RE:[sap-log-mm] Sox Segregation Of Duties.
Posted by
Admin at
|
Share this post:
|
on 07/24/2009 12:41:00 PM
Hello Henry,
SOX Compliance in SAP is not only FI query, it generally regards the internal control and segregation of duties. From SAP point of view it looks as following: when you start work with SAP in a company with SOX, your tasks are assigned to SOX roles and they limit your access and authorizations in system. You have to request the access and roles via internal application and then your requests are processed at one or more levels, for example by your team leader next by system owner.
For example, in IT team you cannot act both as system developer, processing configuration change requests and as the tester. These are intermodular rules and they regard system as a whole, not only FI.
One more example - as MM user, you are authorized to do some customizing changes (according to the company rules and processes) in MM, but you cannot do any changes for FI - let's say accounts changes. You are only authorized to display the necessary account or other basic data.
When you need another authorization, you have to request via internal application again.
This application usually has different setting for IT roles and business roles, it all depends on your company structure. Usually IT does not see the business roles and vice versa.
Hope I have clarified your doubts, even in a small range. __.____._
Toolbox.com
4343 N. Scottsdale Road
Suite 280
Scottsdale, AZ 85251
In the Spotlight
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion