Audit of User Management Process with SAP Security

Nov 6
07:39

2014

Attia Kiran

Attia Kiran

  • Share this article on Facebook
  • Share this article on Twitter
  • Share this article on Linkedin

One of the primary building block in SAP Security is granting proper access to user within the SAP software, with rights to perform transaction which will execute specific type of functions in the system. The primary objective to perform an audit on an implemented SAP system is to cross check the process of approval, used to add users in the system and also approval for changing accessibility of a particular user.

mediaimage

SAP Security Audit

One of the primary building block in SAP Security is granting proper access to user within the SAP software,Audit of User Management Process with SAP Security Articles with rights to perform transaction which will execute specific type of functions in the system. SAP Role provides access for transaction which provides a direct access for the system. Traditionally when a SAP solution is implemented in a company, the company will always ascertain number of employees and will straightaway group their set of tasks into specific jobs. After this their role will be built based on their job functionality.

SAP Security Audit for user approval process

The primary objective to perform an audit on an implemented SAP system is to cross check the process of approval, used to add users in the system and also approval for changing accessibility of a particular user. This whole process could be completely automated or manual. However if there is an external audit team they would definitely like to have a visibility on the complete process. They would also confirm user creation process in the system has proper approval or not.

SAP Security audit for qualifying the users:

This process involves identifying training requirements by the audit team before a particular user granted access to the system. A professional training could be provided in this regard, apart from providing training completely based on prior experience. Auditors may also look at the training completion documentation which will be verified by them ,and this is considered as one of the important aspects.

SAP Security Audit for Removing the Users from the system:

There will be many users who would be inactive due to attrition or limited access, and their removal or locking would be necessary, the sap security audit oversees this whole process of removal. Most of the companies have a policy in place for inactive users, where it will lock those accounts if it is not used for certain number of days. Typically it is between 60 to 180 days. The auditors examines this threshold and check the level of consistency of following this process. The process might be as simple as completely lock the user or deletion from the system after acquiring proper approvals to effect the change. There might be a different aspect to this as well where either the employee leaves or he might move to a different job role in the same company, but that doesn’t require an access to SAP. The auditors will definitely make a proper identification of inactive users who have been removed completely in the HR records or might be working in a different job role, they will also identify the affected change in the SAP system. Auditors will examine the respective changes and will also check the necessary authorizations for these changes.

SAP User Validation Process:

In this process auditors will check the validation process of the users, and will also confirm whether those users are still required to access SAP system or not. Also there is a requirement in SAP security process which requires review at regular intervals of user access by a dedicated process owner or a supervisor. They have to confirm the given access is still valid. This review can be done yearly as well as quarterly, however it is entirely based on company’s policies.

 

 

 

Also From This Author

Computer Software Training for your life

Computer Software Training for your life

With the advent of IT in every field of life, it has become unavoidable for everyone to learn computer technology to some extent. Learning computer software education through online courses is a very simple task.Give a serious thought on what you exactly want to learn and then select the best software provider with reasonable rates.
An Overview of Data Mining

An Overview of Data Mining

Extracting the predictive patterns and relevant information from a huge data is termed as Data Mining. It helps in acquiring patterns that contribute to decision making.There are various information mining (DM) methods and the kind of information being analyzed firmly impacts the sort of information mining system utilized. Bunching alludes to the arrangement of information bunches that are gathered together by some kind of relationship that recognizes that information as being comparative.
General Ledger Accounting in SAP FICO

General Ledger Accounting in SAP FICO

General ledger accounting is normally used for comprehensive picture of external financial report. It a known fact that from general ledger every financial statement of an organization is prepared.All definitions of general ledger are placed in charts of accounts in an organized array and every general ledger is organized and prepared according to charts of accounts.While we work world wide we have to follow the rules of that country in which we are working. It means that country specific charts of account are country dependent. It is optional part depending upon the business you have.