|
1 year ago ::
Mar 13, 2012 - 11:37AM
#1
|
|
|
Compliance Forum March 27 on Access Control 10.0
Practical tips for implementing - and integrating - the 4 components of Access Control 10.0: Q&A with SAP GRC expert Simon Persin You have various deployment options for the 4 individual components of SAP BusinessObjects Access Control 10.0. But there are also powerful integration options for risk analysis (RAR), user provisioning (CUP), role management (ERM), and super user management (SPM). How can you fully optimize Access Control for your organization? Post your questions in an exclusive one-hour online Q&A with expert, consultant, and GRC 2012 speaker Simon Persin of Turnkey Consulting, Tuesday, March 27 at 11am-12pm EDT here in the Compliance Forum. To post your question, first log in to Insider Learning Network, and select the “Post Reply” button below. Simon will respond to your questions with his own posts in the forum March 27 from 11am -12 pm EDT. Be sure to refresh your browser to view the latest questions. If you haven't registered for this Q&A, you can still register now to receive the Access Control performance checklist download from Simon Persin’s GRC 2011 session “An Expert Guide to Access Control Performance Optimization”. (Look for the download link in your confirmation email.) Note: To participate in this exclusive live Q&A you must be a member of Insider Learning Network - join today for free. Moderated by Allison Martin, conference producer for GRC 2012
Sponsored by GRC 2012 - Milan June 6-8 
Moderated by
Forum Moderator
on Mar 28, 2012 - 11:48AM
|
|
|
|
1 year ago ::
Mar 22, 2012 - 6:21PM
#2
|
|
|
Hi Simon, What would be the secuence and frecuency recommended to run the ABAP jobs (programs: GRAC_REPOSITORY_OBJECT_SYNC and GRAC_BATCH_RISK_ANALYSIS), that update the Reports & Analytics results in SAP GRC Access Control 10.0 for Access Management? Best regards, Perla S.
|
|
|
|
1 year ago ::
Mar 26, 2012 - 4:17AM
#3
|
|
|
Hi Simon.
- Which one has less efforts and lest risk, upgrade from GRC 5.2 to GRC.10.0 or easier to do fresh installation?
- If we have to fresh installation, can we export the configuration from 5.2 and put into GRC 10.0.
Cheers. Sandy
|
|
|
|
1 year ago ::
Mar 27, 2012 - 10:59AM
#4
|
|
|
Q: Can role assignment conflicts be identified during Risk Analysis and Remediation or only in Compliant User Provisioning. If possible in RAR, how ?
|
|
|
|
1 year ago ::
Mar 27, 2012 - 10:59AM
#5
|
|
|
Welcome to today's forum on Access Control 10.0 with Simon Persin of Turnkey Consulting. Simon is a featured speaker at GRC 2012 in Milan, coming up June 6-8, and will be presenting a session on today’s topic: Integrating & implementing the 4 components of SAP BusinessObjects Access Control 10.0. To post your question, simply hit the “Post Reply” button, and refresh your browser periodically to see the latest posts. This is an opportunity to ask your questions about Access Control 10.0, its functionality, and how to integrate this functionality for optimal security and controls in your SAP systems. Welcome, Simon, and thank you for joining us today! I know there are already some questions posted for you, so we can get started.
|
|
|
|
1 year ago ::
Mar 27, 2012 - 10:59AM
#6
|
|
|
Simon, What's your best practice on updating the ruleset? Of course you can perform this when using the transaction NWBC, but what's your best practice when performing mass maintenance? And if you use upload functionality (like in 5.3) how can you make sure that the upload is done for the correct system (logical / physical) Regards, Jurgen.
|
|
|
|
1 year ago ::
Mar 27, 2012 - 11:01AM
#7
|
|
|
Hi Simon,
What would be the secuence and frecuency recommended to run the ABAP jobs (programs: GRAC_REPOSITORY_OBJECT_SYNC and GRAC_BATCH_RISK_ANALYSIS), that update the Reports & Analytics results in SAP GRC Access Control 10.0 for Access Management?
Best regards,
Perla S.
Hi Perla, With the synchronisation jobs, I would tend to have them all as scheduled periodic background jobs and would suggest the following frequency: Authorisation Sync – Perhaps weekly or even less frequently depending on the volume of changes to the core authorisations in the Target system Repository Object sync – Hourly Action usage – Daily Role usage – Daily I would then run an incremental Batch Risk Analysis on a daily basis after the jobs above. I would also recommend a monthly or weekly full sync to make sure that everything is up to date (ideally outside of core business hours). Simon
|
|
|
|
1 year ago ::
Mar 27, 2012 - 11:05AM
#8
|
|
|
Hi Simon.
- Which one has less efforts and lest risk, upgrade from GRC 5.2 to GRC.10.0 or easier to do fresh installation?
- If we have to fresh installation, can we export the configuration from 5.2 and put into GRC 10.0.
Cheers.
Sandy
Hi Sandy, The official line is that there is no direct upgrade / migration path from 5.2 to 10. You will need to upgrade to 5.3 first and then do the migration of data across. To be honest, with the significant technical shift, you spend almost as much time validating and revalidating the migration that I think that its easier to think of it as a re-implementation with some accellerators on the ruleset front. I'm not actually sure that exporting and importing the configuration is of much value since you'll more often want to re-assess the key design decisions anyway. Especially with workflow, I would re-implement it directly within GRC 10. Simon
|
|
|
|
1 year ago ::
Mar 27, 2012 - 11:07AM
#9
|
|
|
Simon, In GRC 10, is there any restriction in number of SOD rule within a risk as like in GRC 5.3?
|
|
|
|
1 year ago ::
Mar 27, 2012 - 11:09AM
#10
|
|
|
Q: Can role assignment conflicts be identified during Risk Analysis and Remediation or only in Compliant User Provisioning. If possible in RAR, how ?
Hi, You can run risk analysis at numerous levels: the organisation unit; Profile level; role level; and user level. These reports are all in RAR or ARA as it's now identified. If you want the role assignment conflicts, I would lean towards user level analysis as that will advise you on the conflicts arising between roles. You can also simulate potential risks from changes to roles or users as well. Using the access request management (GRC10's CUP module) you can assess the impacts as an integrated check in the request process.
|
|
|