on 2008 Jul 10 11:18 PM
Hi All,
I am looking for the detailed activities that are involved in GRC Internal and External Audit ( SOX Audit ).
Any links or info. will be great.
Thanks in advance.
Rgds,
Raj.
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Raj,
Below given different people Roles and Responsibilities in SAP GRC implementation( Based on the given reference below).
1. Client Project Manager u2013 responsible for coordinating communications, clarifying requirements and reviewing deliverables during the project
2. Business Team -- personnel responsible for protecting the integrity of the information and processes supported by SAP. BPOs are responsible for the following:
u2022 Identifying risk and/or approving controls for monitoring risks
u2022 Approving remediation to address user access issues in SAP
u2022 Designing alternative controls to mitigate Segregation of duty issues
u2022 Communicating access assignments or role changes
Provides documentation of desired workflow components (including Approvers, conditions for workflow and rejections for each type of AE request)
3. Management Team -- approve or reject risks between business areas and approve mitigating controls for risks.
4. Security -- owners of the SOD management process and associated software products who facilitate decision making as well as alternative methods to manage SOD risks.
5. Business Process Analysts -- help security administrators define the technical rules for each business area for approved risk conditions and recommend alternatives to eliminate SOD risks in roles and user assignments.
6. Auditors -- perform risk assessments on a regular basis to identify new risks, perform periodic testing of rules and mitigating controls, and act as a liaison with external auditors.
7. Basis / DBA / Infrastructure - responsible for specifying the technical infrastructure components and selecting the systems to be included in the scope of the implementation. Completing the sizing requirements, hardware procurement, downloading and installing software.
8. CC Administrator u2013 Responsible for the configuration and loading of master data and documentation of processes for users of the capability
9. AE Administrator u2013 Responsible for the configuration and loading of master data and documentation of processes for users of the capability
10. FF Administrator - Responsible for the configuration and loading of master data and documentation of processes for users of the capability
11. RE Administrator - Responsible for the configuration and loading of master data and documentation of processes for users of the capability
Reference: SAP_GRC_52_Roles_and_responsibilities.doc from SAP Best Practices for Governance, Risk and Compliance-->SAP GRC Access Control Accelerators.
Thanks
Himadama
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.