GRC Journal - (Page 41) Governance, Risk & Compliance ExTENSIBILITY SAP GRC Access Control supports open interfaces that can be used to fully integrate in the application into your environment. The application supports interfaces that can be used to incorporate pre-existing content such as rules, roles, and so on. It also supports interfaces to other software components such as identity management solutions from other vendors. Import/Export interfaces SAP GRC Access Control provides a variety of interfaces to import or export pre-existing content such as risks, business functions, etc. You can import business functions, business processes, and risks into the SAP GRC Access Control application from a number of sources. WORKFLOW AND AUTOMATION The orchestration capabilities in SAP GRC Access Control focus on system-to-system communication, supporting compliance processes that depend on integrating diverse software via web services. Yet the ability to coordinate and automate work done in concert by software and by people can streamline more processes than just integration scenarios alone. The SAP GRC Access Control workflow engine is designed to meet this goal. SAP GRC Access Control delivers a single, robust workflow engine that can be used to guide human activity and enforce policies through automated and structured processes – or sequences of activities – across a wide range of business tasks including user access request, role approval, and risk mitigation. A company can customize workflows to reflect company requirements or policies. The embedded workflow engine delivers dynamic and configurable workflow solutions, routing tasks dynamically based on a number of decision criteria including requestor, business process, authorizations requested, etc. Administrators have full overview over all workflows in progress. For auditing, the workflow keeps a full audit log of all activities. For user provisioning, a provisioning log is available via Virsa Access Enforcer. MEETING COMPLIANCE REQUIREMENTS WITH SAP GRC ACCESS CONTROL SAP GRC Access Control delivers a well-rounded access and authorization solution that extends from design time to run-time and – due to its real-time architecture – does not leave any gaps for access risk violations in between. Whether used stand-alone or as a core component within the larger holistic SAP Solutions for GRC approach, SAP GRC Access Control ensures compliance with a wide range of internal policies and external regulations to address the basic need of proper access management. SAP’s holistic GRC offering presents an alternative to the fragmented GRC point solutions available in the market. SAP GRC Access Control makes access and authorization risk management and compliant user provisioning an integral part of any company’s business and IT strategies. By embedding compliance into business processes, SAP is making compliance repeatable, sustainable, and less costly for companies of all sizes in all industry segments. This end-to-end solution for governance, risk management, and compliance drives the value of a comprehensive GRC strategy for controlling and addressing future governance, risk, and compliance areas. The benefits from a comprehensive holistic GRC approach include: intelligent IT risk management; improved business performance and predictability, optimized risk/return portfolios; reduced GRC costs; business sustainability; business agility; and increased shareholder value. SAP has long recognized the growing role of enterprise systems in assisting companies to meet the increasing challenges of corporate compliance and risk management. Customers are looking for powerful compliance solutions that work across heterogeneous IT environments to reduce risk and cost as well as provide improved business control. SAP provides the most comprehensive set of applications for managing and preventing user access and authorization risk, enabling customers to comply with regulatory requirements and maintain high standards of governance and risk management, while minimizing cost and complexity. To learn more about how SAP can help your governance, risk management, and compliance initiatives, visit us at www.sap.com/grc. Q1 2007 | www.btquarterly.com BTQ Business Trends Quarterly 75 http://www.sap.com/grc http://www.btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.