<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: GRC Audit activities in Additional Q&amp;A</title>
    <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120224#M29999</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Majorly, the audit is to check how you have configured your GRC implementation for your organization.  Broadly, to name a few, it will cover areas like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1. The configuration that you have done and the mapping of your company processes in the same. &lt;/P&gt;&lt;P&gt; 2. Checking up that you have taken care of all the SODs and the fuctions are defined in such a way that there are no conflicts within a process in your organization.&lt;/P&gt;&lt;P&gt;3. Looking up for proper controls for Mitigation.&lt;/P&gt;&lt;P&gt;4. User Acess provisioning.&lt;/P&gt;&lt;P&gt;5. Risk mitigation and Alert monitoring should be properly defined and logs should show proper execution for the alerts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each of these and other such tasks can be drilled bown to any level as desired by the audit, to check the health and stability of your implementation against frauds and SOD violations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hersh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jul 2008 08:39:22 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-07-17T08:39:22Z</dc:date>
    <item>
      <title>GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaq-p/4120221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for the detailed activities that are involved in GRC Internal and External Audit ( SOX Audit ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any links or info. will be great. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Raj.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jul 2008 22:18:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaq-p/4120221</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-10T22:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120222#M29997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Raj,&lt;/P&gt;&lt;P&gt;Below given different people Roles and Responsibilities in SAP GRC implementation( Based on the given reference below).&lt;/P&gt;&lt;P&gt;1.	Client Project Manager u2013 responsible for coordinating communications, clarifying requirements and reviewing deliverables during the project&lt;/P&gt;&lt;P&gt;2.	Business Team -- personnel responsible for protecting the integrity of the information and processes supported by SAP.  BPOs are responsible for the following:&lt;/P&gt;&lt;P&gt;u2022	Identifying risk and/or approving controls for monitoring risks&lt;/P&gt;&lt;P&gt;u2022	Approving remediation to address user access issues in SAP&lt;/P&gt;&lt;P&gt;u2022	Designing alternative controls to mitigate Segregation of duty issues&lt;/P&gt;&lt;P&gt;u2022	Communicating access assignments or role changes&lt;/P&gt;&lt;P&gt;Provides documentation of desired workflow components (including Approvers, conditions for workflow and rejections for each type of AE request)&lt;/P&gt;&lt;P&gt;3.	Management Team -- approve or reject risks between business areas and approve mitigating controls for risks. &lt;/P&gt;&lt;P&gt;4.	Security -- owners of the SOD management process and associated software products who facilitate decision making as well as alternative methods to manage SOD risks. &lt;/P&gt;&lt;P&gt;5.	Business Process Analysts -- help security administrators define the technical rules for each business area for approved risk conditions and recommend alternatives to eliminate SOD risks in roles and user assignments.&lt;/P&gt;&lt;P&gt;6.	Auditors -- perform risk assessments on a regular basis to identify new risks, perform periodic testing of rules and mitigating controls, and act as a liaison with external auditors.&lt;/P&gt;&lt;P&gt;7.	Basis / DBA / Infrastructure - responsible for specifying the technical infrastructure components and selecting the systems to be included in the scope of the implementation.  Completing the sizing requirements, hardware procurement, downloading and installing software. &lt;/P&gt;&lt;P&gt;8.	CC Administrator u2013 Responsible for the configuration and loading of master data and documentation of processes for users of the capability&lt;/P&gt;&lt;P&gt;9.	AE Administrator u2013 Responsible for the configuration and loading of master data and documentation of processes for users of the capability&lt;/P&gt;&lt;P&gt;10.	FF Administrator - Responsible for the configuration and loading of master data and documentation of processes for users of the capability&lt;/P&gt;&lt;P&gt;11.	RE Administrator - Responsible for the configuration and loading of master data and documentation of processes for users of the capability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference: SAP_GRC_52_Roles_and_responsibilities.doc from SAP Best Practices for Governance, Risk and Compliance--&amp;gt;SAP GRC Access Control Accelerators.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himadama&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jul 2008 22:16:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120222#M29997</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-14T22:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120223#M29998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the Info. Hima.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for the audit activities list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2008 21:09:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120223#M29998</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-15T21:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120224#M29999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Majorly, the audit is to check how you have configured your GRC implementation for your organization.  Broadly, to name a few, it will cover areas like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1. The configuration that you have done and the mapping of your company processes in the same. &lt;/P&gt;&lt;P&gt; 2. Checking up that you have taken care of all the SODs and the fuctions are defined in such a way that there are no conflicts within a process in your organization.&lt;/P&gt;&lt;P&gt;3. Looking up for proper controls for Mitigation.&lt;/P&gt;&lt;P&gt;4. User Acess provisioning.&lt;/P&gt;&lt;P&gt;5. Risk mitigation and Alert monitoring should be properly defined and logs should show proper execution for the alerts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each of these and other such tasks can be drilled bown to any level as desired by the audit, to check the health and stability of your implementation against frauds and SOD violations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hersh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2008 08:39:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120224#M29999</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-17T08:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120225#M30000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hersh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The list of the things you mentioned are the features of the GRC tools. &lt;/P&gt;&lt;P&gt;I am looking for the complete audit checklist kind of information, if it is available( weblink ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Raj.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jul 2008 20:38:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120225#M30000</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-17T20:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120226#M30001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, in this case, dont have a list as such. Will revert back in case I get one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ciao!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 06:04:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120226#M30001</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-18T06:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120227#M30002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Want to close it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 20:25:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120227#M30002</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-23T20:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Audit activities</title>
      <link>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120228#M30003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your external auditor will have the audit checklistfor reviewing AC 5.x and AC 4.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2008 08:52:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/grc-audit-activities/qaa-p/4120228#M30003</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-29T08:52:37Z</dc:date>
    </item>
  </channel>
</rss>

