Re: [sap-security] Questions about Temporary Roles/Assignments in SAP
Posted by
Admin at
Share this post:
|
0 Comments
Posted by abamrah on Mar 6 at 11:33 AM | Mark as helpful |
Hi Dan,
While you are dealing with this issue and you were not aware of User Master
Compare issue, Please read the following
http://help.sap.com/saphelp_46b/helpdata/ru/52/6711ec439b11d1896f0000e8322d00/content.htm
and
schedule a job that runs every night to take care of profile
enabling/disabling depending on the Validity.
Also look at your SAP GUI options to enable automatic User Master Compare:
http://help.sap.com/saphelp_nw70/helpdata/en/5c/deaa7ad3d411d3970a0000e82de14a/content.htm
The Firefighter stuff is part of SAP GRC tools that is pretty much becoming
a standard these days to deal the SoX/SoD concerns of corporations. So look
into that as well when you get a chance, if not already done so.
I hope that helps.
With best regards,
Amrit
On 5 March 2010 14:31, rdbarahona via sap-security <
sap-security@groups.ittoolbox.com> wrote:
> Posted by rdbarahona(Business Development)
> on Mar 5 at 4:33 PM
> <warning>Newbie questions</warning>
>
> I understand that there are often requirements to assign temporary roles to
> individual users (e.g., to cover for a colleague on vacation, etc.). When
> User X is assigned Role Y for, say, a 2 week validity period, does the Role
> Y automatically get disabled/revoked from User X at the end of the 2 weeks?
> I'm almost certain the answer is yes, but have actually heard conflicting
> answers.
>
> Related, in your organizations, are there policies regarding the duration
> in which a temporary role can be assigned? E.g., do you allow temporary
> roles for up to 14 days? If so, how would you find role-assignments that are
> out of compliance?
>
> Thanks,
>
> Dan
__.____._ While you are dealing with this issue and you were not aware of User Master
Compare issue, Please read the following
http://help.sap.com/saphelp_46b/helpdata/ru/52/6711ec439b11d1896f0000e8322d00/content.htm
and
schedule a job that runs every night to take care of profile
enabling/disabling depending on the Validity.
Also look at your SAP GUI options to enable automatic User Master Compare:
http://help.sap.com/saphelp_nw70/helpdata/en/5c/deaa7ad3d411d3970a0000e82de14a/content.htm
The Firefighter stuff is part of SAP GRC tools that is pretty much becoming
a standard these days to deal the SoX/SoD concerns of corporations. So look
into that as well when you get a chance, if not already done so.
I hope that helps.
With best regards,
Amrit
On 5 March 2010 14:31, rdbarahona via sap-security <
sap-security@groups.ittoolbox.com> wrote:
> Posted by rdbarahona(Business Development)
> on Mar 5 at 4:33 PM
> <warning>Newbie questions</warning>
>
> I understand that there are often requirements to assign temporary roles to
> individual users (e.g., to cover for a colleague on vacation, etc.). When
> User X is assigned Role Y for, say, a 2 week validity period, does the Role
> Y automatically get disabled/revoked from User X at the end of the 2 weeks?
> I'm almost certain the answer is yes, but have actually heard conflicting
> answers.
>
> Related, in your organizations, are there policies regarding the duration
> in which a temporary role can be assigned? E.g., do you allow temporary
> roles for up to 14 days? If so, how would you find role-assignments that are
> out of compliance?
>
> Thanks,
>
> Dan
Copyright © 2010 Toolbox.com and message author.
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
Related Content
In the Spotlight
_.____.__ White Papers
In the Spotlight
55% of IT Pros Use Social Media to Advance Their Careers. See the Survey Results