Case Study of a Segregation of Duties Project
|
|
|
- Katherine Scott
- 9 years ago
- Views:
Transcription
1 Case Study of a Segregation of Duties Project Applies to: SAP Security, SAP GRC Access Control Suite For more information, visit the Security homepage. Summary As Companies today are struggling to meet the Compliancy and regulatory requirements of their SAP Systems, Segregation of Duties plays a key role in the SAP Security design and implementation. Segregation of Duties means that no single user will have the authorizations to all key steps in a business process. This article will explain some of the important details that need to be understood while implementing the SoD project in a typical SAP landscape. Author: Kiran Kandepalli Company: Intelligroup Inc Created on: 13 October 2008 Author Bio Kiran Kandepalli is working with Intelligroup Inc as a Principal Consultant in SAP Security/SAP GRC related projects in USA SAP AG 1
2 Table of Contents 1. Introduction Segregation of Duties Concept Incompatible Job Functions What is an SOD Risk? Implementation Details of an SoD Project Creation of an SoD rule set Functions SoD Conflicts Critical Transactions Critical Authorizations Critical Roles Critical Profiles SoD Conflict Analysis Role Level Analysis User Level Analysis Remediaton of SoD Conflicts Mitigation of SoD Conflicts Segregation of Duties for Background Users...7 Related Content...8 Disclaimer and Liability Notice SAP AG 2
3 1. Introduction Segregation of Duties (SoD) has become an important prerequisite in the implementation of every compliance related project all over the world. As the name suggests that no single user can have access to all authorizations of a process end to end. It is required that job duties in each business process are completely segregated and adequate controls need to be placed. The role of a SAP Security consultant is vital in the design of SAP Security Roles and Authorizations and appropriate SoD remediation and Mitigation Controls are put in place. 2. Segregation of Duties Concept The underlying concept of Segregation of Duties is that no one person should have excessive control over one or more critical business processes. When dealing with Access controls for example, a person should not be able to grant himself/herself rights and then perform the action. Similarly, they should not be able to perform a transaction and then delete all the logs that tracked the activity. Instead, processes should be properly reviewed and separated in order to reduce the risks associated with a process being compromised either maliciously or through human error. Understanding and applying SOD controls are vital to information security. Segregation of duties issues come up frequently in security reviews and audits. Rather than being viewed as arcane control concepts, SOD controls should be recognized as additional means to help manage risks. Like all controls, there will be limits to what organizations can do. To help address concerns, a review can be undertaken to properly align roles with business needs while properly addressing the risks associated with improper segregation of duties. 2.1 Incompatible Job Functions To maintain proper Segregation of Duties, no employee should be responsible for two or more of the following four functions for a single transaction class: Record Keeping Creating and maintaining departmental records Asset Custody Access to and/or control of physical assets Authorization Reviewing and approving transactions Reconciliation Assurance that transactions are proper 2008 SAP AG 3
4 2.2 What is an SOD Risk? Segregation-of-Duties risks are opportunities for one individual to control a process from beginning to end without the involvement of others. When an individual exploits the condition, data integrity, productivity loss, and physical losses can result without being detected. For example, one person may be able to set up a vendor and process payments SOD RISK Access to both FB60 (Enter Vendor Invoice) and F-07 (Post Payments) transactions 3. Implementation Details of an SoD Project The following activities are performed during the implementation of SoD Project. 3.1 Creation of an SoD rule set Every company needs to follow compliancy procedures and regulations in accordance with SOX act and FDA rules. There will be a set of predefined Process Control and Access Control rule sets that come with the SoD tool like SAP GRC that can be used. Company Internal Auditors and SoD team will identify Custom rule sets if needed. The following entities comprise a SoD Rule set Functions A common group of SAP Transaction codes and Authorization objects that fulfill a particular Business Process is termed as a Function. Each of these Functions is very critical for the Business. Create a four character Function ID for each of the Critical Business Processes. For example: The function Process Goods Receipt (PO01) contains the following common transactions: MB01 Post Goods Receipt for PO MB02 Change Material Document MB0A Post GR for PO MB1C Other Goods Receipt MB31 Goods Receipt for Production Order MIGO Goods Movement MIGO_TR Transfer Posting COGI Process Goods Movement w. Errors The function Create and Maintain Purchase Order (PO02) contains the following Common transactions ME21 Create Purchase Order ME22 Change Purchase Order ME25 Create PO with Source Determination ME27 Create Stock Transport Order ME59 Automatic Generation of PO 2008 SAP AG 4
5 3.1.2 SoD Conflicts When two or more critical business functions are combined then it is identified as an SoD Conflict. Create a four character SoD Conflict ID for each of the conflicting business processes. For example: When the above two functions Process Goods receipts (PO01) and Create and Maintain Purchase Orders (PO02) are combined and assigned to a single user, it becomes an SoD Conflict. For example: The SoD Conflict P001 = PO01 + PO Critical Transactions All the important transactions that are critical to each business process need to be listed and documented. Access to these critical transactions is given only with appropriate approval mechanism. Whenever these transactions are executed by the users they can be logged and proper audit trail is maintained. For example: SE38, SA38, SE Critical Authorizations All specific sensitive authorization objects need to be listed and documented. These need to be monitored and logged too. For example: S_TABU_DIS, S_TABU_CLI Critical Roles All the Critical Roles which are considered sensitive must be listed and documented. Whenever there is a request for access to these critical roles, it needs to be documented for Audit purposes. For example: A Role with ABAP Debug Authorizations Critical Profiles All the Critical Profiles that are deemed sensitive must be listed and documented. For example: SAP_ALL, SAP_NEW. 3.2 SoD Conflict Analysis This is a very important step in the SoD Project. The SoD Conflict Analysis must be conducted in a two step iterative approach on all the Roles and Users existing in the SAP System. If there is an SoD tool like SAP GRC already in place then the results will be much quicker and the job can be scheduled on a daily basis to perform SoD analysis on all new roles and users. Manual identification of SoD conflicts is often very time consuming SAP AG 5
6 3.2.1 Role Level Analysis All the Security roles comprising of Single, Derived, Composite Roles need to be checked for any Inherent SoD Conflicts. If the Roles contain any conflicting transactions and authorization objects, then those roles need to be documented for further action User Level Analysis All the Dialog and Non-Dialog users need to be checked for any SoD Conflicts due to the assignment of any Conflicting Roles and Critical Profiles. These Users need to be documented for any further action. 3.3 Remediaton of SoD Conflicts After the analysis of the SoD conflicts are performed at both the Role level and User level, it is very effective to do the remediation of SoD Conflicts at the Role level first as it will remove the Conflicts of all Users that are assigned to each of these roles. For example: If one conflict is removed from a single role that is assigned to 25 users then, almost all of the 25 conflicts are gone. Even after performing the remediation of SoD Conflicts at the Role level, there will be SoD Conflicts at User level. Each of those conflicts need to be analyzed properly and discussed with the appropriate Business Process Owners and User Managers for every action of remediation. Any modification of Roles and authorizations as a result of this process need to be done in Development system and the modified roles and profiles need to be transported to QA for testing and after all successful testing they need to be transported into Production system. It is advisable that the testing has to be perfomed by the End Users themselves in QA and not by the Basis/Security team so that all the Authorizations are tested well. 3.4 Mitigation of SoD Conflicts There are times where the Business requires that the User have roles that contain functions that are conflicting in nature. If there is no way to remediate the SoD Conflicts for that particular user as business demands the authorizations to be in place, Mitigation of SoD Conflicts is only alternative. Any Mitigation Control needs to be documented and appropriate approval needs to be taken from that particular Business Process Owner before granting the authorizations to the Users. The Mitigation Control is identified with a four character ID. For example: If the Business demands due to lack of Buyers that a particular user be given authorization to create a Purchase Order and then Approve the Purchase Orders upto $25000, then a Mitigating Control M001 is placed on that User SAP AG 6
7 3.5 Segregation of Duties for Background Users It is often debated whether the SoD Conflicts need to be applied to Background Users. But the fact is that the whole SAP system needs to be compliant including all Dialog and Non Dialog Users. It becomes very difficult and stands as a challenge to the IT team members when asked to follow compliancy standards, rules and regulations for Non-Dialog users like Background Users. The following steps need to be taken to ensure that the Background users are free of any SoD Conflicts. Critical SAP Profiles like SAP_ALL and SAP_NEW must be deleted from the Background user ids and it will minus most of the SoD Conflicts. All the business jobs that will be run under this background id must be documented. New Security Role must be created and authorizations must be tailored to suit the requirements of the background jobs run by the Background user id. If complete remediation of SoD Conflicts is not possible, as sometimes is the case, then appropriate Mitigation Controls need to be framed and documented SAP AG 7
8 Related Content help.sap.com For more information, visit the Security homepage SAP AG 8
9 Disclaimer and Liability Notice This document may discuss sample coding or other information that does not include SAP official interfaces and therefore is not supported by SAP. Changes made based on this information are not supported and can be overwritten during an upgrade. SAP will not be held liable for any damages caused by using or misusing the information, code or methods suggested in this document, and anyone using these methods does so at his/her own risk. SAP offers no guarantees and assumes no responsibility or liability of any type with respect to the content of this technical article or code sample, including any liability resulting from incompatibility between the content within this document and the materials and services offered by SAP. You agree that you will not hold, or seek to hold, SAP responsible or liable with respect to the content of this document SAP AG 9
Restricting Search Operators in any Search View
Restricting Search Operators in any Search View Applies to SAP CRM 2007 and SAP CRM 7.0. For more information, visit the Customer Relationship Management homepage. Summary The purpose of this article is
Step by Step Guide for Language Translation Tool
Step by Step Guide for Language Translation Tool Applies to: SAP ECC 6.0 Summary This document helps people to understand the steps involved in translation of standard SAP screen and also helps to change
How to Assign Transport Request for Language Translation?
How to Assign Transport Request for Language Translation? Applies to: SAP ECC 6.0. For more information, visit the ABAP homepage. Summary This document helps people to create a transport request for the
Reverse Transport Mechanism in SAP BI
Reverse Transport Mechanism in SAP BI Applies to: SAP Net Weaver 2004s BI 7.0 Ehp1 SP 08. For more information, visit the EDW homepage Summary This document helps you to understand the detailed step by
ALE Settings, for Communication between a BW System and an SAP System
ALE Settings, for Communication between a BW System and an SAP System Applies to: SAP ECC 6.0. For more details, visit the EDW homepage. Summary This document helps people to create ALE settings, which
Step by Step Guide How to Copy Flat File from Other Application Server to BI and Load through Info Package
Step by Step Guide How to Copy Flat File from Other Application Server to BI and Load through Info Package Applies to: SAP BW 7.x. For more information, visit the EDW Homepage. Summary The objective of
Automating Invoice Processing in SAP Accounts Payable
Automating Invoice Processing in SAP Accounts Payable Applies to: SAP 4.6C, SAP 4.7 Enterprise, mysap ERP 2004, mysap ERP 2004 Summary Paying to the vendor who supplies good or provides services is the
Standard SAP Configuration of SMS through HTTP with Third Party SMS Gateway
Standard SAP Configuration of SMS through HTTP with Third Party SMS Gateway Applies to: SAP R/3 4.7 EE SR 200,ECC 5.0 For more information, visit the Web Services homepage. Summary There is an increasing
SAP FI - Automatic Payment Program (Configuration and Run)
SAP FI - Automatic Payment Program (Configuration and Run) Applies to: SAP ECC 6.0. For more information, visit the Financial Excellence homepage. Summary This document helps you to configure and run Automatic
SAP CRM 2007 - Campaign Automation
SAP CRM 2007 - Campaign Automation Applies to: SAP CRM 7.0 For more information, visit the Customer Relationship Management homepage Summary Campaign Automation is designed to help you in the increasingly
Creating Email Content Using SO10 Objects and Text Symbols
Creating Email Content Using SO10 Objects and Text Symbols Applies to: SAP ECC 6.0. For more information, visit the ABAP homepage. Summary The article describes the benefits of SO10 objects in comparison
How to Modify, Create and Delete Table Entries from SE16
How to Modify, Create and Delete Table Entries from SE16 Applies to This article applies to all SAP ABAP based products; however the examples and screen shots are derived from ECC 6.0 system. For more
Working with SAP BI 7.0 Data Transfer Process (DTP)
Working with SAP BI 7.0 Data Transfer Process (DTP) Applies to: SAP BI 7.0. For more information, visit the EDW homepage Summary The objective of this document is to know the various available DTP options
Invoice Collaboration: Self Billing Invoice
Invoice Collaboration: Self Billing Invoice Applies to: Supply Network Collaboration 5.1 with the back end system ERP 5.0 with SP 10 and above. For more information, visit the Supply Chain Management homepage.
Web Dynpro: Multiple ALV Grids and Layouts in ALV
Web Dynpro: Multiple ALV Grids and Layouts in ALV Applies to: SAP ECC 6.0. For more information, visit the Web Dynpro ABAP homepage. Summary The article is designed in such a way that person with ABAP
Deleting the User Personalization done on Enterprise Portal
Deleting the User Personalization done on Enterprise Portal Applies to: SRM 7.0 with EP 6.0. For more information, visit the Supplier Relationship Management homepage Summary This document explains the
Vendor Consignment. Applies to: Summary. Author Bio. SAP ECC 6.0. For more information, visit the Supply Chain Management homepage.
Applies to: SAP ECC 6.0. For more information, visit the Supply Chain Management homepage. Summary This document helps the P2P consultants to understand the Vendor Consignment scenario in SAP. It explains
Creation and Configuration of Business Partners in SAP CRM
Creation and Configuration of Business Partners in SAP CRM Applies to: SAP CRM 2005 (5.0) and above release. For more information, visit the Customer Relationship Management homepage. Summary This document
Make to Order in SAP ERP
Applies to: SAP ECC 6.0. For more information, visit the Enterprise Resource Planning homepage. Summary This document shall help consultants in the cross functional areas like Sales and Distribution, Production
Deleting the Requests from the PSA and Change Log Tables in Business Intelligence
Deleting the Requests from the PSA and Change Log Tables in Business Intelligence Applies to: SAP BI 7.0. For more information, visit the Business Intelligence homepage Summary This paper discusses how
Sales Commission Calculation & Settlement Handling through Order Processing
Sales Commission Calculation & Settlement Handling through Order Processing Applies to: SAP Sales & Distribution & Incentive and Commission Management in ECC 6.0. For more information, visit the Enterprise
Display Options in Transaction SE16
Display Options in Transaction SE16 Applies to: SAP-HCM. For more information, visit the Enterprise Resource Planning homepage. Summary This document deals with the various data display options available
Quantifying the Amount of Cash Discount Lost
Quantifying the Amount of Cash Discount Lost Applies to: All Business organizations where the Financial Controller wants to analyze how much cash discount is lost due to non-adherence to payment terms
Table of Content. SAP Query creation and transport Procedure in ECC6
SAP Query creation and transport Procedure in ECC6 Applies to: ECC6, For more information, visit the Enterprise Resource Planning homepage. Summary This article guides the how to technique for creating
Inventory Management (0IC_C03) Part - 3
Inventory Management (0IC_C03) Part - 3 Applies to: SAP NetWeaver Business Warehouse (Formerly BI), Will also work on SAP BI 3.5. For more information, visit the Business Intelligence homepage. Summary
Process Controlled Workflow SRM 7.0 (Using BRF)
Process Controlled Workflow SRM 7.0 (Using BRF) Applies to: SAP SRM 7.0 For more information, visit the Supplier Relationship Management homepage. Summary This document helps user to create workflow s
Overview of SAP BusinessObjects Risk Management 10.0
Overview of SAP BusinessObjects Risk Management 10.0 Applies to: SAP BusinessObjects Risk Management 10.0, SAP NetWeaver 7.0, Enhancement Package 2. For more information, visit the Governance, Risk, and
SPDD & SPAU Adjustments Handbook
SPDD & SPAU Adjustments Handbook Applies to: SAP Upgrades. For more information, visit the ABAP homepage. Summary Through this document the reader will be able to get a detailed idea about the working
Creating Transaction and Screen Variants
Creating Transaction and Screen Variants Applies to: Tested on SAP version ECC 6. Summary This article explain a way to create Transaction and Screen Variants to change screen layouts. And how to assign
Direct Subcontracting Process (SAP SD & MM)
Direct Subcontracting Process (SAP SD & MM) Applies to: This article is applicable to SAP SD & MM modules of SAP for version SAP 4.7 till ERP 6.0 Summary This article describes a process called Direct
Guidelines for Effective Data Migration
Guidelines for Effective Data Migration Applies to: SAP R/3. All releases. For more information, visit the ABAP homepage. Summary Data Migration is an important step in any SAP implementation projects.
Order Split Usage in Production Orders
Order Split Usage in Production Orders Applies to: SAP Shop Floor Control (Production Orders) R/3 and ECC 6.0. For more information, visit the Enterprise Resource Planning homepage. Summary: This is an
BW Performance Monitoring
Applies to: SAP BW 7.0. For more information, visit the EDW homepage. Summary This article helps to achieve BW statistics of the system which will help a user to calculate the performance for a particular
SAP CRM 7.0 for Newbies: (Part 1) Simple BOL Object Creation for CRM Webclient UI
SAP CRM 7.0 for Newbies: (Part 1) Simple BOL Object Creation for CRM Webclient UI Applies to: This article applies to SAP Netweaver 7.0, CRM ABAP 7.0. For more information, visit the Customer Relationship
SAP NetWeaver Developer Studio 7.30 Installation Guide
SAP NetWeaver Developer Studio 7.30 Installation Guide Applies to: SAP NetWeaver CE 7.30, SAP Net Weaver Developer Studio (7.30). For more information, visit the Web Dynpro ABAP homepage. Summary This
Middleware Configuration and Monitoring for Master Data Transfer from SRM to ECC
Middleware Configuration and Monitoring for Master Data Transfer from SRM to ECC Applies to: SRM 5.0, SRM 7.0 For more information, visit the Supplier Relationship Management homepage. Summary Master data
Step by Step Procedure to Block and Debug a CIF Queue Flowing from R/3 to APO System
Step by Step Procedure to Block and Debug a CIF Queue Flowing from R/3 to APO System Applies to: SAP R/3 and SAP APO. For more information, visit the ABAP homepage. Summary This article gives a detailed
Web Dynpro ABAP: ALV and Table in Popup Window
Web Dynpro ABAP: ALV and Table in Popup Window Applies to: SAP ECC 6.0 Summary Normally in ABAP, we come across the scenario of displaying ALV in popup. This article tells about displaying data both in
Table of Contents. Passing Data across Components through Component Controller between Two Value Nodes
Passing Data across Components through Component Controller between Two Value Nodes Applies to: SAP CRM WEBCLIENT UI 2007. For more information, visit the Customer Relationship Management homepage Summary
How to Generate Stack Xml for Ehp4 and Above Upgrade
How to Generate Stack Xml for Ehp4 and Above Upgrade Applies to: ECC 6.0 EHP4 or Above. For more information, visit the Enterprise Resource Planning homepage Summary For upgrading Enhancement Package4
How to Integrate CRM 2007 WebClient UI with SAP NetWeaver Portal
How to Integrate CRM 2007 WebClient UI with SAP NetWeaver Portal Applies to: Enterprise Portal, CRM 2007. For more information, visit the Portal and Collaboration homepage. Summary This document will describe
SAP CRM 7.0 E2C Setup: CRM via Email Toolset
SAP CRM 7.0 E2C Setup: CRM via Email Toolset Applies to: SAP CRM 700/NW 701. For more information, visit the Customer Relationship Management homepage. Summary This article describes the Email2CRM functionality
First step to Understand a Payroll Schema
First step to Understand a Payroll Schema Applies to: This article is relevant to SAP HCM module where Payroll is implemented. This applies to all SAP Releases. For more information; visit the Enterprise
Deploying Crystal Reports on Top of a SAP BI Query
Deploying Crystal Reports on Top of a SAP BI Query Applies to: SAP BI NetWeaver 2004s, Crystal Reports 2008. For more information, visit the Business Intelligence homepage. Summary The objective of the
SAP BW - Excel Pivot Chart and Pivot Table report (Excel)
SAP BW - Excel Pivot Chart and Pivot Table report (Excel) Applies to: SAP BI Consultants. For more information, visit the EDW HomePage. Summary Document explains to create Excel Pivot Chart and Pivot Table
Release Strategy Enhancement in Purchase Order
Release Strategy Enhancement in Purchase Order Applies to: SAP ECC 6.0. For more information, visit the Enterprise Resource Planning homepage Summary This document helps the P2P consultants to understand
Integrated Testing Solution Using SAP Solution Manager, HP-QC/QTP and SAP TAO
Integrated Testing Solution Using SAP Solution Manager, HP-QC/QTP and SAP TAO Applies to: SAP Test Acceleration and Optimization, HP Quality Center, HP Quick Test Professional, SAP Solution Manager. For
Understanding BW Non Cumulative Concept as Applicable in Inventory Management Data Model
Understanding BW Non Cumulative Concept as Applicable in Inventory Management Data Model Applies to: SAP R/3, SAP ECC 6.0 and SAP BI NetWeaver 2004s. For more information, visit the Business Intelligence
Compounding in Infoobject and Analyzing the Infoobject in a Query
Compounding in Infoobject and Analyzing the Infoobject in a Query Applies to: SAP BI 7.0. For more information, visit the EDW homepage Summary This article demonstrates step by step process of creating
ABAP How To on SQL Trace Analysis
Applies To: ABAP Summary SQL trace is a performance analysis tool that shows how open SQL statements are converted into native SQL statements. The following document discusses the performance measure utility
Creating New Unit of Measure in SAP BW
Creating New Unit of Measure in SAP BW Applies to: Software Component: SAP_BW. For more information, visit the Business Intelligence homepage. Release: 700 Summary This article is intended to serve as
Create Automatic Mail Notification/ Email Alert for Process Chain Monitoring
Create Automatic Mail Notification/ Email Alert for Process Chain Monitoring Applies to: SAP BW 3.X, Business Intelligence 7.0. For more information, visit the EDW homepage. Summary This document will
SAP BW 7.3: Exploring Semantic Partitioning
SAP BW 7.3: Exploring Semantic Partitioning Applies to: SAP BW 3.x & SAP BI Net Weaver 2004s. For more information, visit the EDW homepage. Summary A semantically partitioned object is an InfoProvider
Multi Provider Creation Based on Sales and Planning Info Cubes
Multi Provider Creation Based on Sales and Planning Info Cubes Applies to: SAP BI 2004s or SAP BI 7.x. For more information, visit the Business Intelligence homepage. Summary In This article, I am going
Valuation of Materials using FIFO Method
Valuation of Materials using FIFO Method Applies to: 4.7EE, ECC 6.0 For more information, visit the Enterprise Resource Planning homepage. Summary This article explains the Configuration and Process steps
Step by Step Procedures to Load Master Data (Attribute and Text) from FlatFile in BI 7.0
Step by Step Procedures to Load Master Data (Attribute and Text) from FlatFile in BI 7.0 Applies to: SAP Business Intelligence (BI 7.0). For more information, visit the EDW homepage Summary This article
Workflow Troubleshooting and Monitoring in SAP ECC 6.0
Workflow Troubleshooting and Monitoring in SAP ECC 6.0 Applies to: ECC 6.0, Workflow Troubleshooting & Monitoring Summary A major advantage of workflow is the ability to monitor the workflow steps according
Exposing RFC as Web Service and Consuming Web Service in Interactive Forms in ABAP
Exposing RFC as Web Service and Consuming Web Service in Interactive Forms in ABAP Applies to: SAP Interactive Forms by Adobe and Web Service in ABAP. For more information, visit SAP Interactive forms
Inventory Management in SAP BW
Applies to: SAP BW 3.X and BI NetWeaver 2004s. For more information, visit the EDW homepage. Summary This document aims to explain the concept of Inventory management using non cumulative key figures in
SAP MM: Purchase Requisition with Classification and Workflow Approval
SAP MM: Purchase Requisition with Classification and Workflow Approval Applies to: SAP 4.7 and above, SAP-MM-PUR-REL. For more information, visit the Enterprise Resource Planning homepage. Summary The
ABAP Debugging Tips and Tricks
Applies to: This article applies to all SAP ABAP based products; however the examples and screen shots are derived from ECC 6.0 system. For more information, visit the ABAP homepage. Summary This article
Extractor in R/3 and Delta Queue
Applies to: SAP BW (3.5) / SAP BI(7.0). For more information, visit the Business Intelligence homepage. Summary This article contains all the information required in order to create data sources in R/3
Introduction to COPA and COPA Realignment
Introduction to COPA and COPA Realignment Applies to: SAP BI Consultants & Developers working on COPA Data Model. For more information, visit the EDW homepage Summary This document gives a brief introduction
SAP BW - Generic Datasource Function Module (Multiple Delta Fields)
SAP BW - Generic Datasource Function Module (Multiple Delta Fields) Applies to: SAP BW 3.5 / SAP 7.0 Consultants. For more information, visit the EDW HomePage. Summary Fetch the delta on multiple fields
U.S. FDA Title 21 CFR Part 11 Compliance Assessment of SAP Records Management
U.S. FDA Title 21 CFR Part 11 Compliance Assessment of SAP Records Management Disclaimer These materials are subject to change without notice. SAP AG s compliance analysis with respect to SAP software
Multi Level Purchase Order Release Strategy
Multi Level Purchase Order Release Strategy Applies to: SAP ECC 6.0. For more information, visit the Enterprise Resource Planning homepage. For more information, visit the Supply Chain Management homepage.
Configuration and Utilization of the OLAP Cache to Improve the Query Response Time
Configuration and Utilization of the OLAP Cache to Improve the Query Response Time Applies to: SAP NetWeaver BW 7.0 Summary This paper outlines the steps to improve the Query response time by using the
SAP Workflow in Plain English
Applies to: SAP Workflow. For more information, visit the Business Process Modeling homepage. Summary This article describes the basics of SAP workflow in very simple terms along with the basic terminology
Infosys: Treating Governance and Compliance Strategically with SAP Access Control
Infosys: Treating Governance and Compliance Strategically with SAP Access Control Stringent management of user access controls and the segregation of duties are becoming a strategic concern for businesses
How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions
How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions Introduction This paper provides an overview of the integrated solution and a summary of implementation options
Currency Conversion using Variables in SAP BI -Reporting
Currency Conversion using Variables in SAP BI -Reporting Applies to: SAP BI 7.0. For more information, visit the Business Intelligence homepage. Summary This Article gives you a brief idea on how to do
LSMW: Upload Master Data using Batch Input Recording
LSMW: Upload Master Data using Batch Input Recording Applies to: All modules of SAP where upload of data need to be performed using Batch Input Recording. For more information, visit the Master Data Management
SAP CRM-BW Adapter an Overview
Applies to: SAP CRM / SAP BW (3.5 / 7.0). For more information, visit the Customer Relationship Management homepage. Summary This article gives an overview about the BW Adapter that is used in the BI-CRM
Embedding Crystal Reports inside ECC ALV Reports
Embedding Crystal Reports inside ECC ALV Reports Applies to: Applies to ECC Enhancement Package 5 Summary These steps describe how to configure and set up embedded Crystal Reports inside the ECC system
SAP ECC Audit Guidelines
Applies to: Applies to SAP R/3 and ECC systems. F me infmation, visit the Security homepage. Summary The Purpose of this document is to provide the Security Administrat with guidance on preparing f the
Market Basket Price Calculation in Retail
Market Basket Price Calculation in Retail Applies to: SAP IS Retail 6.0 (release number, SP, etc.) to which this article or code sample applies. For more information, visit the Business Process Expert
Step By Step Procedure to Create Logical File Path and Logical File Name
Step By Step Procedure to Create Logical File Path and Logical File Name Applies to: SAP BW (3.5) / SAP BI(7.0) For more information, visit Business Intelligence Homepage. Summary These documents describe
Creating Web Service from Function Modules/BAPIs & Integrating with SAP Interactive Forms
Creating Web Service from Function Modules/BAPIs & Integrating with SAP Interactive Forms Applies to: ECC 6.0, SAP Interactive forms by Adobe. Summary This document states how to create Web Service from
Step by Step Procedure to Create Broadcasters, to Schedule and to Enhance of SAP- BI Queries from Query Designer
Step by Step Procedure to Create Broadcasters, to Schedule and to Enhance of SAP- BI Queries from Query Designer Applies to: SAP Business Intelligence 7.0. For more information, visit the EDW homepage.
Overcoming Testing Challenges in SAP Upgrade Projects
Overcoming Testing Challenges in SAP Upgrade Projects Applies to: SAP Upgrade Projects. For more information, visit the Enterprise Resource Planning homepage. Summary Testing in SAP Upgrade forms the crucial
Credit Management in Sales and Distribution
Credit Management in Sales and Distribution Applies to: Credit Management in Sales and Distribution. For more information, visit the Enterprise Resource Planning Homepage. Summary This document illustrates
Forgot or Lock "Administrator or J2EE_ADMIN" Password
Forgot or Lock "Administrator or J2EE_ADMIN" Password Applies to: SAP NetWeaver Portal 7.0. For more information, visit the Portal and Collaboration homepage. Summary This article provides you a step guide
SAP CRM System 6.0/7.0. For more information, visit the Customer Relationship Management homepage
Applies to: SAP CRM System 6.0/7.0. For more information, visit the Customer Relationship Management homepage Summary This article explains how to customize the Fact Sheet for different business roles.
Configuration of Enterprise Services using SICF and SOA Manager
Configuration of Enterprise Services using SICF and SOA Manager Applies to: SAP NetWeaver 7.0 SP14 and above. For more information, visit the SOA Management homepage. Summary This document will provide
Continuous Monitoring: Match Your Business Needs with the Right Technique
Continuous Monitoring: Match Your Business Needs with the Right Technique Jamie Levitt, Ron Risinger, September 11, 2012 Agenda 1. Introduction 2. Challenge 3. Continuous Monitoring 4. SAP s Continuous
SDN Community Contribution
SDN Community Contribution (This is not an official SAP document.) Disclaimer & Liability Notice This document may discuss sample coding or other information that does not include SAP official interfaces
Quick Viewer: SAP Report Generating Tool
Quick Viewer: SAP Report Generating Tool Applies to: SAP Net Weaver 7.0, ABAP, SAP ECC 6.0, to all those who wants to learn about SAP Report Generating Tool: Quick Viewer. For more information, please
INFORMATION TECHNOLOGY CONTROLS
CHAPTER 14 INFORMATION TECHNOLOGY CONTROLS SCOPE This chapter addresses requirements common to all financial accounting systems and is not limited to the statewide financial accounting system, ENCOMPASS,
Compliance & SAP Security. Secure SAP applications based on state-of-the-art user & system concepts. Driving value with IT
Compliance & SAP Security Secure SAP applications based on state-of-the-art user & system concepts Driving value with IT BO Access Control Authorization Workflow Central User Management Encryption Data
Business-Driven, Compliant Identity Management
SAP Solution in Detail SAP NetWeaver SAP Identity Management Business-Driven, Compliant Identity Management Table of Contents 3 Quick Facts 4 Business Challenges: Managing Costs, Process Change, and Compliance
SAP BASIS and Security Administration
SAP BASIS and Security Administration An Article From thespot4sap LTD Contents 1.0 Introduction...2 2.0 SAP Security Components The Big Picture...2 2.1 SAP Authorization Concept...3 2.2 Composite Profiles...4
Understanding DSO (DataStore Object) Part 1: Standard DSO
Understanding DSO (DataStore Object) Part 1: Standard DSO Applies to: SAP NetWeaver BW. Summary This is the first of a three part series of documents containing each and every detail about DSOs and their
SDN Contribution Beginners guide to CRM Interaction Center (IC) Winclient setup
SDN Contribution Beginners guide to CRM Interaction Center (IC) Winclient setup 2006 SAP AG 1 Applies to: SAP CRM 4.0 and higher Summary The Interaction Center forms the foundation for collaboration and
SAP Secure Operations Map. SAP Active Global Support Security Services May 2015
SAP Secure Operations Map SAP Active Global Support Security Services May 2015 SAP Secure Operations Map Security Compliance Security Governance Audit Cloud Security Emergency Concept Secure Operation
Transfer of GL Master from Source SAP System to a Target SAP System through IDOCS
Transfer of GL Master from Source SAP System to a Target SAP System through IDOCS Applies to: SAP ECC 6.0. For more information, visit the Enterprise Resource Planning homepage. Summary SAP offers a wide
Connecting the dots: IT to Business
Connecting the dots: IT to Business Jason Wood, CPA, CISA, CIA, CITP, CFF April 2015 1 Speaker Bio Jason Wood Over 18 years of international business experience in planning, conducting, and quality reviewing
Data Extraction and Retraction in BPC-BI
Data Extraction and Retraction in BPC-BI Applies to: Document is applicable to all the BPC 7.0 NW version users and the users BI 7.0 integration with BPC. For more information, visit the Enterprise Performance
