Hi!
My question is a bit complex, is it possible for a company to create SoD risks without GRC tool?
I have an idea of how to have this, but I need help with ideas to automate this process and one north for starting this.
What comes to mind is to get a list of transactions that the functional/business area considers critical and define what cannot be with a single user, my point is how do I consolidate this by centralizing it in one place so that I can do simulations, for example of new access to a user and be able to identify if this can be assigned.
I know it sounds like an difficulty thing to do, but I want to at least try to have better risk control and be able to make improvements until the company acquires a GRC tool that does this type of work in an automated way.
Request clarification before answering.
Hi Caiogvn,
indeed that is difficult, that's why Access Governance tools for SAP have been developed 🙂
Nevertheless, you should be able to create a rough manual-intensive and error-prone tool extracting data about users and roles from an SAP system and using e.g. MS Excel.
But it requires a lot of work anyway.
Hope it helps and that your company can decide to adopt a GRC tool soon!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.