07-02-2008 8:47 AM
Hello,
i heard that SAP has standard tools available for compliance i.e. AIS, MIC..etc. They are smaller in scope than GRC. Could someone help show me where I can find them in my SAP v4.6c system.
Many thanks.
Charles
PS: I intend to post this in the GRC forum as well.
07-02-2008 8:57 AM
> PS: I intend to post this in the GRC forum as well.
Officially, that would be non-compliant with the SoX "rules of engagement" of this site
However I can understand special cases where it is usefull to go beyond forum boundaries and have made a suggestion for a feature to mirror threads to other related forums. However that is on a long and prioritized list of suggestions.
Back to your question: If you start transaction SECR then a 46C system will tell you more about the AIS. Also see report RSUSR009 (and the newer one RSUSR008_009_NEW). Tcode AUT10 might also be of interest.
To my knowledge there is nothing in the standard 46C system which "brings it all together" like GRC intends to.
Cheers,
Julius
07-02-2008 8:59 AM
the audit information system can be found in 4.6c, I believe, under transaction SECR.
edit: Julius 'John Wayne' shooting from the hip...
Edited by: Dimitri van Heumen on Jul 2, 2008 10:00 AM
07-02-2008 2:18 PM
In later versions of SAP, transaction SECR is no longer applicable. The AIS component has been broken down into standard SAP Roles. If you enter transaction PFCG and search for roles starting SAP_AUD* you will find a number of the standard audit focused roles which can be used in conjunction with the User Information System, SUIM.
It is not as integrated as the GRC tools but it can be used to perform detective controls.
Regards,
Simon