<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP authorization auditing in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500753#M1064916</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Koushal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP has a tool called GRC which can be used for SOD analysis and auditing.Earlier, it used to be known as VIRSA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, there are other tools ........also available in the market like APPROVA and so on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also take a look at Axis - Risk Management Software for SAP R/3 at the website &lt;A href="http://axxiominfo.com" target="test_blank"&gt;http://axxiominfo.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each one claims that they are better than others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Saby..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Sep 2008 11:20:16 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-09-30T11:20:16Z</dc:date>
    <item>
      <title>SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500748#M1064911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i wanted do SAP authorization auditing for a organization. they have already implemented SAP in there organization but there is proper procedure for it. I want to find out conflicting roles for all user and compare users roles with the standard roles which would be standard roles as per the roles matrix for them. &lt;/P&gt;&lt;P&gt;how could i find out all this data and how i should i proceed for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Koushal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 14:35:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500748#M1064911</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-29T14:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500749#M1064912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi koshal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked the auditing section of our "sticky" thread: &lt;SPAN __jive_macro_name="thread" id="791548"&gt;&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;In there are links to some nice discussions including this one: &lt;SPAN __jive_macro_name="thread" id="737045"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should get you started. The question you've asked today is very general and I do not expect anyone to deliver an answer that completely covers it. So please read along, expand your knowledge and feel free to come back with more specific questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jurjen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Sep 2008 15:36:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500749#M1064912</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-09-29T15:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500750#M1064913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Koushal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the following link [http://www.auditnet.org/docs/SAP_AP2.doc] which is a bit comprehensive but will definitely be of help to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Saby..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 09:15:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500750#M1064913</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-30T09:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500751#M1064914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanx for your reply Jurjen and saby.. i will check the links given by you ppl and try to follow it.&lt;/P&gt;&lt;P&gt; i want to know is there any tool for SAP auditing which could help to find conflicting roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Koushal Solanki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 10:35:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500751#M1064914</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-30T10:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500752#M1064915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;  i want to know is there any tool for SAP auditing which could help to find conflicting roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you've defined the conflicts have a look at (or search on) reports RSUSR008 and RSUSR009, or RSUSR008_009_NEW. Another usefull keyword may be GRC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 11:17:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500752#M1064915</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-09-30T11:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500753#M1064916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Koushal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP has a tool called GRC which can be used for SOD analysis and auditing.Earlier, it used to be known as VIRSA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, there are other tools ........also available in the market like APPROVA and so on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also take a look at Axis - Risk Management Software for SAP R/3 at the website &lt;A href="http://axxiominfo.com" target="test_blank"&gt;http://axxiominfo.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each one claims that they are better than others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Saby..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 11:20:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500753#M1064916</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-30T11:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500754#M1064917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i found that SAP also provide a tool called Audit Information System (AIS) for auditors. The SAP Audit Information System (AIS) provides a centralized repository for reports, queries, and views of data that have a control implication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Transaction code SECR is used to access the AIS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;koushal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 11:57:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500754#M1064917</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-30T11:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAP authorization auditing</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500755#M1064918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SECR is/was a menu as far as I know but that's been replaced in newer versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nowadays the menus and authorizations for audit tools are to be found in a set of standard SAP roles. &lt;/P&gt;&lt;P&gt;Look for roles with names like "SAP&lt;STRONG&gt;AUD&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll have a look for relevant notes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found:&lt;/P&gt;&lt;P&gt;Note 705197 - Audit Information System (AIS) 5.00 - Composite note&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should get you up to speed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Jurjen Heeck on Sep 30, 2008 2:16 PM Note added&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 12:13:37 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-authorization-auditing/m-p/4500755#M1064918</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-09-30T12:13:37Z</dc:date>
    </item>
  </channel>
</rss>

