GRC Journal - (Page 35) Governance, Risk & Compliance For companies struggling to effectively meet their governance, compliance, and risk management requirements, SAP® GRC Access Control provides a comprehensive, cross-enterprise GRC solution that virtually shuts the door on access and authorization risks and SoD violations. Delivered with the largest and most comprehensive library of SoD rules that covers all of your business processes, SAP GRC Access Control eliminates existing risks and ensures the ongoing compliance integrity of your entire IT landscape through preventive controls and compliant user provisioning. With SAP GRC Access Control, you receive a rule set that has been developed and proven over ten years of successful implementations and backed by the deep process and industry expertise that only SAP can provide. From supply chain to core finance operations to production floor operations, SAP GRC Access Control delivers access risk management across your entire enterprise. It can even be extended to provide extensive support for legacy or custom applications. SAP GRC Access Control is available and supported worldwide in six languages. The unparalleled rules library built into SAP GRC Access Control covers virtually all business functions and processes within the enterprise. Most companies can start with the application with only a few changes and additions to the library to cover their particular business. Making changes to the rules library is a logical and intuitive process in which all business processes and relationships can be easily expressed in the library, bridging the gap between the business definition and the technical definitions. The cross-enterprise design and the holistic approach taken by the SAP GRC Access Control products provide an unprecedented level of simplicity while delivering depth and breadth of services. Only a comprehensive solution that covers the breadth and depth with a global solution can cover each and everyone in the organization and therefore simplify the way to compliance. A BETTER APPROACH TO MANAGING ACCESS AND AUTHORIZATION CONTROLS Companies spent at least $27bn on addressing tactical compliance issues in 2006 alone, yet they remain vulnerable to risks and burdened with high costs. SAP and its partners are stepping up to the challenge by helping companies take control of governance, risk, and compliance issues, and ultimately leveraging this capability as a competitive advantage. SAP will achieve this vision by delivering an integrated GRC foundation across a heterogenous system landscape for customers to adopt in a pragmatic approach, leveraging existing IT investments in SAP software and other technologies. In today’s highly regulated environment, companies are increasingly pressured by governance, risk, and compliance concerns, while at the same time needing to drive business performance, predictability, and stakeholder confidence. The current approach to managing GRC is marked by two sets of problems: 1) highly fragmented business processes and systems that compound the cost of managing risk and compliance; and 2) little or no investment in identifying and mapping out a phased approach to comprehensive GRC management. Underlying these issues is the inherent risk in strategically coordinating and managing a wide range of IT infrastructures that directly support the processes and systems in the GRC business environment. Organizations are deprived of a powerful tool for controlling and addressing risk effectively, while at the same time they are shifting investments and resources to non-revenue generating activities. SAP’s GRC solutions offer a holistic approach for addressing a broad range of cross-industry and industry-specific regulations. They include a comprehensive set of integrated applications, collectively called SAP GRC Access Control, that address a fundamental issue in many regulatory mandates. They simplify – and reduce the cost of ensuring – compliance with access and authorization control mandates such as the SoD or compliant user provisioning. These market-leading applications provide end-to-end automation for detecting, remediating, mitigating, and preventing access and authorization risk across the enterprise, resulting in lower costs, reduced risk, and better business performance. SAP GRC Access Control consists of: • Virsa Compliance Calibrator – supports 24/7 real-time compliance to detect, remove, and prevent access and authorization risk, and stops security and controls violations before they occur. Using live data to assess risk, it enables businesses to identify conflicts immediately, drill down into root causes, and achieve resolutions. • Virsa Access Enforcer – enables fully compliant provisioning throughout the employee lifecycle. As companies provision and de-provision access to enterprise systems, they often overlook how these changes can impact SoD requirements. Virsa Access Enforcer can automate provisioning, test for SoD issues, streamline approvals, all while reducing the workload for IT staff. • Virsa Role Expert – standardizes and centralizes role creation, eliminating manual errors and making it easier to enforce best practices. The application prevents SoD violations by performing a real-time simulation of the data in a production system and testing the entire SAP software landscape. • Virsa FireFighter – for SAP enables privileged access for regular users to perform emergency activities outside their role under a privileged but controlled and auditable environment. Q1 2007 | www.btquarterly.com BTQ Business Trends Quarterly 9 http://www.btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.