<output id="qn6qe"></output>

    1. <output id="qn6qe"><tt id="qn6qe"></tt></output>
    2. <strike id="qn6qe"></strike>

      亚洲 日本 欧洲 欧美 视频,日韩中文字幕有码av,一本一道av中文字幕无码,国产线播放免费人成视频播放,人妻少妇偷人无码视频,日夜啪啪一区二区三区,国产尤物精品自在拍视频首页,久热这里只有精品12

      Security Design for SAP GRC

      Security Design for SAP GRC

      • Security Roles are functional buckets of authorizations generally divided by: Functional Process (Sales Order Processing), Authorization level Information:
        • Org Level Restrictions (Location: Company Code, Plant, Sales Org., etc) (Auth Object)
        • Object level restrictions (Functional: Accounting Document, Sales Order Type, Movement Type, etc) (Auth Object)
        • Activity Level restriction of needed... Display / Maintain / Approve type authorizations
      • What a user should or should not be able to do can be guided by the security team, but the ultimate decisions are defined by the Business with assistance by the functional / change management teams and

      image-20240613161924198

      image-20240613163621166

      Security Design: What to do with the Requirements?

      • Perform iterations of reviews and analysis to finalize functional design
      • Level of Design: Process Role --> Business Role
      • Ensure COMPLETENESS of Transaction Inventory!
      • Ensure functional accuracy
      Business Role Security Role Transaction Transaction Description
      Branch Manager AmEx Extract ZAMEX Credit Cart Payment
      Consingment Maintenance VA01 Create Sales Order
      VA002 Change Sales Order
      Create Standard Order/Quot VA01 Create Sales Order

      With the T_Code data available, map the functional requirements to the SAP technical (delivered) requirements to obtain data restriction (authorization checks) at the T_Code level.

      • MS Access / Any Database
      • ABAP Program
      Table Description
      USOBT_C Relation Transaction to Auth. Object (Customer)
      TSTC SAP Transaction Codes
      TOBJ Authorization Objects
      AGR_1251 Authorization data for the activity group

      Gohil-Woo-Part-2-image1

      Security Design: ECC Requirement Gathering

      Consider Data Restrictions!!!

      Completion of Values for Data Restriction:

      -Organization Values

      • Sales Org
      • Sales Office
      • etc

      -Functional Values

      • Document Type
      • etc
      Business Role Security Role Transaction Transaction Description Authorization Authorization Description Values
      Branch Manager AmEx Extract ZAMEX Credit Card Payment In ZOM_VBKA Authorization Object for Sales org. and Sales Office Each Sales Office
      Consignment Maintenance VA01 Create Sales Order B_USERST_T Status Management: Set/Delete User Status using Transaction
      B_USERSTAT Status Management: Set/Delete User Status
      C_TCLS_BER Authorization for Org. Areas in Classification System
      C_TCLS_MNT Authorization for Characteristics of Org. Area
      K_CKBS CO-PC: Product Costing
      K_KEA_TC Profitability Analysis: Maintain Operating Concerns
      V_VBAK_AAT Sales Document: Authorization for Sales Document Types
      V_VBAK_VKO Sales Document: Authorization for Sales Areas
      VA02 Change Sales Order B_USERST_T Status Management: Set/Delete User Status using Transaction
      B_USERSTAT Status Management: Set/Delete User Status
      C_TCLS_BER Authorization for Org. Areas in Classification System
      C_TCLS_MNT Authorization for Characteristics of Org. Area
      K_CKBS CO-PC: Product Costing
      K_KEA_TC Profitability Analysis: Maintain Operating Concerns
      V_VBAK_AAT Sales Document: Authorization for Sales Document Types
      V_VBAK_VKO Sales Document: Authorization for Sales Areas
      Create Standard Order/Quot VA01 Create Sales Order B_USERST_T Status Management: Set/Delete User Status using Transaction
      B_USERSTAT Status Management: Set/Delete User Status
      C_TCLS_BER Authorization for Org. Areas in Classification System

      image-20240615140741130

      Security Design: MDM - Requirement Gathering

      MDM uses Functions and Tables/Fields To define functional requirements for access.

      Function - determine what kind of access (delivered)

      Tables/Fields - determine restriction on access (configuration)

      image-20240615141550920

      Access Risk Analysis - ARA

      • SoD checks for clean security design
      • Clean user to role mapping for go-live

      Business Role Management - BRM

      • Not efficient in project mode "Role Build" effort due to complexity of workflow requirement

      Access Request Management - ARM

      • Ability to be used for project provisioning but restrictions exist

      Emergency Access Management - EAM

      • FF logging not required in Non-Production Systems

      image-20240615142346374

      Getting Compliant

      image-20240615143749982

      Staying Compliant

      image-20240615145612960

      Access Risk Analysis - ASA

      • SoD reporting
      • Mitigating control repository

      Business Role Management - BRM

      • Ensure compliant role maintenance
      • Documentation repository for approvals, testing, SoD checks

      Access Request Management - ARM

      • Ensure compliant end-user security
      • Audit trail of approvals, SoD checks, Auto-provisioning

      Emergency Access Management - EAM

      • Superuser activity logging and reporting

      image-20240615145936843

      References

      https://tcblog.protiviti.com/2021/10/13/where-to-start-modernizing-sap-access-governance-with-grc-12-0-fiori-capabilities-part-2/

      posted @ 2024-12-08 09:16  晨風_Eric  閱讀(5)  評論(0)    收藏  舉報
      主站蜘蛛池模板: AV人摸人人人澡人人超碰| 好吊视频一区二区三区人妖 | 国产一区二区不卡自拍| 亚洲少妇人妻无码视频| 亚洲欧美综合在线天堂| 亚洲成a∨人片在线观看不卡| 18禁极品一区二区三区| 中文字幕在线国产精品| 色噜噜亚洲精品中文字幕| 一区二区三区在线 | 欧洲| 国模肉肉视频一区二区三区| 欧美日韩国产图片区一区| 热久在线免费观看视频 | 国产成人精品亚洲资源| 精品乱码一区内射人妻无码| 国产一区二区不卡精品视频| 久久久久久综合网天天| 与子敌伦刺激对白播放| 女同在线观看亚洲国产精品| 色婷婷日日躁夜夜躁| 亚洲丶国产丶欧美一区二区三区| 国产av无码国产av毛片| 国产精品一二三中文字幕| 午夜福利偷拍国语对白| 精品无码久久久久国产电影| 亚洲精品第一区二区在线| 日本极品少妇videossexhd| 久久99精品久久久久麻豆| 高清破外女出血AV毛片| 国产成人无码性教育视频| 国产女人叫床高潮大片| 99久久99这里只有免费费精品| 国产对白叫床清晰在线播放| 爆乳喷奶水无码正在播放| 干中文字幕| 久久国产乱子伦免费精品无码| 九九热精品在线观看| 欧美日韩性高爱潮视频| 亚洲爆乳WWW无码专区| 99国产精品永久免费视频| 国产精品美女网站|