Advice needed: what does your company log for SAP security role changes?

My client has a situation where for many years, they never logged changes to SAP security roles.  By that I mean, they never logged even basic details, like who requested a change, tested it, approved it, and what changed!!  Sadly their ticketing system is terrible, completely free-form text and not even searchable. 
Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details?   What details do you capture?  What about Projects, that involve dozens of changes and testing over several months?
I plan to recommend, at least, they need to use a unique# (a ticket#, or whatever) for every change and update the same in PFCG role desc tab, plus in CTS description of transports... but what about other details, since they have a bad ticketing system?  I spoke with internal audit and change Mgmnt "manager" about it, and they are clueless and will not make recommendations.  It's really weird but they will get into big trouble eventually without any logs for security changes!

Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details? What details do you capture? What about Projects, that involve dozens of changes and testing over several months?
I have questions:
a) Do you want to make things straight
b) Do you want to implement a versioning mechanism
c) You cannot implement anything technical, but you`re asking about best "paper" practise?
The mentioned scenarios can be well maintained if you use SAP GRC Solutions 10 (Business Role Management)
Task Based, Approvals, Risk Analysis, SOD and role generation and maintenance in a structured way (Business Role Management). Workflow based, staged process with approvals.
PFCG transaction usage will be curtailed to minimum if implemented fully.
Do we really want to do things "outside" PFCG?
@all:
a) do you guys use custom approval workflows for roles?
b) how tight your processes are? how much paperwork, workflow, tickets, requests and incidents you have to go through to change a role?
c) who is a friend of GRC here, raise your hand
Cheers Otto
p.s.: very interesting discussion, I would like to learn something here about how it works out there in the wild

Similar Messages

  • 1099misc processing and corrections - How does your company deal with it

    When we went live with SAP, we implemented a hybrid, SAP and in-house developed solution to handle the 1099misc reporting and corrections process. 
    We run a Z version of RFW1099M program to produce our initial file for 1099misc reporting
    We run a home grown program that takes in the file produced by our Z version of RFW1099M and any other miscelleneous  files that we need to bring in for 1099misc and we produce the first cut of  the 1099misc SMART forms (we don't use the same form that SAP has as standard as we produce a pressure sealed one) and a 'final' file to go to the IRS.
    This home grown program also allows us to modify the 'final' file to produce corrected 1099s. 
    The issue that we have going forward is that there are IRS changes for 2009 that require changes to the way 1099Misc corrections are reported.  I have ideas about how we can change our home grown process, but was wondering how everyone else deals with the process?
    Why doesn't SAP have a comprehensive, integrated solution to 1099M reporting?  What does your company do?
    Thanks for your help in advance.
    Marianne

    Hi Marianne,
    Report RFW1099M is fully compliant with requirements of IRS. Please also note that if you are on release 470 or higher you should use report RFIDYYWT instead of report RFW1099M, as SAP only supports report  RFW1099M in releases 46C and lower.
    with kind regards
    Cora

  • Sync message, "You have changed the settings for your iphone.  Would you like to apply these changes?" What does this mean?  I don't recall changing anything...

    Sync message, "You have changed the settings for your iphone.  Would you like to apply these changes?" What does this mean?  I don't recall changing anything...

    The main settings that are changed in these cases can be found in this article:
    http://support.apple.com/kb/ht1386
    To ensure you don't lose any data you don't want taken off, ensure that each Summary, Apps, Music, Movies, TV Shows, Podcasts, iTunes U, Books, & Photos have the settings you would prefer on the computer. 
    If anything gets changed on any of those pages, you will be prompted with that message.  If they look fine, especially after adding some media like songs or videos, then you can apply the changes without fear.

  • What does Apple mean by "For best battery performance, leave your device connected to a power source until the restore is complete."

    I just recently returned an IPad air and exchanged it for another. I first set up this new one as a new IPad but then deleted all content and settings right away (since I wasn't getting the progress I had made in apps and games) in order to restore it from my previous IPad Air. I then checked after on how to backup via icloud and saw this line under the subtitle of how to restore from a backup, "For best battery performance, leave your device connected to a power source until the restore is complete." What does Apple mean by "for best battery performance"? Im just a bit worried of issues.
    p.s. And yes I did have it connected to the power. And the ios is the default ios for new IPad Airs.

    Welcome to the Apple Community.
    It only means you should restore whilst it is connected to a power supply, so that your battery doesn't go flat during the process.

  • Does your iPhone disable for 24 hours when failing a few times to enter your passcode?

    Does your iPhone disable for 24 hours when failing a few times to enter your passcode?

    Hello Hayema0,
    After reviewing your post, I have located an article that can help with iOS passcodes. It contains a number of troubleshooting steps and helpful advice for the issue you are experiencing:
    About iOS passcodes - Apple Support
    Forget your passcode?
    If you or someone else enters the wrong passcode too many times, your device will disable itself temporarily. Get help if you forgot your passcode or your device is disabled.
    Learn what to do if you forgot your Restrictions passcode.
    Thank you for contributing to Apple Support Communities.
    Cheers,
    BobbyD

  • What does the "s" stand for in iPhone4s

    What does the "s" stand for in iPhone4s??

    Yes, that is correct. There is no right answer 100%. I don't really know how to explain it. But you have to see where I am coming from. I guess you can think about it like this. S is a word. The word was defined as speed 2 years ago. Now it is being used again. Since S was already defined it does not need to be defined again. It just makes sense that apple would be consistent in their product names.
    But that isn't what they said. They said "that's the probmlem i'm having with people saying its siri.." In other words, that's why I am not so sure siri is the correct answer. They are just curious, that's all. If someone said, "The iPhone is to die for" would you think they would actually die for an iPhone? Like I said, just relax. You don't need to go attack people by saying that they need mental help when they are just curious about something.
    However, you are entitled to your opinion. I have presented my case and you seem to be getting pretty upset over my comments so I think this whole thing should be let go. There are plenty of posts here for the OP to make a decision for themselves and if he/she needs more clarification he/she will ask.

  • What does it WF_EVENT_OJMSTEXT_QH use for?

    Dear all:
    I found the error in the alert_log:
    *** 2010-08-05 16:13:26.608
    *** SESSION ID:(572.533) 2010-08-05 16:13:26.608
    Exception signal: 11 (SIGSEGV), code: 1 (Address not mapped to object), addr: 0x2a96b75000, PC: [0x10efcdf, kdkbin()+223]
    *** 2010-08-05 16:13:26.612
    ksedmp: internal or fatal error
    ORA-07445: exception encountered: core dump [kdkbin()+223] [SIGSEGV] [Address not mapped to object] [0x2A96B75000] [] []
    Current SQL statement for this session:
    begin WF_EVENT_OJMSTEXT_QH.enqueue(:v1, :v2); end;
    ----- PL/SQL Call Stack -----
      object      line  object
      handle    number  name
    0x2d3fda4a8       204  package body SYS.DBMS_AQ
    0x2edfb5e38       980  package body APPS.WF_EVENT_OJMSTEXT_QH
    0x2edfbecf8         1  anonymous block
    0x2ebc2ddb8      1720  package body APPS.WF_EVENT
    0x2ebc2ddb8       668  package body APPS.WF_EVENT
    0x2ea538c30       229  package body APPS.WF_RULE
    0x2ed36d538        31  package body APPS.FND_BES_PROC
    0x2ed374d60         1  anonymous block
    0x2ebc2ddb8       443  package body APPS.WF_EVENT
    0x2ebc2ddb8      1599  package body APPS.WF_EVENT
    0x2ebc2ddb8      2372  package body APPS.WF_EVENT
    0x2ebc2ddb8       700  package body APPS.WF_EVENT
    0x2ed39d3a0      4990  package body APPS.FND_FLEX_SERVER
    0x2efd60840         3  anonymous block
    ----- Call Stack Trace -----
    I've been raised the SR for this case ,and also install the Patch 6047085, the issue still happened. The ORACLE ask me: what kind of object this is, what is the owner etc? How is this object called? Can someone can tell me what does the WF_EVENT_OJMSTEXT_QH use for? or any article to introduce it?
    my environment : ebs 11.5.9
    database : oracle 9.2.0.8 64bit
    platform: linux redhat 4.0
    Regards
    Terry

    Hi Srini:
    Thank you for your reply.
    Not sure why Support is asking you about this object - they should be the one providing you the answers ;-)-- I feel confused too. This issue last for one month and still have no idea for this case.
    Pl see if MOS Doc 1073171.1 (ORA-7445 [kdkbin()+223] on Linux x86-64 platforms on 9i release) is relevant in your case.--- I've been apply the patch, but no help.
    Regards
    Terry

  • What does your account type does not support the view account feature mean?

    What does your account type does not support the view account feature mean?

    In reference to what? Where are you seeing this message - iTunes? Do you use a credit card for purchases in iTunes or do you download only free content?

  • What does "Your Creative Cloud membership has transitioned from Paid to Free" mean?

    What does "Your Creative Cloud membership has transitioned from Paid to Free" mean?

    Hi Don
    As you've cancelled your paid membership you will continue to have access until June 28th.  After that you will only have access to certain services associated with the free level of membership.
    Please check the FAQ for further details: Adobe Creative Cloud – FAQ
    Thanks
    Bev

  • What does symbol ! stand for in the following code?

    What does symbol *!* stand for in the following code? What does SYSTEM mean?
    <! DOCTYPE report-group SYSTEM "report-group.dtd">
    Edited by: user11337968 on Jul 3, 2009 4:53 PM

    It is just part of the XML specification; to do a "doctype", you must have an open angle bracket followed by an exclamation point. See [doctype decl | http://www.w3.org/TR/REC-xml/#NT-doctypedecl] for more information.
    Peace,
    Cameron Purdy | Oracle Coherence

  • ACR 4.4, ACR 3.3...What does the "ACR" stand for ?

    In the Camera Calibration tab in Camera Raw or Lightroom, we can choose the profile from the menu.
    There are so many profiles in the menu, ACR 4.4, ACR 3.3...What does the "ACR" stand for ?

    ACR x.x designates an older style of profile where Adobe named their profiles for the version of Adobe Camera RAW that first supported the camera--basically the vintage of the profile, so if Adobe updated the profile then you'd be able to pick whether you wanted the old one or the new one.

  • What does the owner use for?

    What does the owner use for?
    owner such as those found in:
    JWindow(Frame owner)
    JWindow(Window owner)
    and more.

    ah... i'm creating a splash with a JWindow and set it with a no owner and it shows the splash then proceed to the showing of the gui is it ok? or will there be problems?

  • HT4623 what does the mm stand for on my model of ipad mini?

    what does the mm stand for on my model of my ipad mini that is also cellulat?

    Copied from another discussion, from Phil0124
    The MM or Millenium Media according to what I can find, refers to the CDMA variation of the Cellular iPad for Verizon Networks.
    The non MM version is for GSM carriers like AT&T.
    https://discussions.apple.com/thread/5093889?start=0&tstart=0

  • HT201471 What does the (MM) stand for ie  wi-fi+cellular(MM)?

    What does the (MM) stand for ie:wi-fi+cellular (MM)?

    I don't know what the "MM" stands for specifically, but those are the CDMA models, A1455 for the mini and A1460 for the 4th-gen iPad Retina.
    Regards.

  • What does the "1" stand for on the Aperture Icon?

    A 3.4  What does the "1" stand for on the Aperture Icon?

    As far as I see, the red number shows that the recipient has accepted the stream.  If you delet the stream the red number is gone.
    I am not sure -this may be a coincidence: Yesterday I saw the red number "1" appear everytime I received a notification when a comment was added to one of the images I posted. When I read the comment, the number went away. The number is gone now, but I still have the stream.

Maybe you are looking for

  • I have to save as CMYK for print, but the colours are out of whack..

    hey all, I am designing something for a CD cover that is going to be printed at a print shop, They say they want their images in CMYK and prefer it in a PDF or highest quality JPEG.... So I have been working in CMYK, everything looks fine in photosho

  • EZXS88w prints garbage

    I replaced a 4 por router with a 8 port  EZXS88w  switch.   My HP injet works fine. My Brother HL 1440 prints graphics, but text is all jibberish. Thanks 4 all help received.

  • Changing Header

    In swing application , there is a cofee symbol in the header , I want to hide that symbol or replace it with another my own symbol , can anybody tell me how can I do this ????? Thanks

  • BUG in ThreadLocal Example

    Hi, I just spot a bug in ThreadLocal example demonstrated in the JAVA API doc. here is the code snippet: public class UniqueThreadIdGenerator {           private static final AtomicInteger uniqueId = new AtomicInteger(0); private static final ThreadL

  • IPod Touch "Two-Way Sync"

    I am pleased to report that I just returned from a month-long trip throughout Europe and my iPod touch worked like a charm. I bought it prior to departing to use it for mobile internet access as I new I would find WiFi-enabled places everywhere. It e