Guiding Principles for SAP access controls


The first level of SAP Access control is the transaction assigned to the roles. These transactions can be update, configuration and display / reports.  The Configuration transactions have to be properly secured and only present in limited number of roles

 

httpv://www.youtube.com/watch?v=XiPlObarL9Y

which achieves specific access control purposes reducing business SAP risks.  Object and field level security should be purposeful in minimizing true system risks.

SAP User Provisioning
SAP User Provisioning

SAP Basis and Support team security requirements are somewhat standard and largely focused on minimizing sensitive access controls. This is mainly focused toward the damage they can cause to the system

SAP Access Controls on the business process and securing the business data security requirements are client dependent and focused on achieving access control objectives.

The purpose and implementation strategy of all access controls should be documented.  The impact of access controls should be understood globally across the security model. This will ensure the reliability of access controls over time and reduce the risk of cross-pollination of SAP Authorization values between roles and combination of roles.

SAP Security should be built on small definable tasks executed by an end user. Many tasks make up a user’s job. For example small task based roles could be Vendor master Maintainer, Invoice Verification, Material master Creator etc

 

SAP Transaction codes should be rarely duplicated between roles – instead task roles should be reusable building blocks across the organizations with minimal maintenance requirements with each release.

Role assignments should be flexible and SOD remediation is simple with the granularity of task roles.

Role naming convention should be meaningful and intuitiveto both IT and business users. Role integrity and structure should be maintained with sound build principles.
[vc_row css=”.vc_custom_1512575306373{margin-top: 50px !important;}”][vc_column width=”1/3″][vc_cta h2=”Free Step by Step SAP License Optimization Guide” shape=”square” add_button=”bottom” btn_title=”click here” btn_style=”flat” btn_color=”default” btn_i_icon_fontawesome=”stm-diamond” btn_css_animation=”left-to-right” css_animation=”left-to-right” btn_add_icon=”true” css=”.vc_custom_1512579904776{padding-top: 50px !important;padding-right: 35px !important;padding-bottom: 50px !important;padding-left: 35px !important;background-color: #3a80f1 !important;}” btn_link=”url:http%3A%2F%2Fexpressgrc.com%2Ffree-sap-license-optimization-guide%2F||” el_class=”c_action”]SAP Customer is liable to pay 70 Million additional SAP licensing fees as a result of what is broadly known as Indirect Access.[/vc_cta][/vc_column][vc_column width=”1/3″][vc_cta h2=”Free SAP GRC 10.0 Step by Step Guide” shape=”square” add_button=”bottom” btn_title=”download here” btn_style=”flat” btn_color=”default” btn_i_icon_fontawesome=”stm-diamond” btn_css_animation=”left-to-right” css_animation=”bottom-to-top” btn_add_icon=”true” css=”.vc_custom_1512579856805{padding-top: 50px !important;padding-right: 35px !important;padding-bottom: 50px !important;padding-left: 35px !important;background-color: #f1b500 !important;}” btn_link=”url:http%3A%2F%2Fexpressgrc.com%2Fsap-grc-10-1-step-step-guide%2F||” el_class=”c_action”]Are you fed up with being not able to get job? Tired of being disappointed in yourself, because you just can’t seem to get started in the career as SAP  GRC Consultant?[/vc_cta][/vc_column][vc_column width=”1/3″][vc_cta h2=”Financial Loss due to Fraud Risk” shape=”square” add_button=”bottom” btn_title=”click here” btn_style=”flat” btn_color=”default” btn_i_icon_fontawesome=”stm-diamond” btn_css_animation=”left-to-right” css_animation=”right-to-left” btn_add_icon=”true” css=”.vc_custom_1512579731433{padding-top: 50px !important;padding-right: 35px !important;padding-bottom: 50px !important;padding-left: 35px !important;background-color: #1d9e3f !important;}” btn_link=”url:http%3A%2F%2Fexpressgrc.com%2Ffree-sap-process-control-step-step-guide%2F||” el_class=”c_action”]Using the right kind of SAP Controls in the right way can be trans formative for any SAP System[/vc_cta][/vc_column][/vc_row]

Recent Posts