<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Reports Tab - Mitigation Controls - GRC in Additional Q&amp;A</title>
    <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662498#M129419</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ameet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the details. I understand the functionality of Mitigation Controls, Reports and how alerts will be generated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how does I map a report to a risk ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally Risk is combination of Functions and Function is combination of actions and permissions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Report which we mention under reports tab while creating mitigation control what information does that provide to control monitor and this report is it linked to Action in the functions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When monitor executes them what details will be shown to them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~ Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 02 Nov 2014 10:42:56 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2014-11-02T10:42:56Z</dc:date>
    <item>
      <title>Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaq-p/10662496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear GRC Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need some details about Mitigation Controls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When creating Mitigation Controls, we will mention below details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Risk ID&lt;/P&gt;&lt;P&gt;Mitigation Monitor and Mitigation Approver details&lt;/P&gt;&lt;P&gt;Frequency&lt;/P&gt;&lt;P&gt;Reports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my knowledge under REPORTS tab we will maintain a report name which need to be executed by Mitigation monitor within the frequency set in the mitigation control.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If monitor doesn't run this report in specified frequency, we can schedule Alert generation job which sends alerts to the monitor about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Queries:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. On what basis these reports are derived? Are these reports, standard or customized reports? Can someone give me an easy example to understand the purpose of the Report maintained in REPORTS tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. When monitor executes theses reports what information is shown to them? On basis of that what is the understanding for the monitor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me to understand these details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~ Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Nov 2014 03:09:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaq-p/10662496</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-11-02T03:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662497#M129418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;H Madan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes youare right about the report tab usage.&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; background: transparent;"&gt;Mitigation monitor is sole responsible yo keep checking whether or not&amp;nbsp; the mitigation is being performed. This monitoring can be done either manually or by scheduling the alert generation&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-style: inherit; font-weight: inherit; background-color: transparent;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-size: 10pt; font-style: inherit; font-weight: inherit; background-color: transparent;"&gt;Reports which are maintained in reports tab of mitigating control, will trigger an e-mail to the Mitigation approver if control monitor does not run that report with in the frequency mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; background: transparent;"&gt;Alerts can be set through the program mentioned below by executing the Tcode&lt;STRONG style="font-style: inherit; font-size: 24px; font-family: inherit; background: transparent;"&gt; GRAC_ALERT_GENERATE.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; background: transparent;"&gt;&lt;STRONG style="font-style: inherit; font-size: 24px; font-family: inherit; background: transparent;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;You can refer to:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;&lt;A __default_attr="51292" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="Creation of Mitigation Controls in GRC 10.0" href="https://community.sap.com/" modifiedtitle="true" title="Creation of Mitigation Controls in GRC 10.0"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;And these reports are standard ones.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;Let us know for any more concerns.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;Regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background: #ffffff;"&gt;&lt;SPAN style="color: #333333; font-size: 22px;"&gt;Ameet &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Nov 2014 05:44:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662497#M129418</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-11-02T05:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662498#M129419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ameet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the details. I understand the functionality of Mitigation Controls, Reports and how alerts will be generated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how does I map a report to a risk ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally Risk is combination of Functions and Function is combination of actions and permissions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Report which we mention under reports tab while creating mitigation control what information does that provide to control monitor and this report is it linked to Action in the functions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When monitor executes them what details will be shown to them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~ Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Nov 2014 10:42:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662498#M129419</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-11-02T10:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662499#M129420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Madan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will give you details about the reports with one example of Mitigation control we are using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Access Controls is used as a documental tool for Mitigating Controls, rather than a implementing tool, i.e. you apply the control against the role/user, but the actual application of the control is performed outside of Access Control. This may be realized by running a custom SAP report to monitor the usage of the risky functions within the ECC system etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Action is for the t-code of the SAP Report. A brief explanation below will help in understanding&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;If you have a mitigation control that Mr. Z will run X report using Y t-code on a frequent basis of monthly or quarterly and reviews the report.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Then you need to give that Report name- X, in Action - Y T-code and frequency as Monthly/Quarterly. This helps for the system to check if the t-code has been executed or not in that frequency by the Monitor and generates an Alert [based on alert generation configuration]. If the monitor doesn't execute the action in backend in the set frequency, we will find an alert in Alert monitor- control monitoring, but if the monitor executes the action we will NOT get alert.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;EM&gt;The role of Monitor is to see whether everything that was risky from the access being mitigated is fine or not. That is, he/she would see to it that the user who has been given extra excess or conflicting access has not mis-used it. Every Mitigation control, for this purpose has a Monitor attached to it who does this job.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt;"&gt;Action &lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;- This is some tcode a monitor has to execute in backend to see that reports.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="list-style-type: upper-alpha;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;E.g. if someone is doing check payment entry(risk), and mitigation is done for a user/role, there must be a tcode where we can check what payments are made( sorry I am not well versed in FI Tcodes) , this tcode will be put in action tab and monitor will have to check it via that particular tcode.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG style="font-size: 9.0pt;"&gt;Frequency&lt;/STRONG&gt;&lt;SPAN style="font-size: 9.0pt;"&gt; is simply what the period you want to set within which a monitor must perform this activity - say one week or one month.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;If a monitor doesn’t execute that action/tcode within that time, an alert will be generated and mail will be triggered to mitigation approver (indicating that supposed task is not being performed).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;Example:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;We have a mitigation control defined for Risk " To check if a user has created a fictituous GL account and generated Journal activity via positing entries".&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;So, we are giving this access to some of the users by defining a control on top of it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;EM&gt;The role of Monitor is to see whether everything that was risky from the access being mitigated is fine or not. That is, he/she would see to it that the user who has been given extra excess or conflicting access has not mis-used it. Every Mitigation control, for this purpose has a Monitor attached to it who does this job.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;So, our monitor will run the report everyday using the report for G/L accounts change log Tcode as mentioned in the control.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;So, the Tcodes which we mention under ACTION field under reports tab actually depends on what are you trying to monitor if that access risk access is given to any user. This action which we mention can be standard ones or Customized reports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/576446" /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Let me know if you have more queries about this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Madhu.&lt;STRONG style="text-decoration: underline;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 07:15:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662499#M129420</guid>
      <dc:creator>madhusap</dc:creator>
      <dc:date>2014-11-03T07:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662500#M129421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Madhu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for detailed explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So shall I consider that "Reports" are not standard SAP reports alone which are maintained under mitigation control and these reports actually depend on the control objective of your mitigation control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I understood that maintaining REPORTS is optional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if maintain it is just for documenting and auditing purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if I have 100 mitigation controls, then may be I need to internally discuss with my Functional consultant and Business in understanding the objective of defining a control for that risk and if there is any standard report to monitor that risk or getting customized report created for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if my understanding is incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once&amp;nbsp; again thanks for detailed explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~ Madan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Nov 2014 10:27:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662500#M129421</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-11-03T10:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Reports Tab - Mitigation Controls - GRC</title>
      <link>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662501#M129422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Madan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with all the comments above, just a small addition;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trick is to have mitigating controls which are as effective as possible. Its about quality, not quantity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some questions which need to be asked when creating / assigning mitigating controls:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which control mitigates the risk better than others ? Is this control activity currently being performed ? Has this control been tested in the past by Internal Audit / External Audit ? Is this control due to mitigate a high / critical risk ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last thing you want, is to be over-controlled in some areas which are not considered a high and/or critical risk areas by the business.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2014 23:13:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/reports-tab-mitigation-controls-grc/qaa-p/10662501#M129422</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-11-12T23:13:29Z</dc:date>
    </item>
  </channel>
</rss>

