cancel
Showing results for 
Search instead for 
Did you mean: 

Looking for customer case studies who use AC to manage mitigating controls

jean-luc_dene
Advisor
Advisor
0 Kudos

Dear All,

We are discussing with major French Groups and they would like to know how Access Control (AC) existing customers have implemented AC to manage mitigating controls in an end-to-end process (i.e. documentation, execution, corrective actions, follow-up and monitoring).

Their concerns are due to the fact that Access Control currently only allows to document mitigating controls but there is no way within Access Control to track and follow-up execution of those mitigating controls. It is clear that Process Control could be used for tracking mitigating control execution but there is currently no interface between AC and PC relating to this point and consequently mitigating controls have to be documented redundantly in AC and PC.

Question:

Do you have any customer experiences or any information to share with me regarding AC usage to manage mitigating controls in an end-to-end process?

Many thanks in advance for your help and support.

Best regards,

Jean-Luc Dene

Presales Senior Specialist

Governance, Risk and Compliance (GRC) and Sustainability Solutions

SAP BusinessObjects Division

Capital 8 Building u2013 32, rue de Monceau

75008 Paris, France

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Jean-Luc,

Within Access Controls 5.3 you can use Mitigation control alerts to notify the monitors that their controls have not been executed within the required periods.

Have you looked at the SAP Reference Sites for SAP to try and identify where customers have agreed to share experiences?

You may also find the SAP User Group helpful for this kind of request: www.sapusers.org

Simon