on 2021 Jun 06 7:30 AM
Hi All,
i have read numerous articles on GDPR compliance through GRC PC Controls, assessments and Policies. But could not find any which says about which assessment need to be applied.
My understanding is that Manual Control Performance can be used to certify if backend SAP systems have any violation in complying with GDPR.
And then ToE can be used to verify if the control passed or Failed.
please suggest if the above idea can fit GDPR check through SAP PC.
Also, please suggest if Risk Management and Automated monitoring can be used with configurable examples
Regards
Plaban
Request clarification before answering.
Hi Plaban,
GDPR a data privacy regulation and as a first step you have to first identify what personal data is processed in SAP and who has access to it? Once you have this information, the next steps are to assess the controls that are required (Access/Process) to comply with GDPR clauses. Few examples are below:
Regards,
Madhu
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Madhu,
Thanks for your reply.
Yes i am aware about the scoping. Eg. Personnel, Customer, Bank or Vendor Master data . But i am unaware of DPIA, i.e which type of Manual assessments can cater to DPIA. I believe MCP can. And if so, what are the next steps after MCP.
Can you suggest or suggest any reference/link on the controls for DPIA
Regards
Plaban
User | Count |
---|---|
6 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.