Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: SAP R3 User Access Management Best Practices

06/06/07

Permalink 07:26:24 am, Categories: SAP R/3, SAP BW, 192 words   English (US)

SAP R3 User Access Management Best Practices

Managing user access is critical in any IT environment. Companyies which have implemented SAP need to be aware of risks which inappropriate user access poses. Authorization objects like SAP_ALL which provide users with increased access should be removed. Similarly, IT personnel should never be allowed access to the production environment where they can change or delete business data. Though the profile generator is an excellent way of granting access, it should be complimented with periodic reviews of user access, and segregation of duties.

SAP comes with lots of pre-delivered roles however, these shipped roles do not in may cases meet the SOD requirements in wake of laws like the sarbanes oxley. One of the best ways for SAP user access management is to create strong processes for adding, changing and deleting users. This process should include communication of user access changes to HR also. User validity should be restricted by configuring validity periods. All said and done, one should keep the principal of least privileged and "need to know-do" while granting users' access.

Related Posts

SAP R/3 Inherent Controls
SAP R/3 Configurable Controls
Securing SAP* User ID
SAP IMG Implementation Guide

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

September 2008
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Misc

Syndicate this blog XML

What is RSS?