Advice needed: what does your company log for SAP security role changes?
My client has a situation where for many years, they never logged changes to SAP security roles. By that I mean, they never logged even basic details, like who requested a change, tested it, approved it, and what changed!! Sadly their ticketing system is terrible, completely free-form text and not even searchable.
Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details? What details do you capture? What about Projects, that involve dozens of changes and testing over several months?
I plan to recommend, at least, they need to use a unique# (a ticket#, or whatever) for every change and update the same in PFCG role desc tab, plus in CTS description of transports... but what about other details, since they have a bad ticketing system? I spoke with internal audit and change Mgmnt "manager" about it, and they are clueless and will not make recommendations. It's really weird but they will get into big trouble eventually without any logs for security changes!
Does anyone here use Word docs, Excel sheets, or some other way to capture security role change details? What details do you capture? What about Projects, that involve dozens of changes and testing over several months?
I have questions:
a) Do you want to make things straight
b) Do you want to implement a versioning mechanism
c) You cannot implement anything technical, but you`re asking about best "paper" practise?
The mentioned scenarios can be well maintained if you use SAP GRC Solutions 10 (Business Role Management)
Task Based, Approvals, Risk Analysis, SOD and role generation and maintenance in a structured way (Business Role Management). Workflow based, staged process with approvals.
PFCG transaction usage will be curtailed to minimum if implemented fully.
Do we really want to do things "outside" PFCG?
@all:
a) do you guys use custom approval workflows for roles?
b) how tight your processes are? how much paperwork, workflow, tickets, requests and incidents you have to go through to change a role?
c) who is a friend of GRC here, raise your hand
Cheers Otto
p.s.: very interesting discussion, I would like to learn something here about how it works out there in the wild
Similar Messages
-
1099misc processing and corrections - How does your company deal with it
When we went live with SAP, we implemented a hybrid, SAP and in-house developed solution to handle the 1099misc reporting and corrections process.
We run a Z version of RFW1099M program to produce our initial file for 1099misc reporting
We run a home grown program that takes in the file produced by our Z version of RFW1099M and any other miscelleneous files that we need to bring in for 1099misc and we produce the first cut of the 1099misc SMART forms (we don't use the same form that SAP has as standard as we produce a pressure sealed one) and a 'final' file to go to the IRS.
This home grown program also allows us to modify the 'final' file to produce corrected 1099s.
The issue that we have going forward is that there are IRS changes for 2009 that require changes to the way 1099Misc corrections are reported. I have ideas about how we can change our home grown process, but was wondering how everyone else deals with the process?
Why doesn't SAP have a comprehensive, integrated solution to 1099M reporting? What does your company do?
Thanks for your help in advance.
MarianneHi Marianne,
Report RFW1099M is fully compliant with requirements of IRS. Please also note that if you are on release 470 or higher you should use report RFIDYYWT instead of report RFW1099M, as SAP only supports report RFW1099M in releases 46C and lower.
with kind regards
Cora -
Sync message, "You have changed the settings for your iphone. Would you like to apply these changes?" What does this mean? I don't recall changing anything...
The main settings that are changed in these cases can be found in this article:
http://support.apple.com/kb/ht1386
To ensure you don't lose any data you don't want taken off, ensure that each Summary, Apps, Music, Movies, TV Shows, Podcasts, iTunes U, Books, & Photos have the settings you would prefer on the computer.
If anything gets changed on any of those pages, you will be prompted with that message. If they look fine, especially after adding some media like songs or videos, then you can apply the changes without fear. -
I just recently returned an IPad air and exchanged it for another. I first set up this new one as a new IPad but then deleted all content and settings right away (since I wasn't getting the progress I had made in apps and games) in order to restore it from my previous IPad Air. I then checked after on how to backup via icloud and saw this line under the subtitle of how to restore from a backup, "For best battery performance, leave your device connected to a power source until the restore is complete." What does Apple mean by "for best battery performance"? Im just a bit worried of issues.
p.s. And yes I did have it connected to the power. And the ios is the default ios for new IPad Airs.Welcome to the Apple Community.
It only means you should restore whilst it is connected to a power supply, so that your battery doesn't go flat during the process. -
Does your iPhone disable for 24 hours when failing a few times to enter your passcode?
Does your iPhone disable for 24 hours when failing a few times to enter your passcode?
Hello Hayema0,
After reviewing your post, I have located an article that can help with iOS passcodes. It contains a number of troubleshooting steps and helpful advice for the issue you are experiencing:
About iOS passcodes - Apple Support
Forget your passcode?
If you or someone else enters the wrong passcode too many times, your device will disable itself temporarily. Get help if you forgot your passcode or your device is disabled.
Learn what to do if you forgot your Restrictions passcode.
Thank you for contributing to Apple Support Communities.
Cheers,
BobbyD -
What does the "s" stand for in iPhone4s
What does the "s" stand for in iPhone4s??
Yes, that is correct. There is no right answer 100%. I don't really know how to explain it. But you have to see where I am coming from. I guess you can think about it like this. S is a word. The word was defined as speed 2 years ago. Now it is being used again. Since S was already defined it does not need to be defined again. It just makes sense that apple would be consistent in their product names.
But that isn't what they said. They said "that's the probmlem i'm having with people saying its siri.." In other words, that's why I am not so sure siri is the correct answer. They are just curious, that's all. If someone said, "The iPhone is to die for" would you think they would actually die for an iPhone? Like I said, just relax. You don't need to go attack people by saying that they need mental help when they are just curious about something.
However, you are entitled to your opinion. I have presented my case and you seem to be getting pretty upset over my comments so I think this whole thing should be let go. There are plenty of posts here for the OP to make a decision for themselves and if he/she needs more clarification he/she will ask. -
What does it WF_EVENT_OJMSTEXT_QH use for?
Dear all:
I found the error in the alert_log:
*** 2010-08-05 16:13:26.608
*** SESSION ID:(572.533) 2010-08-05 16:13:26.608
Exception signal: 11 (SIGSEGV), code: 1 (Address not mapped to object), addr: 0x2a96b75000, PC: [0x10efcdf, kdkbin()+223]
*** 2010-08-05 16:13:26.612
ksedmp: internal or fatal error
ORA-07445: exception encountered: core dump [kdkbin()+223] [SIGSEGV] [Address not mapped to object] [0x2A96B75000] [] []
Current SQL statement for this session:
begin WF_EVENT_OJMSTEXT_QH.enqueue(:v1, :v2); end;
----- PL/SQL Call Stack -----
object line object
handle number name
0x2d3fda4a8 204 package body SYS.DBMS_AQ
0x2edfb5e38 980 package body APPS.WF_EVENT_OJMSTEXT_QH
0x2edfbecf8 1 anonymous block
0x2ebc2ddb8 1720 package body APPS.WF_EVENT
0x2ebc2ddb8 668 package body APPS.WF_EVENT
0x2ea538c30 229 package body APPS.WF_RULE
0x2ed36d538 31 package body APPS.FND_BES_PROC
0x2ed374d60 1 anonymous block
0x2ebc2ddb8 443 package body APPS.WF_EVENT
0x2ebc2ddb8 1599 package body APPS.WF_EVENT
0x2ebc2ddb8 2372 package body APPS.WF_EVENT
0x2ebc2ddb8 700 package body APPS.WF_EVENT
0x2ed39d3a0 4990 package body APPS.FND_FLEX_SERVER
0x2efd60840 3 anonymous block
----- Call Stack Trace -----
I've been raised the SR for this case ,and also install the Patch 6047085, the issue still happened. The ORACLE ask me: what kind of object this is, what is the owner etc? How is this object called? Can someone can tell me what does the WF_EVENT_OJMSTEXT_QH use for? or any article to introduce it?
my environment : ebs 11.5.9
database : oracle 9.2.0.8 64bit
platform: linux redhat 4.0
Regards
TerryHi Srini:
Thank you for your reply.
Not sure why Support is asking you about this object - they should be the one providing you the answers ;-)-- I feel confused too. This issue last for one month and still have no idea for this case.
Pl see if MOS Doc 1073171.1 (ORA-7445 [kdkbin()+223] on Linux x86-64 platforms on 9i release) is relevant in your case.--- I've been apply the patch, but no help.
Regards
Terry -
What does your account type does not support the view account feature mean?
What does your account type does not support the view account feature mean?
In reference to what? Where are you seeing this message - iTunes? Do you use a credit card for purchases in iTunes or do you download only free content?
-
What does "Your Creative Cloud membership has transitioned from Paid to Free" mean?
What does "Your Creative Cloud membership has transitioned from Paid to Free" mean?
Hi Don
As you've cancelled your paid membership you will continue to have access until June 28th. After that you will only have access to certain services associated with the free level of membership.
Please check the FAQ for further details: Adobe Creative Cloud – FAQ
Thanks
Bev -
What does symbol ! stand for in the following code?
What does symbol *!* stand for in the following code? What does SYSTEM mean?
<! DOCTYPE report-group SYSTEM "report-group.dtd">
Edited by: user11337968 on Jul 3, 2009 4:53 PMIt is just part of the XML specification; to do a "doctype", you must have an open angle bracket followed by an exclamation point. See [doctype decl | http://www.w3.org/TR/REC-xml/#NT-doctypedecl] for more information.
Peace,
Cameron Purdy | Oracle Coherence -
ACR 4.4, ACR 3.3...What does the "ACR" stand for ?
In the Camera Calibration tab in Camera Raw or Lightroom, we can choose the profile from the menu.
There are so many profiles in the menu, ACR 4.4, ACR 3.3...What does the "ACR" stand for ?ACR x.x designates an older style of profile where Adobe named their profiles for the version of Adobe Camera RAW that first supported the camera--basically the vintage of the profile, so if Adobe updated the profile then you'd be able to pick whether you wanted the old one or the new one.
-
What does the owner use for?
What does the owner use for?
owner such as those found in:
JWindow(Frame owner)
JWindow(Window owner)
and more.ah... i'm creating a splash with a JWindow and set it with a no owner and it shows the splash then proceed to the showing of the gui is it ok? or will there be problems?
-
HT4623 what does the mm stand for on my model of ipad mini?
what does the mm stand for on my model of my ipad mini that is also cellulat?
Copied from another discussion, from Phil0124
The MM or Millenium Media according to what I can find, refers to the CDMA variation of the Cellular iPad for Verizon Networks.
The non MM version is for GSM carriers like AT&T.
https://discussions.apple.com/thread/5093889?start=0&tstart=0 -
HT201471 What does the (MM) stand for ie wi-fi+cellular(MM)?
What does the (MM) stand for ie:wi-fi+cellular (MM)?
I don't know what the "MM" stands for specifically, but those are the CDMA models, A1455 for the mini and A1460 for the 4th-gen iPad Retina.
Regards. -
What does the "1" stand for on the Aperture Icon?
A 3.4 What does the "1" stand for on the Aperture Icon?
As far as I see, the red number shows that the recipient has accepted the stream. If you delet the stream the red number is gone.
I am not sure -this may be a coincidence: Yesterday I saw the red number "1" appear everytime I received a notification when a comment was added to one of the images I posted. When I read the comment, the number went away. The number is gone now, but I still have the stream.
Maybe you are looking for
-
I have to save as CMYK for print, but the colours are out of whack..
hey all, I am designing something for a CD cover that is going to be printed at a print shop, They say they want their images in CMYK and prefer it in a PDF or highest quality JPEG.... So I have been working in CMYK, everything looks fine in photosho
-
I replaced a 4 por router with a 8 port EZXS88w switch. My HP injet works fine. My Brother HL 1440 prints graphics, but text is all jibberish. Thanks 4 all help received.
-
In swing application , there is a cofee symbol in the header , I want to hide that symbol or replace it with another my own symbol , can anybody tell me how can I do this ????? Thanks
-
Hi, I just spot a bug in ThreadLocal example demonstrated in the JAVA API doc. here is the code snippet: public class UniqueThreadIdGenerator { private static final AtomicInteger uniqueId = new AtomicInteger(0); private static final ThreadL
-
I am pleased to report that I just returned from a month-long trip throughout Europe and my iPod touch worked like a charm. I bought it prior to departing to use it for mobile internet access as I new I would find WiFi-enabled places everywhere. It e