<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Role Mapping in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482994#M837409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My company is implementing SAP and we have this huge issue about role mapping. Being the junior member of a 2-person Security team, I would really appreciate your responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Functional teams identifies the roles and tcodes. Security creates the roles. But who is responsible for mapping roles to users? We have this huge issue about who should be driving this activity. Our Security Consultant said that our team should be responsible for this. But the Change Management team also wants ownership and have actually started the process. Based on your experience who should be responsible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;JB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Mar 2008 07:41:56 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-03-05T07:41:56Z</dc:date>
    <item>
      <title>Role Mapping</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482994#M837409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My company is implementing SAP and we have this huge issue about role mapping. Being the junior member of a 2-person Security team, I would really appreciate your responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Functional teams identifies the roles and tcodes. Security creates the roles. But who is responsible for mapping roles to users? We have this huge issue about who should be driving this activity. Our Security Consultant said that our team should be responsible for this. But the Change Management team also wants ownership and have actually started the process. Based on your experience who should be responsible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;JB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 07:41:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482994#M837409</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-05T07:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Role Mapping</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482995#M837410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you should distinguish between 'responsible' as in 'who signs off' and 'who does the actual work'. &lt;/P&gt;&lt;P&gt;Maybe creating a [raci diagram|http://en.wikipedia.org/wiki/RACI_diagram] could provide some additional insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is definately not an easy one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 07:49:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482995#M837410</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-03-05T07:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Role Mapping</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482996#M837411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally Security team will create the Roles, and its test plans.&lt;/P&gt;&lt;P&gt;then finally assign to the endusers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if there is a integrated help desk, they will assign to the endusers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 08:01:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482996#M837411</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-05T08:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Role Mapping</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482997#M837412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The guys before are talking in solutions. The person responsible for the employee and the work he is doing is also responsible that he/she gets the authorization they need. It should not be so that the person that create roles can also connect them to the user. It is a possible fraud moment. In principle you have a function that create the user, an other that connects roles to the user and a function that create/maintain roles(authorizations). What you must do is avoiding the possibilities of fraud. Not every organization is ready for this, you see often a combination. Segregation of duties is the magic word.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have fun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;Jan van Roest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 08:30:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482997#M837412</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-05T08:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Role Mapping</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482998#M837413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&amp;gt;But who is responsible for mapping roles to users? We have this huge issue about who should be driving this activity. Our Security Consultant said that our team should be responsible for this. But the Change Management team also wants ownership and have actually started the process. Based on your experience who should be responsible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Change Management team should own the mapping of roles to users.  It is a business activity, not a technical one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security team is responsible for performing those assignments in SAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally user mapping causes more issues at go-live than any other area in security.  Usually the Change Management team will be in a better position to manage this business related function.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 20:47:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/role-mapping/m-p/3482998#M837413</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-03-05T20:47:07Z</dc:date>
    </item>
  </channel>
</rss>

