<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Critical Actions in Additional Q&amp;A</title>
    <link>https://community.sap.com/t5/additional-q-a/critical-actions/qaa-p/6857856#M66875</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To cut down on the administrative burden of mitigating the users you could create a critical transaction role and assign the users you want to mitigate to this role and then assign the role to the mitigating control. This way you'll only be adding user to the SAP role to consider them mitigated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave wood&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 May 2010 16:15:56 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-05-11T16:15:56Z</dc:date>
    <item>
      <title>Critical Actions</title>
      <link>https://community.sap.com/t5/additional-q-a/critical-actions/qaq-p/6857854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to establish what is a good practice to follow on how to deal with critical actions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our thinking is that even though they are critical actions people will still need to have access to them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some options with the cons we have been considering: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Add the actions into Firefighter id's &amp;amp; roles. We don't necessarily want to add actions into a firefighter role that someone is expected to do during their daily/weekly/routine activities. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Disable the Critical Actions rules. This will disable your ability to easily identify when an unwanted user has access to these actions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Create mitigation controls for these critical actions and assign them to the specific users. This is quite and administrative  burden due to the number of critical actions. We would not want to mitigate at the Higher risk level but rather at the individual rule level. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are leaning towards option 3 but would appreciate some other options and input on how to deal with these? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 May 2010 06:27:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/critical-actions/qaq-p/6857854</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-05-10T06:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Actions</title>
      <link>https://community.sap.com/t5/additional-q-a/critical-actions/qaa-p/6857855#M66874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are going through the same process and are using a combination of your suggestions.  First we are going through the critical actions and determining if our company (business reps and auditors) agrees with SAP standards.  Some of the transactions we don't consider as being critical so those will be disabled.  Next, we will put some critical actions in our firefighter ID's and not allow an end-user to have them in production.  Then, we will mitigate the users who use some of the transactions regularly. And lastly, we will run the critical action notify job weekly or maybe even monthly.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peggy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 May 2010 13:12:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/critical-actions/qaa-p/6857855#M66874</guid>
      <dc:creator>Rich_Turnquist1</dc:creator>
      <dc:date>2010-05-11T13:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Actions</title>
      <link>https://community.sap.com/t5/additional-q-a/critical-actions/qaa-p/6857856#M66875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To cut down on the administrative burden of mitigating the users you could create a critical transaction role and assign the users you want to mitigate to this role and then assign the role to the mitigating control. This way you'll only be adding user to the SAP role to consider them mitigated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave wood&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 May 2010 16:15:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/additional-q-a/critical-actions/qaa-p/6857856#M66875</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-05-11T16:15:56Z</dc:date>
    </item>
  </channel>
</rss>

