cancel
Showing results for 
Search instead for 
Did you mean: 

SAP GRC Audit requirements

Former Member
0 Kudos

Hi Gurus,

As pert of GRC system audit I got this below requests, can any one help me how to pull these requests?

1. Screenshot of password parameters within the UME (User Management Engine)

2. List of all users within the UME (User Management Engine).

3. List of users with the ability to administer access.

4. List of users with access to assign authorizations and create users within the SAP backend system.

5. Evidence of user verification process (if reverification of users have occurred.)

6. Obtain copy of the current rule set in place with management approval (if applicable).

7. Obtain a list of users who have access to make changes/modify to the ruleset within Risk Analysis and Remediation. (Front end and Back End Access)

8. Obtain scrrenshot/list of users with access to:

1.)Configuration Tab

2.)Informer Tab

9. System generated list of all changes/modifications to the Ruleset.

10. System generaeted list of all changes to the GRC application.

11. Obtain evidence that separate Development and Procuction Environment exist.

It would really helpful to me if I get setp by step process of downloading the above reports.

Thanks.

Accepted Solutions (0)

Answers (1)

Answers (1)

sunny_pahuja2
Active Contributor
0 Kudos

Hi,

These are very basic questions, you should check GRC configuration and security guide to get the same information.

Thanks

Sunny