GRC Journal - (Page 36) SEGREGATION Of DuTIES AND COMPLIANT uSER PROVISIONING Access Risk Prevention and Mitigation with SAP GRC Access Control The Access Risk Analysis Process The fundamental principle of SoD is that the power to initiate, approve, and review activities is not held by the same person. Access risk analysis is the process of identifying potential SoD violations. When you run an access risk analysis or a simulation, you generate reports presenting different types of information. Collaboration between Business and IT SAP GRC Access Control delivers a collaborative approach to facilitate the communication of business owners, auditors, and chief information security officers to achieve proper application access control. A powerful yet elegant architecture not only ensures the reliable identification and mitigation of access risks across the enterprise, but it also enables organizations to be more efficient and gives business owners the transparency of and visibility into their user access and authorizations across the enterprise that allows them sign-off on SOX attestations with confidence. Cross-Enterprise Solution To promote transparency, GRC solutions must span business processes. For many, this also means that the GRC software applications must work with all of the enterprise applications used to support those business processes. The answer is to implement a single, holistic solution that provides true cross-enterprise GRC management. A GRC solution that delivers true cross-enterprise capabilities delivers key functionality across two dimensions: • Breadth in terms of business processes or functions covered • Depth in terms of integration with multiple business applications In cross-enterprise GRC, all applications that are part of the holistic GRC solution are cross-enterprise – meaning they address GRC issues across all applications and business functions – and feed to and from a single, centralized GRC data repository. These two characteristics of cross-enterprise GRC enable you to address a multitude of GRC challenges, providing the following benefits: • A holistic, cross-enterprise GRC solution addresses risk monitoring across all enterprise applications and business functions. A single, holistic solution significantly lowers the effort and cost of GRC for your company, freeing resources for innovation and top-line growth. • Executives gain greater transparency into business operations across the enterprise, which is essential to increasing overall GRC effectiveness. Transparency overcomes fragmentation which increases risks, reduces the effectiveness of controls, and causes strategic misalignment and missed opportunities. • You can automate processes that are currently manual, putting into place repeatable and auditable practices. • You can enjoy cost-effective reporting – a huge time and money saver – and be confident that the data you submit to regulatory agencies is reliable and supportable. • You can adjust to regulatory changes easily and speed compliance efforts, which can play a critical role in, for example, bringing new products to market faster than competition. 70 BTQ Business Trends Quarterly Q1 2007 | www.btquarterly.com http://www.btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.