Preventative ongoing maintenance and monitoring of your users’ SAP security access is critical to avoiding significant deficiencies or control weaknesses. A governance, risk, and compliance (GRC) tool (such as SAP GRC, Control Panel, ComplianceNow, ERP Maestro) is a great start, but there is more to monitor! System parameters and client settings are also part of your audit but are outside the monitoring scope of most GRC applications.
Regular security health checks are key to (1) identifying these access issues before they spiral out of control, (2) mitigating the risk from control deficiencies, and (3) ensuring your security administrators are following best practices. In an SAP environment, security health checks are periodic assessments of key application-layer ITGC controls related to user access. They should cover sensitive access monitoring, general access monitoring, and mitigating control assignment, as well as any other ITGC controls your external auditor may assess.
If you have a GRC application, you likely have a control policy that states all user access rights originate from the tool and follow an approval process. A health check ensures that any access assignment deviation is identified, investigated, and documented for its inevitable discovery during your audit. For example:
There are limitations to what controls a GRC tool can monitor. Health checks help your organization close that gap. Any change should be well documented, reviewed, and executed according to your change management process. These include:
Health checks assess whether your security administrators are following industry best practices. While best practices are not audit related, your organization will maintain efficiency and lower control costs by following them. Irregularities should be identified and remedied. This review should include:
An SAP security health check should be well documented and provide your organization with a prioritized list of issues and the actions that should be taken to remediate them. For example:
Key:
Health checks should be a routine part of your SAP security monitoring efforts. When performed frequently and consistently, they provide critical insights into your SAP access security. Focal Point specializes in helping companies improve their SAP security through a wide range of SAP-specific services, including security health checks. To learn more about our services, contact one of our SAP security specialists.
Subscribe to Focal Point's Risk Rundown below - a once-a-month newsletter with templates, webinars, interesting white papers, and news you may have missed. Thousands of your colleagues and competitors have signed up! You can unsubscribe at any time.