cancel
Showing results for 
Search instead for 
Did you mean: 

What is GRC all about?

Former Member
0 Kudos

Hello

What is GRC (Governance; Risk and Compliance) module all about?

What is its implementation time if it is to be implemented stand alone post Go live?

What are the functionalities available in it a

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

SAP GRC Access Control has a central repository for access and authorization based risks and controls:-

1. Provides risk analysis for every Process that can be covered by the solution

2. Supports the creation and assignment of a mitigation control out of an approval workflow via

the mitigation service

SAP Access Control contains the following tools which are becoming increasingly integrated for optimum usage:

1. Compliance Calibrator (Risk Analysis and Remediation u2013 RAR)

This tool supports real-time compliance by stopping security and controls violations before they occur. It contains the most comprehensive library of Segregation of Duty (SoD) rules available for enterprise applications from SAP, Oracle, and PeopleSoft. This makes it easy for business-process owners to deploy rules applicable to their organization and to eliminate risks from enterprise applications.

2. Firefighter (Super Privilege Management u2013 SPM)

This enables super-users to perform emergency activities outside the parameters of their normal role, but to do so within a controlled, fully auditable environment. The application assigns a temporary ID that grants the super-user broad yet regulated access, and tracks and logs every activity the super-user performs using that temporary ID.

3. Role Expert (Enterprise Role Management - ERM)

ERM centralizes and standardizes enterprise wide role management. This helps to eliminate manual errors, provides an audit trail for changes, and enforces best practices. Using the application, business managers can define functional roles, and IT managers can define the associated technical permissions.

4. Access Enforcer (Compliant User Provisioning - CUP)

CUP supports fully compliant user provisioning across applications throughout the employee life cycle. Multi-step guided procedures automate approval processes and enforce mandatory, real-time risk assessments prior to provisioning users to enterprise applications.

Former Member
0 Kudos

Vimal,

As Raja mentioned here, the most famous porudct in GRC is Access Control. Here is more information about other products:

Risk management u2013 Balance business opportunities with strategic, operational, financial, legal, and compliance risks to maximize corporate performance and minimize the market penalties from high-impact events.

Access control u2013 Protect information efficiently and prevent fraud by identifying and preventing access and authorization risks in cross-enterprise IT systems.

Process control u2013 Ensure compliance and enable business process control management by centrally monitoring key controls and data across-enterprise systems.

Global trade services u2013 Lower the cost and risk of international trade with a comprehensive platform to ensure trade compliance, expedited cross-border transactions, and optimum utilization of trade agreements.

Environment, health, and safety management u2013 Empower your organization to address regulatory compliance; integrate the management of operational risks related to environment, health, and safety; and address corporate sustainability initiatives.

Also, check out [www.sap.com/grc |http://www12.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx]for more information.

Alpesh