sap business objects access control [1]

Upload: abhishek-chakraborty

Post on 07-Apr-2018

223 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/4/2019 SAP Business Objects Access Control [1]

    1/16

    Eecties toa stggeto aess compiaceiitiaties o a ee-iceasig mbe o eg-ato eiemets. At tesame time, bsiess pat-es a cstomes epecta moe eiciet ecage oiomatio om bsiesses,

    wic mst estabis aope IT iastcte iespose. Esig popesegegatio-o-ties poi-cies to maage access asa be o IT stakeoesi tese ogaiatios. TeSAP BsiessObjects

    Access Coto appicatioeps bsiess maages,IT secit, a aitoscoaboate i cotoigaccess a peetiga acoss te etepise

    wie miimiig ait timea ait-eate costs.

    SAP BuSineSSOBjectSAcceSS cOntrOlCOnIdEnTly COnTrOl

    ACCESS And PrEvEnT rAud

    SAP Solution in DetailSAP BsiessObjects Goeace,risk, a Compiace Sotios

    SAP BsiessObjects AccessCoto

  • 8/4/2019 SAP Business Objects Access Control [1]

    2/16

  • 8/4/2019 SAP Business Objects Access Control [1]

    3/16

    4 Challenges to EicientCompliance Management

    4 agmete AppoacIceases risk

    4 Ieiciet CompiacePocesses

    4 lack o rea-Time Oesigt

    6 Reduced Access Risk Acrossthe Enterprise

    6 Etepise-Wie risk Aasis6 risk Mitigatio

    8 Streamlined ComplianceProcesses

    8 Etepise roe Maagemet9 Compiat use Poisioig10 Spese Piiege

    Maagemet

    11 Real-Time Oversight11 Maagemet Oesigt o

    Bsiess Owe Accotabiit12 Miimie Ait Time a Ait-

    reate Costs12 Itegate Sotios to Bi

    Bsiess Eectieess

    13 SAP BusinessObjects Gover-nance, Risk, and ComplianceSolutions

    13 Obtai Compete Isigt,Geate Eiciec, aImpoe eibiit

    13 Compete Isigt13 Geate Eiciec13 Impoe eibiit

    13 Find Out More

    cOntent

  • 8/4/2019 SAP Business Objects Access Control [1]

    4/16

    Global fau repot, Isse 8, Mac2009). Caegig ecoomic coi-tios te to ea to icease aas compaies ae pesse to acieeiacia ests. Iceases i aca aso occ i pbic o piateogaiatios tog tet o compaiomatio as empoees ae oceto wok ae wit ece esocesa epeiece saa ectios a

    aos. Wat is eee is a ato-mate, etepise-wie sstem oaccess coto tat eabes IT eec-ties to aess egato eie-mets, maitai a ope iastcteto sppot bsiess ees, a ptcotos i pace to ece isk apeet a.

    Te egato eiomet o pbica opoit ogaiatios as be-come iceasig compe. Compaiesmst aess ot o oiota ma-ates i sc aeas as iacia epot-ig, secit, piac, ecos etetio,

    impot-epot egatios, eiome-ta staas, occpatioa saet, aceit isk epose bt aso eticamaates o tei ist-speciicaeas. Te gowig mbe o ega-to eiemets ote ests i aagmete appoac acoss te ete-pise, i wic eac epatmet obsiess it is iepeet taskewit impemetig poicies, ietiiga measig isks, a sppotigegato maates.

    Fragmented Approach IncreasesRisk

    Tis agmetatio geat impactsaccess coto maagemet oeo te ke cotos o eectie com-piace, wic ca o be aesseetepise-wie. Amiistatos aeace wit tosas o ses, oes,a pocesses tat eie accesseaatio, testig, a emeiatio.Witot pope segegatio o ties

    (Sod) cotos, mistakes a ae to oeeacig sstem-accesspiieges ca sigiicat impact tepeomace a eptatio o aogaiatio. Te cost i moe aesoces to impemet Sod cotosa peet citica access isk o aogoig basis ca be oewemigo ma compaies.

    Ineicient Compliance Processes

    I tis appoac, isk a compiaceiitiaties ae geea eie amease at te oca ee a sp-pote b oca epatmeta IT ss-

    tems. Te oca ecisio makesesposibe o tei iitiatie ae oteawae o te iteepeeciesbetwee tei maates a tose iote epatmets. Compicatig tematte, eac epatmeta IT sstemma se its ow metics, staas,a metooogies o aaig teisk a compiace iomatio o teiitiatie it sppots. As a est, ataaggegatio becomes a compe atime-cosmig task a ote ests

    i a imite o ase iew o ete-pise isk. Sc a ieiciet appoacca ea to picatio o cotos,icosistet poicies, a iict ipeictig isk. Taspaec is ost,wie te cost o peetig citicaaccess isk a maagig compiaceises sigiicat.

    Lack o Real-Time Oversight

    recet, tee as bee a iceasigmbe o iciets o copoate a

    i ews eaies. Ma o te a-et actios wee eecte i patsig impope access to copoatesstems, e-mai accots, a popie-ta iomatio. Oe te past teeeas, compaies ae ost uS$8.2miio eac ea o aeage, aicease o 22% oe te same igeom te peios eas se (Koll

    chAllengeS tO efficient cOmPliAncemAnAgementrAGMEnTEd APPrOACh duE TOCOMPlEx rEGulATOry EnvIrOnMEnT

    Wie te isibiitcoties to impoe,te access to sesitie

    ata b cet aome empoeescoties to be a keisk eemet.

    2010 Global State oInomation SecuitSue b CIO, CSO, anPiceWatehouseCoopes

    4 SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    5/16

    Te SAP BsiessObjects AccessCoto appicatio eps ogaiatiosoecome tese caeges so tatte ca coiet coto access apeet a. Te appicatio eabesbsiess maages, IT secit, a

    aitos to: rece Sod ioatios a citica

    access isk acoss te etepise Steamie compiace pocesses deie ea-time oesigt o te

    cet isk sitatio.

    B sppotig te ceatio ocompiat bsiess pocesses, SAPBsiessObjects Access Cotoeabes bsiess-owe accotabiita miimies ait time a ait-eate costs.

    Te Secit EectieCoci Se epot-e moe ta 40% i-

    ceases i tet, a,a eests o sp-pot to hr eatie toaos i isca ea200809.

    2009 Secuit Bugetreseach repot: Impacto the Economic downtun,

    Api 2009, Secit Eec-tie Coci

    5SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    6/16

    reduced AcceSS riSk AcrOSSthe enterPriSeMInIMIzEd TIME TO COMPly WIThrEGulATOry rEquIrEMEnTS

    o compaies stggig to maagemtipe compiace iitiaties, Sod cabe oe o te most iict cotos toepo. Keepig pace wit costatcagig bsiess eiemets aoe eiitios, aeig ew access

    o to o access, a testig accessatoiatios o tosas o empo-ees acoss aios sstems pesetsa oewemig caege to peet-ig citica access isk. To take cotoo se access i tei ogaiatio,compiace gops so statb coctig a iitia ceap,wic ioes tee steps. ist, aetepise-wie isk aasis mst becocte to coe eistig accessioatios. net, te ioatios o isks

    coee mst be eiewe. Te iastep is to mitigate te isk associatewit te access i estio o emoete access. To peom a compee-sie ceap api a cost-eectie,best- compaies eie sotwaeegieee wit tis ppose i mi.

    Enterprise-Wide Risk Analysis

    SAP BsiessObjects Access Cotoeies isk aasis a emeiatioctioait tat eabes bsiesses

    to aae citica access isk apia ieti Sod coicts base oea-time ata. Te appicatio ietiiespotetia access isks sig a obstatabase o Sod es tat ae baseo best pactices. Te e set ee-ages SAP epetise i bsiess po-cesses a te compas eas oepeiece assistig ist-eaigcstomes wit Sod impemetatios.

    It ices es o te most commobsiess ctios a associateisks, wic is eisite o ietiigSod ioatios a citica accessisks. Te es atabase is compatibewit SAP a o-SAP sotwae

    icig Oace, PeopeSot, a JdEwas pocts as we as egacsotwae a appicatios ot cassiieas etepise esoce paig (ErP)sotwae. Tis compeesie itega-tio eabes te mappig o ctiosa associate isk acoss a tesesotwae sotios to estabis a co-sistet poic a peet picatioo eot.

    Risk Mitigation

    upo ietiig Sod ioatios acitica access isks, bsiess maag-es ca te eiew isses oig te iitia isk aasis. robstepotig ctioait i SAPBsiessObjects Access Cotoaows bsiess maages to sot teSod ioatios b oe, b bsiesspocess, a b se a to eiewte oot case o te ioatio. Tesotwae aso iicates te seeitee o a ioatio. Wit tis ee

    o etaie epotig, stakeoes aeabe to esoe isses o ig teaasis a peet isk.

    A eampe o peetig a Sodioatio is we it is iscoee tatempoees ae atoie bot toceate ew eos a to make pa-mets to tose eos. Tat opesp te possibiit o a, becase te

    Votorantim Celulose

    e Papel S.A., one of

    Brazils largest pulp and

    paper producers, reduced

    access conflicts by 91%with SAP BusinessObjects

    Access Control.

    Celso yao, risk Manage,

    votoantim Celulose e

    Papel S.A.

    6 SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    7/16

    empoees ca pa moe ito accotste temsees ae coige.Atoiatio o tis combiatio obsiess ctios epesets a Sodioatio. To peet te isk, te maag-e mst ecie ow to mitigate te ioa-

    tio. Oe wa is to esci empoeesatoiatio to peom oe o te bsi-ess ctios. I bot ctios aeeie, te maage ca coose aappopiate mitigatig coto a assiga moito to oesee tat te mitigatigcoto is caie ot. Ate te iitiaceap, maages ca coct egaisk aases o se access eestsa oe eiitios to sstai Sod co-to a peet citica access isks oa ogoig basis.

    SAP BsiessObjects Access Cotoeces Sod ioatios a citicaaccess isks acoss te etepise,teeb steamiig compiace witegato eiemets. I aitio toepig eimiate eistig access isks,

    te appicatio eps peet te ai-tio o ew isks b sppotig com-piat bsiess pocesses ig, oeampe, oe ceatio a oe poi-sioig. Te sotwae eeages esets tat ae package wit it atat wee eeope b SAP oea peio o 12 eas base o bestpactices.

    7SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    8/16

    ioatios. new oes ae ote testeo wete te se ca peom tetasks eie b tei oe bt otteste o compiace. We Sod io-atios ae eeae ig se accep-tace testig, IT is eie to et

    to te eeopmet pase a eceatete oe. Tis pocess is ot o iei-ciet, bt it aso ceates isk o tecompa o te time ig wicte impope piieges ae assigeto a oe.

    SAP BsiessObjects Access Cototasates tecica access isks itocommo bsiess agage, aciitatigimpoe coaboatio betwee IT absiess owes. B icopoatig

    Sod es ito te oe esig aoe ceatio pocess, te appicatioaows o to eie compiat oespoactie. Te eibe oe-biigmetooog i te appicatio gies

    o tog a step-b-step pocess obiig ew oes. Te appicatio asooes o ctioait to peom pe-etie simatios, wit wic o casee wat impact access cages wiae beoe te ae itoce ito a

    poctio eiomet. Simatiosca be peome at te se ee,oe ee, o positio ee to test oa Sod ioatios. yo ca aso pe-om atomate isk assessmet, tackcages, a peom oe maiteace,wic iceases te cosistec o seaccess a owes IT costs.

    As a sige atoitatie soce oetepise oe eiitio, SAPBsiessObjects Access Coto

    eoces best-pactice metooogieswie eimiatig oie, maa po-cesses sc as patig MicosotEce seets actios tat ca escapeatomate, sotwae-sppote Sod

    Te cost i moe a esoces toeoce access coto, Sod, a com-piat se poisioig o a cotiabasis ca be oewemig o macompaies. Ee ate coctig aiitia ceap, ew access coto isks

    ma aise o a ai basis as se oesa bsiess ees cage a ewegatios ae itoce.

    SAP BsiessObjects Access Cotoeps ogaiatios itoce coti-os access maagemet. Te sotioatomates a aspects o access ma-agemet, icig etepise oe ma-agemet, compiat se poisioig,a emegec piiege maagemetto icease eiciec a ece te

    esoces a time eie ocompiace.

    Enterprise Role Management

    A ke caege to ceatig compiatetepise oe maagemet is te acko eectie coaboatio betwee ITteams a bsiess maages. Bsi-ess maages ow te esposibiito maagig Sod a citica accessisk. Te ma coct peioic accesseiews a pepae o a espo to

    moe stiget aits; owee, teae ote most cocee wit simpobtaiig te ecessa access tomake tei empoees poctie aess cocee wit te potetia iskspose to Sod i te pocess.

    IT as te tecica epetise to ptpope sstem a appicatio accesscotos i pace. howee, IT secitote bis oes iepeet o Sodcotos, a tis ca ea to Sod

    Figure 1: ReduceCost with AutomatedEnterprise RoleManagement

    Centralized Role Management

    Etepise es Ait og

    SAPBsiessObjectsAccess Coto

    appicatio

    Across Applications

    Compliant Enterprise Roles

    roe roe roe roe roe roe roeroeroeroe

    roe

    SAP Oace PeopeSot legac

    StreAmlined cOmPliAncePrOceSSeSCOnTInuOuS ACCESS MAnAGEMEnT

    8 SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    9/16

    es. Its appoa wokow ca seeas a eco o ocmetatio aait pposes. Wit tis cetaietoo, tecica a bsiess owes aeabe to se te same, cosistet temsto ocmet oe eiitios. Bsiess

    ses ae empowee wit atomatecage maagemet, sige-cickatomatic oe ceatio, a oecompaiso eates. B atomatigetepise oe maagemet, SAPBsiessObjects Access Cotoeabes bsiesses to ece te costo oe maiteace, eimiate maaeos, a eoce best pactices.

    Compliant User Provisioning

    Ma ogaiatios se ieiciet po-cesses i tei attempt to maitaiogoig access coto compiace.Tese pocesses ice sc toos ase-mai, speaseets, a ie papecopies, eac o wic ioes mtipemaa steps. Tasitioig e sesto a ew assigmet o iig ewempoees a gatig tem accessca take weeks awa om poctiewok. Tis tpe o appoac oteeaes ot isk aasis atogete. Asogaiatios gat a esci access

    to etepise sstems, te empoeeswo peom te wok ote oeookow tese cages ca impact Soda citica access isk. A tee isote itte o o atomate wokowto poie a eco o cages, eaigtat wok to be peome maa bcompiig oms, e-mai messages, apape ies.

    SAP BsiessObjects Access Cotoeabes atomate a compiat

    se poisioig togot te

    empoee iecce to peet Sodioatios. Empoees ca eestaccess sig a stcte iaog ose-seice wokows tat specibsiess pocesses a oes, ec-ig te IT esoces eie. Maag-

    es eceie a e-mai otiicatio o aempoees eest. Te appicatioatomatica tests o Sod isses,emoes SOd o citica access isks,a impemets mitigatig cotospio to appoa. Wit tis ctioait,te appicatio peets Sod ioatiosom beig itoce ito te po-ctio eiomet. Aitioa, itsamic wokow poies e-to-eatomatio o se poisioig i m-tipe appicatios. Te appicatio aso

    oes epae atomate poisio-ig tog itegatio wit staas-base ietit maagemet sotwae.reests ca be atomatica itegat-e wit se ietit iomatio om aligtweigt diecto Access Potoco(ldAP) iecto o ote maesoces atabases so tat maagesca appoe eests ia e-mai.

    Wit compiace embee i bsi-ess pocesses, ogaiatios ca takea peetie appoac, epig estict

    maagemet om gatig access toa empoee i a mae tat migtceate a Sod ioatio. howee, ia ie sitatio eies ig-iskaccess piieges to be gate scas we a sma bac oice maagemst be abe to bot ceate a paeos te appicatio eabes teceatio o mitigatig cotos, wicca be assige as eie. Itegat-e, ea-time isk aasis ca be co-cte beoe access is gate.

    I aitio, SAP BsiessObjectsAccess Coto ceates a moeeiciet itea ait pocess wit

    bsiess-ie epotig a ea-tes sc as ait ogs o etaietackig, cstomiabe epotig, apocess-eiciec statistics. Isteao tig to i oms, e-mai messag-es, a eeat ies, cage ogs aeeai aaiabe eectoica, teebmiimiig ait time a ait-eatecosts. B atomatig compiat sepoisioig, o ogaiatio caicease poctiit a ece teoea cost o compiace.

    Finally we have just one

    place to look for all our

    compliance rule sets, viola-

    tions, mitigation controls,

    checks and balances, and soforth. That winds up saving

    us quite a bit of money.

    dia daa, diecto o Secit a

    qait Assace, newe rbbemai

    9SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    10/16

    Superuser Privilege Management

    Gatig emegec access to ete-pise sstems eas to oe o te mostcommo ait isses compaies epe-iece toa. yo ma ae aitioaaccotig pesoe wo ee topost pamets ig te mot-ecose o a saes maage wo eiesappoa o a picig iscot i oeto cose a ea we is maage is

    o acatio. I sstem access is tooseee esticte, cost apoctie eas ca occ as teappoig maage is cotacte, ewaccess piieges ae ceate, aemegec access is appoe agate. eet, eistig accessigts ae sae to cicmet tecotos, itocig egato ioa-tios a eaig aitos witot aai tai o wo i wat.

    I sitatios sc as tese, SAPBsiessObjects Access Cotoeabes api espose wit ctioa-it tat atoies ses to peomactiities otsie tei oe sig ie-igte ogi Ids wit spese pii-eges i a cotoe, aitabe eio-met. no oge wi o ae to waito wake p speisos i te mie ote igt to get appoas o piiegeaccess. Te appicatio eiciet

    ceates emegec access o ase a aows compaies to ickesoe tis commo ait isse,sigiicat ecig te time eieto peom citica tasks.

    Wit tis ctioait, te appicatioaso eies te ecessa aitepotig to peet egato ioa-tios. It tacks, moitos, a ogsee actiit a se peoms wieogge i wit te piiege se Id.

    Staa epots, icig otiica-tios o sage a etaie actiitogs, ae set atomatica to spe-isos o icease isibiit. Actiitogs tack ipt ow to te ie aeee a aow o to ite, sot, aowoa ipt iomatio. Ait timeis miima, becase etaie ogs aeaaiabe o aitos immeiate aca be eiewe a sige o iaace o te oicia ait epot.

    SAP BsiessObjects Access Cotoatomates Sod a access maage-met cotos a aciitates impoecoaboatio betwee IT a bsiessses. Atomate epotig embeei bsiess pocesses eces tetime a cost o aits. Te sotiosteamies compiace pocesses oetepise oe maagemet, compiatse poisioig, a emegec pii-ege maagemet, so o ca maitai

    cotios compiace ig oeesig, i ai opeatios, a eeig get sitatios.

    Ecessie accessigts was te topitea/etea ait

    iig oe te past12 mots.

    Potecting What Mattes,Te 6t Aa GobaSecit Se, eba16, 2009, deoitte

    Figure 2: Prevent Riskwith Compliant UserProvisioning

    Compliant Provisioning with Dynamic Worklow

    100% atomate

    Empoeeie o etie

    Pat wokow base oeest tpe a se attibtes

    Escaatio wokow

    Escaatio wokow

    ......

    ......

    ......

    Oe-cick peetiesimatio

    via e-mai

    100% atomate

    hr eet reest geeatio

    Maage appoa

    risk aasis

    Atomate poisioig

    SAP Oace PeopeSot legac

    10 SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    11/16

    Oce ogaiatios ae competete iitia aasis a impemetecotos to mitigate Sod ioatios apeet citica access isk, it is impea-tie to ae ea-time isibiit ito teai eets tat co impact ogoig

    compiace. As te ees o a bsi-ess eoe, oe eiitios cage,empoees ae pomote, a accesspiieges ae moiie costat.Maagemet caot obtai a ceaiew acoss te etepise to assesscet isk epose om epotsbase o peioic ata owoas.Wat is eee is sotwae tataaes a compaes es aetects potetia isks base o ea-time ata. Witot tis sppot, it is

    iict o bsiess owes to bet accotabe o peetig isk.

    I bsiess maages caot accateeiew a tack access coto cag-es a associate pobems, a ite caot poie compete ecosto aitos, ait costs icease. Ite-a aitos wo ae ace wit spea-seets istig te access a atoia-tios o a empoees ca peom oa e imite ait. Ee i te o cap-te te stats o at oe poit i time

    ig a aa ait, cages to oeso bsiess pocesses ca eetose oes o pocesses ocompiatat a time teeate.

    SAP BsiessObjects Access Cotooes maagemet ea-time access-isk aasis, epotig, a as-boas o icease accac. Maag-es ca peom wat-i simatios topeet access ioatios. Te sotiopoies ctioait aowig maage-

    met to take esposibiit o eectieoesigt o Sod a citica accessisk. Te appicatio ices ea-timeetectio cotos a tasactio-

    sage moitoig to gie aitos tetoos te ee to sta i coto oaccess compiace.

    Management Oversight orBusiness Owner Accountability

    Maages mst coct se accesseiews peioica to ese Sodmitigatios ae eectie. SAPBsiessObjects Access Cotoaows maagemet to eeage ato-mate, pebit epotig to impoe

    isibiit i ie ke access coto aeas:User provisioning reports ispa a

    se access eaimatios aaccess appoas

    Potential risk reports igigt seswit Sod coicts wo ae tepotetia to make mistakes o commita

    Actual risk reports moito tasac-tios to etect we ses eectetasactios tat costitte a Sodioatio

    Policy reporting eiews te Sodes iba a aows maagemetto make pates a cages tobsiess pocesses as eie b

    cages i te egato eio-met, wit maagemet aso abe toeiew mitigatio cotos a assesstei eectieess

    Emergency access reports sowwic empoees ae se spe-se piieges a wat tasks weepeome sig tat access

    reAl-time OverSightIMMEdIATE vISIBIlITy O CurrEnTrISK SITuATIOn

    Figure 3: ContinuousMonitoring o Compli-ance and Access Risk

    11SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    12/16

    SAP BsiessObjects Access Cotoatomates se access eiews,eabig o to eiew te potetiaisks i o ogaiatio a woktowa api esotio. o eampe,o ca peom a isk aasis b se

    a iscoe a mitigate isk tateies attetio. yo ca aso eiewmitigatig cotos a te empoeesassige to moito tem. Te appi-catio aets te appopiate maagewe te moito assige to amitigatio epot oes ot peom teties assige witi te speciietime peio. Acta sage a oesage epots eea we a ioatiooccs, o eampe, we a empo-ee peoms coictig ctios, sc

    as ceatig a ew eo a paig aeo. Te aet sstem aows maag-es to ocs o ig-pioit items aeceptios. repots poie compe-esie eiece o aitos tat miti-gatio meases ae eectie.

    Tis obst epotig gies o tetaspaec tat is eie b eg-atos a aitos, a it gies tecoiece essetia o sccessbsiess maagemet. It oes teeibiit to ioate bsiess pocess-

    es a impoes te poctiit omaages, teeb sigiicat owe-ig te oea cost o compiace.

    Minimized Audit Time and Audit-Related Costs

    SAP BsiessObjects Access Cotoeabes itea a etea aitosto compete compeesie a ei-

    ciet testig to make se a access ispope atoie a tat cotosae i pace a ega teste to miti-gate a Sod isks. Te atomatio bitito te appicatio simpiies te ies-tigatio pocess a eies staa,ait-ea epotig to coim tat aaccess to sstems was pope ato-ie, icig se access appoa aswe as oe appoa. Istea o tigto i maa oms, speaseets,a ies, appoa wokows a a

    oe-cage isto atomaticapoie a ait tai. notiicatios oemegec piiege sage a etaieactiit ogs ae aso aaiabe o ai-tos to tack tis tpe o sage.

    Aitos ca se te appicatio to testo mitigatio eectieess, especiao tose ses wo ae Sod co-icts. Aitos ca test wete iskesciptios a mitigatio cotosmatc a wete te mitigatio isacta eecte.

    SAP BsiessObjects Access Cotoeies immeiate isibiit o tecet isk sitatio o bot maage-met a itea ait pesoe. Teappicatio oes impoe accacwit ea-time epotig a eabesbsiess-owe accotabiit witbit-i eiew a appoa pocesses.

    Integrated Solutions to BuildBusiness Eectiveness

    Te SAP BsiessObjects so-tio potoio ices wo-eaigsotios o bsiess iteigece,iomatio maagemet, ete-pise peomace maagemet,a goeace, isk, a com-piace. Togete, tese sotiospoie a peetatie, ea-timeappoac to goeace, isk, acompiace acoss eteogeeoseiomets, eabig competeisigt, geate eiciec, aimpoe eibiit.

    With SAP BusinessObjects

    Access Control, GRUMA

    is able to achieve 90% faster

    resolution of auditorobservations.

    Ja Caos voa, CIO, GruMA S.A.B.

    e C.v.

  • 8/4/2019 SAP Business Objects Access Control [1]

    13/16

    Obtain Complete Insight, GreaterEiciency, and Improved Flexibility

    SAP BsiessObjects Access Cotois pat o te SAP BsiessObjectsgoeace, isk, a compiace

    (GrC) sotios. Tese sotios po-ie ogaiatios wit a peetatie,ea-time appoac to GrC acosseteogeeos eiomets. Tesotios poie compete isigt itoisk a compiace iitiaties, eabeesoces to be se moe eectie,a aow o a aste espose tocagig bsiess coitios.

    Compete IsigtSAP BsiessObjects GrC sotios

    eabe compete isigt b poiig acommo appoac to isk a compi-ace iitiaties a cotios moi-toig tem so tat bsiess coitiosca be estoo, isks maage, aecisios impoe.

    Geate EiciecSAP BsiessObjects GrC sotiosae esige to eiciet sppot teocmetatio a impemetatio oatomate cotos o a amewok.Atomatio o maa isk a compi-

    ace actiities, compiace atioaia-tio, a pepopate ie-o-bsiessa ist-speciic cotet eabescosts to be ece a esoces tobe se moe eectie. Tis eas toa mc moe eiciet compiaceeiomet.

    Impoe eibiitWokig togete, SAPBsiessObjects GrC sotios po-ie a peetatie, ea-time appoaco o eteogeeos eiomet.Peomace iicatos acoss ag-

    mete coto eiomets aeaggegate to eie a commo,sstem-wie iew a i maage-met o stategic, iacia, opeatioa,a compiace-eate isks acoss teogaiatio. haig a sige statego itea poic a etea ega-tio eabes aste espose to cag-ig bsiess coitios.

    Find Out More

    Te SAP BsiessObjects AccessCoto appicatio eabes o tocoiet coto access a peeta acoss o etepise wie mii-miig te time a cost o compiace.To i ot moe abot ow tis aote SAP BsiessObjects GrC so-tios ca beeit o bsiess, peasecotact o SAP epesetatie oisit s o te Web atwww.sap.com/sapbsiessobjects/gc.

    SAP BuSineSSOBjectS gOvernAnce, riSk,And cOmPliAnce SOlutiOnSPrOACTIvEly BAlAnCE rISK And OPPOrTunITy

    ACrOSS yOur BuSInESS PrOCESS

    13SAP Solution in Detail SAP BsiessObjects Access Coto

    http://www.sap.com/sapbusinessobjects/grchttp://www.sap.com/sapbusinessobjects/grchttp://www.sap.com/sapbusinessobjects/grchttp://www.sap.com/sapbusinessobjects/grc
  • 8/4/2019 SAP Business Objects Access Control [1]

    14/16

    14 SAP Solution in Detail SAP BsiessObjects Access Coto

  • 8/4/2019 SAP Business Objects Access Control [1]

    15/16

  • 8/4/2019 SAP Business Objects Access Control [1]

    16/16

    Quick fActS www.sap.com/contactsap

    50 098 921 (10/04)2010 SAP AG. A igts esee.

    SAP, r/3, SAP netWeae, det, PateEge, Bdesig,

    Cea Etepise, SAP BsiessObjects Epoe, a ote SAPpocts a seices metioe eei as we as tei espectieogos ae taemaks o egistee taemaks o SAP AG iGema a ote coties.

    Bsiess Objects a te Bsiess Objects ogo, BsiessObjects,Csta repots, C sta decisios, Web Iteigece, xcesis, aote Bsiess Objects pocts a seices metioe eeias we as tei espectie ogos ae taemaks o egisteetaemaks o SAP ace i te uite States a i ote coties.

    A ote poct a seice ames metioe ae te taemaks otei espectie compaies. data cotaie i tis ocmet seesiomatioa pposes o. natioa poct specicatios ma a.

    Tese mateias ae sbject to cage witot otice. Tese mateiasae poie b SAP AG a its afiate compaies (SAP Gop)o iomatioa pposes o, witot epesetatio o waat oa ki, a SAP Gop sa ot be iabe o eos o omissios

    wit espect to te mateias. Te o waaties o SAP Goppocts a seices ae tose tat ae set ot i te epess

    waat statemets accompaig sc pocts a seices, ia. notig eei so be coste as costittig a aitioa

    waat.

    SummaryTe SAP BsiessObjects Access Coto appicatio eabes bsiess maages,IT secit, a aitos to coaboate i cotoig access a peetig a acosste etepise. Te sotwae eps steamie pocesses a estabis cotos to maitaisegegatio o ties (Sod), miimie citica access isk, a assig compiat seaccess, wie miimiig ait time a ait-eate costs.

    Business Challenges Maage iese, appicabe egato eiemets rece ait a compiace costs case b maa pocesses Maitai a ope IT iastcte wie mitigatig Sod isks Impoe coaboatio betwee IT a bsiess maages

    Key FeaturesSoD rules library leeage best pactices a SAP epetise o bsiess pocesses Automated worklows Icease eiciec a coaboatio betwee IT a bsiess

    owes What-i simulations deie compiat oes poactie sig peetie simatios Reporting Impoe isibiit o se poisioig, potetia a acta isk, poic

    epotig, a spese access

    Business BeneftsReduced risk o raud b sppotig te ceatio o compiat bsiess pocesses Reduced SoD violations a citica access isk acoss SAP a o-SAP sotwae

    tog isibiit o te cet isk sitatio base o ea-time ata Minimized time to comply with regulatory requirements b atomatig te etectio o

    access isk Minimized audit time and audit-related costs tog atomate ait tais, ea-time

    etectio cotos, a tasactio moitoig Improved visibility o current risk situation tog ea-time epotig

    For More InormationTo i ot moe abot ow SAP BsiessObjects Access Coto a ote SAPBsiessObjects goeace, isk, a compiace sotios ca beeit o bsiess,pease cotact o SAP epesetatie o isit s at

    www.sap.com/sapbsiessobjects/gc.