  5. 5. SAP GRC Access Control Sustainable prevention of segregation of duties violations Cross-enterprise library of best practice segregation of duties rules Compliant User Provisioning Prevent SoD violations at run time Superuser Privilege Management Close #1 audit issue with temporary emergency access Periodic Access Review and Audit Focus on remaining challenges during recurring audits (Stay in Control) (Stay Clean) Risk analysis, remediation and prevention services Enterprise Role Management Enforce SoD compliance at design time Risk Identification and Remediation Rapid, cost-effective and comprehensive initial clean-up (Get Clean) Minimal Time To Compliance Continuous Access Management Effective Management Oversight and Audit
  6. 6. Risk Analysis, Remediation and Prevention Services Delivers 24/7, real-time compliance by stopping security and controls violations before they occur Alerts Framework Reporting Reporting Real-time Simulation Mitigation Management Remediation Management Critical Transaction Monitoring Real-time SoD Risk Analysis Cross-Application Integration Risk Identification Elimination Prevention Mandatory Prevention Access Risks Services Cross-Enterprise Rules Architect Cross-Enterprise Rules Database Rules Access Risks Library <ul><li>Common services across all SAP GRC Access Control capabilities </li></ul>“ SAP GRC Access Control, with its comprehensive preconfigured rule set, reflected deep expertise within SAP that would have taken us a very long time to replicate.” Synopsys Inc.
  7. 7. Risk Analysis and Remediation Getting clean Reporting Risk Elimination Risk Identification Prevention End-to-End Automation Initial Risk Analysis and Remediation <ul><li>Facilitates collaboration between Business and IT to clean up access risks </li></ul>“ The clean-up process has brought a tremendous degree of discipline to the way we think about and manage user access and authorizations.” Synopsys Inc.
  8. 8. Enterprise Role Definition Enables enterprise role definition and maintenance in a single location Centralized Role Management Across applications Enterprise Rules Audit log SAP GRC Access Control <ul><li>Reduce cost of role maintenance </li></ul><ul><li>Ease compliance and avoid authorization risk </li></ul><ul><li>Eliminate errors and enforce best practices </li></ul><ul><li>Assure audit-ready traceability and security checks </li></ul>28% time savings in role management Customer Survey, 3/2006 Compliant enterprise roles Role … Role Role Role Role Role Role Role Role Role
  9. 9. SAP GRC Access Control Superuser Access Management Key Functionality Alert Framework Date Restrictions ID Administration Audit Logs Security Notification Reporting Reporting The only compliance-focused emergency access solution Compliant Superuser Access Privileged Access Firecall ID SD Firecall ID MM Firecall ID FICO Firecall ID . . . New Session New Session New Session New Session Superuser <ul><li>Pre-assigned firecall IDs </li></ul><ul><li>Access restrictions </li></ul><ul><li>Validity dates </li></ul><ul><li>Field-level changes tracked in audit log </li></ul>Log-in Restrictions Single User per ID Specific Authorization Access Log Log Log Log
  10. 10. SAP GRC Access Control Compliant Provisioning Enables Compliant End-to-End Provisioning “ hire to retire” Current Approach—Inefficient, Not Compliant email email spreadsheets, paper forms spreadsheets, paper forms Access Request Manager Approval Role Owner IT Security Manual Provisioning
  11. 11. GRC Access Control Compliant Provisioning Compliant Provisioning with Dynamic Workflow Path Workflow—based on request type and user attributes Escalation Workflow Exception Workflow 100% Automated HR Event Employee Hired/Retired Via e-mail 1 “Click” Preventive Simulation 100% Automated <ul><li>Embed cross-enterprise preventive compliance into business process </li></ul><ul><li>Reduce cost of user administration </li></ul><ul><li>Improve productivity of end users </li></ul><ul><li>Auditable tracking for auditors </li></ul>“ We reduced provisioning from 2 weeks to 2 days” – Web Seminar Rockwell Collins, 3/2005 Request Generated Automated Provisioning Mgr Approval Risk Analysis … … …
  12. 12. <ul><li>Key Solution Capabilities and Benefits </li></ul><ul><ul><li>Identifies and prevents access and authorization risks in cross-enterprise IT systems to prevent fraud and reduce the cost of continuous compliance and control </li></ul></ul><ul><ul><li>Provides end-to-end automation for detecting, remediating, mitigating, and preventing access and authorisation risk across the enterprise </li></ul></ul><ul><ul><li>Allows for true cross-enterprise SoD risk mitigation by integrating into SAP and non-SAP systems </li></ul></ul><ul><li>Common Customer Challenges Addressed </li></ul><ul><ul><li>Need to comply with SOX regulations for section 404, or similar regulations </li></ul></ul><ul><ul><li>Weak support for the audit process to ensure the right measures are in place to prevent fraud </li></ul></ul><ul><ul><li>Manual or people-intensive compliance processes involving emails, spreadsheets and/or paper </li></ul></ul><ul><ul><li>Costly, manual remediation </li></ul></ul><ul><ul><li>Uncontrolled role management </li></ul></ul><ul><ul><li>Excessive super-user access </li></ul></ul><ul><ul><li>Inefficient and un-auditable user provisioning </li></ul></ul><ul><ul><li>Reactive vs. preventative </li></ul></ul><ul><li>Value Proposition </li></ul><ul><ul><li>Establish approach and process to manage risk rules </li></ul></ul><ul><ul><li>Gain alerts on potential violations </li></ul></ul><ul><ul><li>Identify business functions which produces risks when executed by same individual </li></ul></ul><ul><ul><li>Focus on prevention vs. “a point in time” detection </li></ul></ul><ul><ul><li>Simplify compliant enterprise level role administration </li></ul></ul><ul><ul><li>Enforce compliant security for Privileged Access </li></ul></ul><ul><ul><li>Increase visibility through timely notification </li></ul></ul><ul><ul><li>Deliver audit ready, detailed reporting </li></ul></ul><ul><ul><li>Lower risk and save money through proactive compliance </li></ul></ul>GRC Access Controls
  13. 13. Our offer to you <ul><li>The Two Faces of Risk: </li></ul><ul><li>Cultivating Risk Intelligence for Competitive Advantage </li></ul><ul><li>Deloitte Review </li></ul>
  14. 14. Questions?
  15. 15. Thank you [email_address]

×