<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SoD Mitigation Controls design in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990826#M1803232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jose,&lt;/P&gt;&lt;P&gt;We are not live yet (SP12), but I have been running some of the standard reports in our test system, and both the Mitigation Control report and the Mitigated Objects report seem to be adequate and appear to report our mitigations accurately. What were your auditors looking for that is not included in those standard reports? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Gretchen &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 Jan 2014 21:10:46 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2014-01-31T21:10:46Z</dc:date>
    <item>
      <title>SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990825#M1803231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im responsible for the design of the Segregation of Duties matrix in our company, which I have already built the Matrix, and it has also been reviewed by our external Auditors.&lt;/P&gt;&lt;P&gt;the problem that Im facing at the moment is the reports to support the mitigation controls. We had a discussion with our internal IS developers and apparently the effort to build up such reports will be too much expensive, therefore I need to come up with some alternative.&lt;/P&gt;&lt;P&gt;My first thoughts were to redesign the mitigation controls, but again Im not very much familiar with the availiable reports in the ERP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there anyone there, that could give me some tips on mitigation controls that somehow use standard reports from SAP ? any suggestion is very much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SoD risk matrix covers all aeras, FICO, MM, PM, PS, CRM, SRM...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 09:27:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990825#M1803231</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-01-28T09:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990826#M1803232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jose,&lt;/P&gt;&lt;P&gt;We are not live yet (SP12), but I have been running some of the standard reports in our test system, and both the Mitigation Control report and the Mitigated Objects report seem to be adequate and appear to report our mitigations accurately. What were your auditors looking for that is not included in those standard reports? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Gretchen &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jan 2014 21:10:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990826#M1803232</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-01-31T21:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990827#M1803233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Gretchen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said Im not very much familiar with the Standard reports in ECC. I had a discussion with our External Auditors and they suggest to run some reports from the tables in ABAP, but the problem is that those reports are not much friendly, specially considering that the Business Manager would be then runing and checking it.&lt;/P&gt;&lt;P&gt;Would you be able to maybe provide me with a list of standard reports, so I can review it and check if it helps.&lt;/P&gt;&lt;P&gt;Appreciate it.&lt;/P&gt;&lt;P&gt;Thank you very much,&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Marcos &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 08:04:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990827#M1803233</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-03T08:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990828#M1803234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jose&lt;/P&gt;&lt;P&gt;Can you share what kind of reports are you looking from SRM perspective and would you be able to create a custom report by using "joins" to combine data from multiple tables &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 10:05:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990828#M1803234</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-03T10:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990829#M1803235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Marcos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need SAP GRC reports, or standard SAP ECC reports to be used for monitoring of mitigating controls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The easiest way to get standard report from SAP is just to go through report tree or get with description from TSTC table. From practical perspective we normally ask business to provide respective reports for each control.... not sure what input you exactly need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, Andrzej&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 10:10:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990829#M1803235</guid>
      <dc:creator>AndrzejP</dc:creator>
      <dc:date>2014-02-03T10:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990830#M1803236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jose,&lt;/P&gt;&lt;P&gt;You have lost me completely. I thought you were asking about reports in GRC; if you need to help with reports in ECC, this may not be the best forum for such discussions. GRC reports are right where you would expect them to be, on the Reports and Analytics tab.&lt;/P&gt;&lt;P&gt;Good luck,&lt;/P&gt;&lt;P&gt;Gretchen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 13:27:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990830#M1803236</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-03T13:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990831#M1803237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you everyone for your input and help.. I guess I confused you all with my question &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote jiveImage" src="https://community.sap.com/536/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I need reports that can support us to monitore the controls we have designed.&lt;/P&gt;&lt;P&gt;For example we have a SoD risk with Vendor master data maintenance and Posting vendor invoice. For this risk our control designed is to review the vendor master data change report and validate that all changes in the Bank account fields are correct.&lt;/P&gt;&lt;P&gt;Thank you anyway for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 13:36:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990831#M1803237</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-03T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990832#M1803238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;implement process controls (GRC PC) and give link mitigating controls report to the controls in PC, than ECC reports&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 13:44:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990832#M1803238</guid>
      <dc:creator>naveen_alluru</dc:creator>
      <dc:date>2014-02-03T13:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: SoD Mitigation Controls design</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990833#M1803239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jose,&lt;/P&gt;&lt;P&gt;Ahh, *now* your question makes sense. In my humble opionion, the business in this scenario is trying to dodge their responsibility. The business must own their mitigations. If they think that they can mitigate an SOD risk with a monitoring report, it is their responsibility to work with their functional experts to identify which report would be suitable. In my experience, GRC implementers are not expected to be experts in reporting in every ECC module; some of us have some functional experience in a module, but many do not. As Andrzej mentioned, many standard SAP reports are on report trees, and the functional experts from FI/CO, MM, etc, should know which ones could be used to monitor their processes. They would also know which custom reports were already created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;Gretchen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 14:05:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sod-mitigation-controls-design/m-p/9990833#M1803239</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-02-03T14:05:59Z</dc:date>
    </item>
  </channel>
</rss>

