We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

Re: [sap-security] Whether FB60 (Posting Option) And FV50 (Parking Option) Can Be Assigned To A Single User

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Reply from SAPAUSSEC on Aug 4 at 9:36 PM
It is to do with management decisions
FB60 is for posting an invoice - please note posting
FV50 allows parking of a GL document

First it is not considered good practice to allow the same user to post
invoices (which will update the ledger and subsidiary ledger) and post
directly to the ledger as mistakes and manipulation could occur.
Second FV50 is for parking a GL document. Parking means a document is
created then reviewed and approved by an independent person who then
posts the document updating the accounts. It is a 2 step posting process.

Now as both transactions are FI they will use some of the same
authorization objects. For FB60 these objects will require an activity
of 01 to post. For FV50 the normal activity will be 77 which will allow
the document to be created and saved but not posted. If a user
authorized to park also has activity 01 then they can bypass the 2 step
review approval posting process.

Someone has decided that all GL postings should be reviewed - a business
or management or audit requirement. This is normally done with
sensitive postings or where junior staff or non accounting aware staff
are processing. It may be that they have had problems in the past and
implemented this practice. But the user with 01 can by pass this. I
would assume only senior accountants are allowed to review and post and
possibly post directly.

---------------Original Message---------------
From: James Johnson
Sent: Tuesday, August 04, 2015 5:11 PM
Subject: Whether FB60 (Posting Option) And FV50 (Parking Option) Can Be Assigned To A Single User

I'll join the group saying this is a policy issue, not a technical one.

I am interested why this is considered a SoD issue. If someone can post a document and also park a document and nothing else, then what is the risk this creates to make it a SoD issue?

 
Reply to this email to post your response.
 
__.____._
Manage Settings | Unsubscribe | Create FAQ | Send Feedback
  
Copyright © 2015 Ziff Davis, LLC. and message author.
Ziff Davis, LLC. 28 E 28th Street New York, NY 10016
SAPAUSSEC  

achievements
 
Mark as helpful
View this online
Ask a new question
 
In the Spotlight
Earn Recognition for Your Contributions at Toolbox for IT. Gain Points for Community Achievements

_.____.__

0 comments:

Post a Comment

T r a n s l a t e to your language