cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigation controls for cybersecurity in GRC AC

former_member275658
Contributor
0 Kudos

Hi Experts,

We are implementing cybersecurity in our company which covers IT and OT security. Can anyone please advise if we can leverage GRC 10.X mitigation controls capability and include our cybersecurity controls ?

Regards,

Salman

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

If it in anyway concerns someones SAP authorisation accesses, you should be able to.

Are you planning to utilise the Mitigating Control library to document non-SAP risks? Or are you utilising SAP reports to monitor non-SAP related security issues?

former_member275658
Contributor
0 Kudos

Are you planning to utilise the Mitigating Control library to document non-SAP risks?  Yes

We would like to use GRC AC Mitigation piece to include our non sap controls as well.

Former Member
0 Kudos

No harm in using the GRC AC mitigating controls repository like a documentation library, but it will just sit there as a definition and have no real monitoring ability, even in the forms of a GRC report.

Unless you are using 3rd party connectors to connect to the Non-SAP system and analyse Action level violations.

Hope that answers your question.