GRC Journal - (Page 37) Governance, Risk & Compliance The Breadth & Depth of Cross-Enterprise Solutions Cross-Functional A cross-enterprise GRC solution should cover all business processes in your organization. SAP GRC provides an unprecedented coverage of business processes with its SAP GRC solutions. Cross-Application SAP GRC Access Control delivers true multi-application readiness, allowing you to define risks, policies, functions, and controls once in one comprehensive GRC repository. This approach avoids fragmentation of risk analysis, enforces all policies, and avoids duplication of efforts because you do not have to recreate identical rules across application systems. Simplicity The cross-enterprise design and the holistic approach taken by SAP GRC Access Control provide an unprecedented level of simplicity while delivering depth and breadth of services. Because the applications cover an unrivaled number of processes and target enterprise application software, it does not matter where in the organization you are or what enterprise application software you work with since this unified approach covers SoD across the enterprise. SAP GRC Access Control addresses the basic need of proper access management, a fundamental requirement of a wide range of internal policies and external regulations. This end-to-end solution makes access and authorization risk management and compliant user provisioning an integral part of an enterprise’s business and IT strategies. Across applications and business units, SAP GRC Access Control extends the power of the largest rules library of SoD rules to every corner of an enterprise, to virtually every application, and to all of your critical business processes. The solution virtually eliminates the possibility of accidental or deliberate access violations through its preventive capabilities, real-time architecture, and comprehensive monitoring. By embedding compliance into business processes, SAP is making compliance repeatable, sustainable, and less costly for companies of all sizes in all industry segments. ENTERPRISE RULES When addressing access risk across enterprise application software, three primary goals must be met: • The access control application must have a large rules library that covers all business functions and defines all possible risks. It must cover the necessary level of detailed granularity to uncover all possible SoD violations, without reporting false positives. • The rules library must be a manageable set of rules that can easily be maintained and adjusted to meet changing business requirements. • To facilitate collaboration between business and IT, the definitions of the rules library must be easily accessible in commonly understood terms for business owners, but must also be able to directly translate into all technical aspects of the various target enterprise application software systems. Q1 2007 | www.btquarterly.com BTQ Business Trends Quarterly 71 http://www.btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.