cancel
Showing results for 
Search instead for 
Did you mean: 

Shopping cart Monitor: Search done based on User ID - Changes since SP14?

Former Member
0 Kudos

Hi SDN

We have just implemented SP14 on our SRM5.0 installation, and we have noted major changes in the Shopping Cart Monitor iView. Before SP 14, the search parameter fields 'Requester' and 'Created by', used to take the User ID as input. As per OSS Note 1148093, this behavior was not SOX compliant. For SOX compliancy, the search parameter fields 'Requester' and 'Created by' have been changed to contain the business partner number, and not the user ID.

Moreover, the search result, used to display the User ID of the creator of the shopping cart (field 'Created by'). which was also not SOX compliant as per Note 1154480.

Is anyone aware of the Article/Section/Rule/Guideline of the SOX policy that SAP is referencing to in order to say that this was not SOX compliant? I would like to understand this as it has major impacts on our users, that never used the Business Partner ID.

Let me know.

Eric L.

Accepted Solutions (0)

Answers (3)

Answers (3)

matthias_kasig2
Participant
0 Kudos

Hi Eric,

we just did an upgrade in SRM to SP Stack 15.

In fact we are also not really pleased with the new search - bus.partner id instaed of user id.

Anyway, we are in Germany and we don't know nothing about SOX and care a **** about it.

Just read that note 1344821 reverts the changes back to "normal".

In fact I can't get the note - I get a message:

"Der angeforderte SAP-Hinweis wird entweder gegenwärtig überarbeitet oder ist nur intern freigegeben"

English: The requested note is being re-edited or released for internal use only"

Do you have the note installed? Or do you know anything about it?

Help welcome,

kind regards,

Matthias

Former Member
0 Kudos

SAP has confirmed that Note 1344821 will revert changes introduced by both notes 1148093 and 1154480.

Former Member
0 Kudos

Hi. I would raise a customer message and ask SAP this question.

I very much doubt that any SOX legislation states that you can not search for shopping carts by user ID. Proabably an auditor somewhere has raised it as an issue with one of SAP's clients, and they have raised a message and SAP have amended the report based on this.

If you have your own auditors then ask them if they have an issue with it. Also, is your company listed on the US stock exchange and do you have to be SOX compliant? If your company is not SOX compliant then why should they force you to have this note?

If you push SAP they may create a new note to back out the changes that you can choose to implement.

Regards,

Dave.

Former Member
0 Kudos

Hi David

Actually, SAP has confirmed that Note 1344821 will revert changes introduced by both notes 1148093 and 1154480, which is a good news.

As you have suggested, I'll go see an auditor here and ask that question.

For me, the issue is bigger than just SRM. R/3 list display, as well as several reports can show UserID or used this value as a search Criteria, so the impacts could be really big. This is why I was questioning the change.

Thanks for your reply

Eric L.