cancel
Showing results for 
Search instead for 
Did you mean: 

Basis SOD risks - Mitigating controls

Former Member
0 Kudos

Hi all,

I was requested to design mitigating controls for all the risks existing in their GRC ruleset.

When I started to think about SOD risks that contains IT functions, I figured out that all the preventive/manual controls would be ineffective, an the automatic ones would be cheated.

Have you ever performed this analysis and designed controls that could really mitigating these basis risks?

All the basis risks came from SAP standard ruleset.

Thanks in advance.

Regards,

Felipe Barros

Accepted Solutions (0)

Answers (1)

Answers (1)

madhusap
Active Contributor
0 Kudos

Hi Felipe,

Can you please elaborate more on your requirement?

"I was requested to design mitigating controls for all the risks existing in their GRC ruleset."


Is your requirement to create mitigation controls for all the risks?? or specific to basis?

Regards,

Madhu.

Former Member
0 Kudos

Hi Madhu,

The requirement it to create mitigation to all risks, but for the FI, PTP, OTC, PM and MM risks it was easier to design.... Now I need to create the mitigation specific to basis...

Thanks.

Regards,

Felipe Barros