<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SOX in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180335#M999192</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,I´ll try to answer your questions.&lt;/P&gt;&lt;P&gt;The sox act is the same for all, but the aplication is diferent between diferent companies. You have to analize wich are the risks in your scenario, and which job roles have risks.&lt;/P&gt;&lt;P&gt;For doing this work you can use Compliance calibrator that is a part of GRC, in this utility you have Risk Terminator which will do an analisys of your risks based on "his own" matrix or in one made by you.&lt;/P&gt;&lt;P&gt;You need to determine wich are the risks in your companie, see which of the predefined risks do you nedd and do an analisis based on thar.&lt;/P&gt;&lt;P&gt;I hope this can help, is my first post so if you haven´t understand anything i´ll try to explain it better.&lt;/P&gt;&lt;P&gt;PS- Sorry for my english, i´m spanish and i´m learning english right now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Jul 2008 11:14:39 GMT</pubDate>
    <dc:creator>jose-manuelvo</dc:creator>
    <dc:date>2008-07-24T11:14:39Z</dc:date>
    <item>
      <title>SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180334#M999191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)   Do organizations follow different SOX act based on the companies work? And where and who implements the sox to the SAP system? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 2)  Based on SOX act are we creating SOD matrix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 22:53:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180334#M999191</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-23T22:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180335#M999192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,I´ll try to answer your questions.&lt;/P&gt;&lt;P&gt;The sox act is the same for all, but the aplication is diferent between diferent companies. You have to analize wich are the risks in your scenario, and which job roles have risks.&lt;/P&gt;&lt;P&gt;For doing this work you can use Compliance calibrator that is a part of GRC, in this utility you have Risk Terminator which will do an analisys of your risks based on "his own" matrix or in one made by you.&lt;/P&gt;&lt;P&gt;You need to determine wich are the risks in your companie, see which of the predefined risks do you nedd and do an analisis based on thar.&lt;/P&gt;&lt;P&gt;I hope this can help, is my first post so if you haven´t understand anything i´ll try to explain it better.&lt;/P&gt;&lt;P&gt;PS- Sorry for my english, i´m spanish and i´m learning english right now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2008 11:14:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180335#M999192</guid>
      <dc:creator>jose-manuelvo</dc:creator>
      <dc:date>2008-07-24T11:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180336#M999193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,  How exactly you predefine the risks and make SOD matrix? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is that we select SOX act(404,402 etc) based on the companies application?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2008 17:47:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180336#M999193</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-24T17:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180337#M999194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To devise the risks, you have to define conflicting actions and their corresponding permissions.  Then devise functions that contain 2 or more conflicting actions.  The devise risks which contain functions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you purchase the SAP GRC Compliance Calibrator, you are provided with a stardardized ruleset, which contains risks for almost every system...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ankur&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2008 22:22:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180337#M999194</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-24T22:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180338#M999195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Jose pointed out, SOX is same for all the companies. However, there are different components to carry out these SOX activities. For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Process Controls 2.5 :- Used for Autiding purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Access Contols 5.3 :-   It includes : Risk Analysis and Remediation, Compliant User Provision, Enterprise Role Management and Super User Privilege Management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for further information, kindly follow the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[SAP GRC Link|https://websmp205.sap-ag.de/~form/sapnet?_SHORTKEY=01100035870000691285&amp;amp;]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 05:26:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180338#M999195</guid>
      <dc:creator>former_member184114</dc:creator>
      <dc:date>2008-07-25T05:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180339#M999196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank u, But I dont have OSS user ID.Is there any way I can read the link content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 20:31:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180339#M999196</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-25T20:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: SOX</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180340#M999197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; thank u, But I dont have OSS user ID.Is there any way I can read the link content?&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin, am afraid that without an OSS user you may not be able to check out the Marketplace portal link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, you may search these on web, there is enough material available which will atleast give you a clear picture.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jul 2008 23:46:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sox/m-p/4180340#M999197</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-07-27T23:46:34Z</dc:date>
    </item>
  </channel>
</rss>

