Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP GRC project proposal

Former Member
0 Likes
2,561

Dear All,

I am trying to do a project proposal for my company and was wondering if any one of you could share your experience in writing such a document. Any examples would be greatly appreciated. Thanks.

Dear All,

I am trying to do a project proposal for my company and was wondering if any one of you could share your experience in writing such a document. Any examples would be greatly appreciated. Thanks.

9 REPLIES 9
Read only

former_member184114
Active Contributor
0 Likes
2,059

Hi Meng,

In GRC suite, you have different things. Can you tell me which one you are planning to implement?

Like GRC Access Control is one part which has RoleExpert, ComplianceCalibrator, AccessEnforcer and FireFighter

Regards,

Faisal

Read only

0 Likes
2,059

Hi Faisal,

thanks for the question. As a start, it will be Access Control.

Regards

Charles

Read only

0 Likes
2,059

Hi Meng,

Please look at your company requirement.which should, be implemented.

e.g if you have users asking tcodes every now and then , then you can give implement firefighter and give them FFID in case of emergencies.

hope this helps

Read only

0 Likes
2,059

Thanks for your input. Yes the FireFighter (Superuser Privilege Management) will be one of the submodules of Access Control which will be in scope inview of the effort required to do this activity manually.

Read only

Former Member
0 Likes
2,059

Hi Meng,

I think you need to clarify a few things here. Access Control is the name that SAP has given to the Virsa suite of products that they have rolled into the GRC suite. Regardless, the question is, where does the customer environment stand? Is it already compliant?

If no compliance related analysis has been done on the current environment, and you don't know that the environment is, in fact, SOD free, then implementing Compliance Calibrator first would make sense. Subsequently, Firefighter would come into play, and once the SOD issues have been properly addressed, then Access Enforcer and Role Expert can come into play.

I hope this gives you some ideas.

Thanks,

Santosh Krishnan

Read only

Former Member
0 Likes
2,059

This document [GRC Access Control - Access Risk Management Guide|https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/80c094de-90aa-2910-02b8-e31a6f5ff0c2] contains helpful advice when starting a segregation-of-duties GRC project.

Read only

0 Likes
2,059

Hi Alex,

yes, your link provides very useful information. It helps to give me an idea what to expect during the requirements planning phase meetings. But I think could also be used for implementation as well.

Thanks !

Read only

0 Likes
2,059

Alex

I am not able to access the GRC - Risk guide that you had set as a hyperlink.

Can you send this again. It will be beneficial for us.

Thanks

Kee

Read only

0 Likes
1,683

This link is not accessible can you please share the document or a new link?