<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP SYSTEM AUDIT in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218857#M1378763</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Julius' suggestions a basic audit scope would cover the following areas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- SAP security settings&lt;/P&gt;&lt;P&gt;- Application security design&lt;/P&gt;&lt;P&gt;- Security design for IT support services&lt;/P&gt;&lt;P&gt;- Segregation of duties&lt;/P&gt;&lt;P&gt;- User provisioning and administration processes&lt;/P&gt;&lt;P&gt;- Authorisation change management processes&lt;/P&gt;&lt;P&gt;- SAP development lifecycle and change management processes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Oct 2009 09:59:23 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-10-12T09:59:23Z</dc:date>
    <item>
      <title>SAP SYSTEM AUDIT</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218855#M1378761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good ady all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would really apprecite it if I could get some assistance with regards to the above.  we are preparing for a system audit from external auditors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know, How to prepare for an SAP audit: What do i  need to do to ensure a successful result. what tranaction codes to i need to ru. in other words what transactions will the auditors be running when they get here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Oct 2009 08:24:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218855#M1378761</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-12T08:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SYSTEM AUDIT</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218856#M1378762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh oh oh... you are in big trouble... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just joking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have no clue where to start and what you should have / could have been doing already (the auditors will lookmfor this...) then start transaction 'SECR'. It is obsolete, but will point you to the Audit Information System's role menus. You can then follow through them to cover the basic stuff which an auditor will look for as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Oct 2009 08:28:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218856#M1378762</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-12T08:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SYSTEM AUDIT</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218857#M1378763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Julius' suggestions a basic audit scope would cover the following areas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- SAP security settings&lt;/P&gt;&lt;P&gt;- Application security design&lt;/P&gt;&lt;P&gt;- Security design for IT support services&lt;/P&gt;&lt;P&gt;- Segregation of duties&lt;/P&gt;&lt;P&gt;- User provisioning and administration processes&lt;/P&gt;&lt;P&gt;- Authorisation change management processes&lt;/P&gt;&lt;P&gt;- SAP development lifecycle and change management processes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Oct 2009 09:59:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218857#M1378763</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-12T09:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SYSTEM AUDIT</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218858#M1378764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most auditors will use the holy trinity of SUIM, SA38 and SE16 to perform the majority of their tests.  The other guys have given you good info on what they will be looking for/how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way to pass an audit is to ensure that you have adequate controls embedded in your security implementation and related processes.  Your auditors will usually provide you a high level overview of what they are looking for if you ask them (lots of people forget to do this).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:22:02 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218858#M1378764</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-10-12T10:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: SAP SYSTEM AUDIT</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218859#M1378765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2010 07:34:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-system-audit/m-p/6218859#M1378765</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-02-16T07:34:15Z</dc:date>
    </item>
  </channel>
</rss>

