<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8842082917241702221</id><updated>2012-01-27T23:11:11.714+08:00</updated><category term='CA/ CM'/><category term='SAP GRC'/><category term='SNC'/><category term='Continuous Monitoring'/><category term='SAP J2ee vulnerability'/><category term='SAP tool'/><category term='Continuous Auditing'/><category term='Segregation of Duties'/><category term='Survey'/><category term='SAP Singapore'/><category term='SAP GRC tool'/><category term='SAP_NEW'/><category term='SAP Controls'/><category term='SAP security survey'/><category term='SAP Audit Logs'/><category term='Mantran'/><category term='Configurable Controls'/><category term='SAP Audit Tool'/><category term='BASIS controls'/><category term='Mantran Consulting'/><category term='SAP Security'/><category term='SOD'/><category term='Secure Network Communications'/><category term='Duplicate Invoice Check'/><category term='Tools'/><category term='Double Invoice Check'/><category term='SAP authorizations'/><category term='SAP Training'/><category term='SAP Security and Controls'/><category term='SAP CAM'/><category term='SAP Security Training'/><category term='SAP Audit'/><title type='text'>SAP Security and Controls</title><subtitle type='html'>Various topics related to SAP security and controls!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>34</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-7386524667003522052</id><published>2011-11-06T09:49:00.000+08:00</published><updated>2011-11-06T09:49:48.777+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='Double Invoice Check'/><category scheme='http://www.blogger.com/atom/ns#' term='Duplicate Invoice Check'/><title type='text'>Double invoice check in SAP</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP provides multiple controls in the area of Accounts Payable. One of them refers to the possibility of entering an invoice twice and therefore, resulting in multiple payments for the same purchase. While, it is not possible for SAP to definitively conclude that an invoice is 'duplicate', it can assist to identify 'potential duplicate' invoice based on certain parameters set in the system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;This is controlled through the 'double invoice check' indicator in the vendor master record. If this indicator is set for a vendor, &lt;/span&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;it  means that incoming invoices and credit memos are checked for double entries at the time of entry. In this case, SAP &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;checks whether the invoice documents have already been entered in the Logistics invoice verification. &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In checking for duplicate invoices, SAP compares the following characteristics by default:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Vendor&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Currency&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Company code&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Gross amount of the invoice&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. Reference document number&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;6. Invoice document date.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;If all of these characteristics are the same, the system issues a message that can be customized. &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP only checks for duplicate invoices in Materials Management if you enter the reference document number upon entering the invoice.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div style="direction: ltr; language: en-SG; margin-bottom: 0pt; margin-top: 4.32pt; mso-line-break-override: restrictions; punctuation-wrap: simple; text-align: left; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In Customizing for the Logistics invoice verification, the following characteristics can be disabled for duplicate invoice checks:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="direction: ltr; language: en-SG; margin-bottom: 0pt; margin-top: 4.32pt; mso-line-break-override: restrictions; punctuation-wrap: simple; text-align: left; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Company code&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Reference document number&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Invoice document date.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;This means that you can increase the likelihood that SAP will find a duplicate invoice, because you can reduce the number of characteristics checked&lt;/span&gt;.&lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div style="direction: ltr; language: en-SG; margin-bottom: 0pt; margin-top: 4.32pt; mso-line-break-override: restrictions; punctuation-wrap: simple; text-align: left; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP then checks whether there are FI or Accounting documents that were created with the original invoice verification or the Logistics verification, and where the relevant criteria are the same. &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Depending on the entry in the field "Reference", one of the following checks is carried out:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. If a reference number was specified in the sequential invoice/ credit memo, SAP checks whether an invoice/credit memo has been posted where all the following attributes agree:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; mso-text-raise: 0%; text-combine: letters; vertical-align: baseline;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;a. &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;Company code&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;b. Vendor&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; mso-text-raise: 0%; text-combine: letters; vertical-align: baseline;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;c. &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;Currency&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;d. Document date&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;e. Reference number.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. If no reference number was specified in the sequential invoice/ credit memo, the system checks whether an invoice/credit memo has been posted where all the following attributes agree:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;a. Company code&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;b. Vendor&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;c. Currency&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;d. Document date&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;e. Amount in document currency.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;As a good practice, you should ensure that 'double invoice check' indicator is set as a 'mandatory' field in the vendor master configuration. This ensures that the indicator is set for all vendors. Alternatively, perform data analytics to ensure that this field is set for all vendors.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Then, check the duplicate invoice check configuration parameters to determine whether any of the three configurable parameters (i.e.,&amp;nbsp;&lt;span style="color: black; font-family: Arial; font-style: normal; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Company code,&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Reference document number and&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: +mn-cs; mso-color-index: 1; mso-fareast-font-family: +mn-ea; mso-font-kerning: 12.0pt; text-combine: letters;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Invoice document date) have been disabled (the more parameters disabled, better is the control).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-7386524667003522052?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/7386524667003522052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/11/double-invoice-check-in-sap.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7386524667003522052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7386524667003522052'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/11/double-invoice-check-in-sap.html' title='Double invoice check in SAP'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-6168093408612662017</id><published>2011-10-26T11:13:00.000+08:00</published><updated>2011-10-26T11:13:51.107+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='Configurable Controls'/><title type='text'>"Alternate Payee" in Vendor Master</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1; mso-fareast-font-family: +mn-ea;"&gt;SAP payment program can make payment to a vendor other than the one to which the invoice was posted. Payment is made to an 'alternative payee', which must be specified in the vendor master record. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1; mso-fareast-font-family: +mn-ea;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1; mso-fareast-font-family: +mn-ea;"&gt;An alternative payee can be defined in the ‘general data area’ and in the ‘company code data area’. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1;"&gt;The alternative payee specified in the general data area is used by every company code. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1;"&gt;If an alternative payee is defined in both areas, the specification in the company code area has priority. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-SG; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1;"&gt;This field can be misued for fraud and should be controlled. As a securtity control, there should be a regular review of vendor masters with 'alternate payee' and appropriateness of the same. Ideally, if an organization does not allow this practice, t&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="color: black; font-family: Arial; language: en-US; mso-ascii-font-family: Arial; mso-bidi-font-family: Arial; mso-color-index: 1; mso-fareast-font-family: +mn-ea;"&gt;he ‘alternate payee' field in the vendor master records should be set to ‘suppressed’.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-6168093408612662017?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/6168093408612662017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/10/alternate-payee-in-vendor-master.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6168093408612662017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6168093408612662017'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/10/alternate-payee-in-vendor-master.html' title='&quot;Alternate Payee&quot; in Vendor Master'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2979141392341655029</id><published>2011-08-18T11:25:00.000+08:00</published><updated>2011-08-18T11:25:23.904+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP J2ee vulnerability'/><title type='text'>SAP NetWeaver J2EE Vulnerability</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;It has been a while since I last blogged. However, the recent news surrounding the SAP NetWeaver J2EE vulnerability is too serious to skip. I am referring to the recent news about Alexander Polyakovk, a SAP technical security expert, who&amp;nbsp;presented a security hole in SAP's J2EE engine, which is part of its NetWeaver platform.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;According to his presentation at Black Hat security conference in Las Vegas, this vulnerability allows an attacker to create new administrator accounts in remotely. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana;"&gt;&lt;span style="font-size: x-small;"&gt;Broadly, the steps are as follows:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Search for a particular string that was typically an indicator of the Management Portal for SAP systems using Google&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Use a Perl script to executed the actual attack in two stages - the script would first create a new user, and then promote the new user to administrator&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Logpn to the vulnerable SAP system using this user ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;According to his calculations, around 50 per cent of all SAP installations are affected by the bug in the J2EE Engine.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Thankfully, to provide SAP to come up with patch to protect against this vulnerability, &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The script will be released by the researcher three months after the publication of an update by SAP, Alexander Polyakovk has not provided the details of the vulnerability.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Follow me for more updates soon!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2979141392341655029?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2979141392341655029/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/08/sap-netweaver-j2ee-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2979141392341655029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2979141392341655029'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/08/sap-netweaver-j2ee-vulnerability.html' title='SAP NetWeaver J2EE Vulnerability'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2437770844359184824</id><published>2011-05-04T17:09:00.000+08:00</published><updated>2011-05-04T17:09:41.471+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>Audit Information System (AIS)</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="DE" style="mso-ansi-language: DE; mso-bidi-font-size: 11.0pt; mso-bidi-font-weight: bold;"&gt;Audit Information System (AIS)&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;span lang="DE" style="mso-ansi-language: DE; mso-bidi-font-size: 11.0pt;"&gt;is a native SAP tool to assist in auditing both technical and business controls in SAP system. In verions SAP R/3 4.6c and earlier, AIS could be accessed using transaction &lt;b style="mso-bidi-font-weight: normal;"&gt;SECR&lt;/b&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;As of SAP Release 4.6C (Software component SAP_APPL, Support Package SAPKH46C27), the AIS program concept has been changed from the former menu technique (Transaction SECR) to a role-based maintenance environment (Transaction PFCG).&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;The AIS now consists of a number of single roles. You can obtain an overview of the AIS standard roles in your system as follows:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;a.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;Call up Transaction PFCG&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;b.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;Enter "SAP*AUDITOR*" in the "Role" field.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;c.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;Trigger with the F4 key. Then choose "Single roles".&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;The single roles are divided into two groups:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-font-weight: bold;"&gt;&lt;span style="mso-list: Ignore;"&gt;a.&amp;nbsp;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt; mso-bidi-font-weight: bold;"&gt;Transaction roles&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-font-weight: bold;"&gt;&lt;span style="mso-list: Ignore;"&gt;b.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt; mso-bidi-font-weight: bold;"&gt;Authorization roles&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;The transaction roles contain a menu, but have no authorization values. The authorization roles contain authorization values, but have no menu. All roles are delivered without an authorization profile.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Authorizations are usually generated on the basis of the authorization default values that are adapted to the transactions in the role menu. For AIS transaction roles, however, the authorizations had to be adjusted significantly afterwards (only display authorizations are to be permitted). As a simplified solution, special authorization roles with appropriate authorizations are available for AIS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;All single roles are combined in composite roles to provide a better overview.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;a.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;SAP_AUDITOR: AIS - Audit Information System&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;b.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;SAP_AUDITOR_TAX: AIS - Tax Audit&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; line-height: 115%; mso-ansi-language: EN-US; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; line-height: 115%; mso-ansi-language: EN-US; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The detailed information can be obtained in SAP Note &lt;b style="mso-bidi-font-weight: normal;"&gt;451960&lt;/b&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2437770844359184824?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2437770844359184824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/audit-information-system-ais.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2437770844359184824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2437770844359184824'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/audit-information-system-ais.html' title='Audit Information System (AIS)'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-4318705793945376737</id><published>2011-05-02T10:04:00.000+08:00</published><updated>2011-05-02T10:04:51.592+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Secure Network Communications'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SNC'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>What is SNC in SAP?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;strong&gt;S&lt;/strong&gt;ecure &lt;strong&gt;N&lt;/strong&gt;etwork &lt;strong&gt;C&lt;/strong&gt;ommunications (SNC) is a software layer in the SAP system architecture that provides an interface to an external security product. With SNC, you can strengthen the security of your SAP system by implementing additional security functions that SAP systems do not directly provide (for example, the use of smart cards for user authentication).&lt;/span&gt;&lt;span lang="EN-US" style="mso-ansi-language: DE; mso-bidi-font-size: 11.0pt;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;SNC provides security at the application level. This means that a secure connection between the components of the SAP system (for example, between the SAP GUI and the SAP application server) is guaranteed, regardless of the communication link or transport medium. You therefore have a secure network connection between two SNC-enabled communication partners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;You cannot apply SNC protection to the communication path between your application servers and your database. Therefore, we recommend you keep your application and database servers in a secured LAN that is protected with a firewall and SAProuter.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US; mso-fareast-language: EN-US;"&gt;There are well-known cryptographic algorithms that have been  implemented by the external security products supported and with SNC, you can  apply these algorithms to your data for increased protection.&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;All communication that  takes place between two SNC-protected components is secured (for example,  between the SAP GUI for Windows and the application server). Also, &lt;/span&gt;&lt;/span&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;the security product can be changed any time without affecting the SAP  system.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;The following three level of security protection can be applied using SNC:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;1. Authentication Only&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;2. Integrity protection&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span dir="ltr"&gt;&lt;span style="mso-ansi-language: EN-US;"&gt;3. Privacy protection&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-4318705793945376737?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/4318705793945376737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/what-is-snc-in-sap.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4318705793945376737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4318705793945376737'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/what-is-snc-in-sap.html' title='What is SNC in SAP?'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-4503134445723626706</id><published>2011-05-02T09:56:00.000+08:00</published><updated>2011-05-02T09:56:40.777+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP_NEW'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>What is SAP_NEW profile in SAP?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;SAP_NEW is a SAP standard Profile which is usually assigned to system users temporarily during an upgrade to ensure that the activities and operations of SAP users are not hindered during the Upgrade. It contains all the necessary objects and transactions for the users to continue their work during the upgrade. It should be withdrawn once all upgrade activities is completed, and replaced with the now modified roles as it has extensive authorizations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;The SAP_NEW profile grants unrestricted access to all existing functions for which additional authorization checks have been introduced. Users can therefore continue to work uninterrupted with functions not previously subject to authorization checks. This ensures upwards compatibility. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;u&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;&lt;strong&gt;Usage during an upgrade:&lt;/strong&gt;&lt;/span&gt;&lt;/u&gt;&lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt; For functions that were not subject to any authorization checks previously, all users were authorized irrespective of their user profiles. If all users have the profile SAP_NEW in their master record, they still have the authorization for the previously unprotected functions after an upgrade. The super user or operator can then decide after the upgrade who should keep the authorizations concerned. These users are assigned the new authorizations in their standard profile. Afterwards the operator or administrator will remove the individual profiles SAP_NEW_&lt;rel&gt; from the collective profile SAP_NEW.&lt;o:p&gt;&lt;/o:p&gt;&lt;/rel&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span lang="EN-US" style="mso-bidi-font-size: 11.0pt;"&gt;For each release SAP_NEW contains a single profile SAP_NEW_&lt;rel&gt;. &lt;/rel&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-4503134445723626706?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/4503134445723626706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/what-is-sapnew-profile-in-sap.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4503134445723626706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4503134445723626706'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/05/what-is-sapnew-profile-in-sap.html' title='What is SAP_NEW profile in SAP?'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-535084387185181573</id><published>2011-04-28T00:55:00.000+08:00</published><updated>2011-04-28T00:55:05.225+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>Internal Transaction Calls</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;  &lt;span style="color: #1f497d; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;In SAP, many transactions are called internally by another transaction. For example, when a user execute transaction OB52 to open or close an accounting period, OB52 internally calls transaction SM30 to update the corresponding tables. This ensures that the end user does not explicitly require access to&amp;nbsp;SM30.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #1f497d; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Lots of people ask me if there are ways to check such internal transaction calls in SAP. The answer - through the tables TSTCP or TCDCOUPLES. Table TCDCOUPLES is more user friendly and I will recommend use of this table if you are trying to identify internal transaction calls in SAP.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-535084387185181573?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/535084387185181573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/04/internal-transaction-calls.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/535084387185181573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/535084387185181573'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/04/internal-transaction-calls.html' title='Internal Transaction Calls'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-6760199641340835027</id><published>2011-02-18T13:16:00.000+08:00</published><updated>2011-02-18T13:16:16.678+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security Training'/><title type='text'>SAP Security Training | 22 - 23 April 2011 | Bangalore, India</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN announces the dates for its next SAP security training at Bangalore, India on 22 and 23 April 2011. The training covers various topics related to SAP authorizations and BASIS security and is very useful for anyone interested in SAP security. Email at &lt;a href="mailto:trainings@mantranconsulting.com"&gt;trainings@mantranconsulting.com&lt;/a&gt; for details.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Introduction&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP is one of the most popular ERP system used across industries. SAP system hosts sensitive and confidential enterprise data and its security is paramount to any organization. Therefore, SAP security is an integral part of information security framework of an organization. While most of the IT audits focus on infrastructure security, security of the core business system such as SAP is often ignored. The primary reason is lack of knowledge and expertise in SAP security. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP security is a complex area and includes various areas such as authorizations, segregation of duties, BASIS controls, and business process controls. SAP provides highly granular and detailed security and controls functionalities, which can be configured as per organization’s requirements. Auditing SAP security requires specialized knowledge and expertise. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP security training workshop aims to cover some of the important security controls in SAP, which an IT auditor should be aware of. A good understanding of SAP security will enable IT auditors to ensure a comprehensive IT audit.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP security training details&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Duration: 2 days&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Training content: The SAP security training will cover the following areas: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Introduction:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a. Overview of SAP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b. Navigating SAP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; c. SAP architecture and landscape&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Authorizations and Segregation of Duties (SoD):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a. Importance of SAP authorizations &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b. SAP authorizations concept – authorization object and field, authorization, profile and role, and user master record&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; c. Profile – manual, generated, single and composite &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d. Difference between profile and role&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; e. Authorization checks carried out by SAP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f. Profile generator – prerequisites, how to use profile generator, advantages and concerns&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; g. SoD – importance, underlying causes of SoD and compensating controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; h. SAP authorizations and SoD review – objectives, manual vs automated, native tools in SAP and commercial tools&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. BASIS controls:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a. System parameters in SAP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b. Access controls - password controls, user types, standard users security (SAP*, DDIC, SAPCPIC, EARLYWATCH), privileged profiles (SAP_ALL and SAP_NEW), standard user reports and tables&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; c. Change controls - SAP landscape, system and client, system and client settings, segregation of environments, transport organizer, transport management system, developer Access Key&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d. Audit logs in SAP - security audit logs, table logs, etc&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; e. Securing tables and reports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Important transactions, tables and reports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;About the trainer&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Verdana&amp;quot;, &amp;quot;sans-serif&amp;quot;; mso-ansi-language: EN-US; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-font-size: 10.0pt; mso-bidi-language: AR-SA; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-language: EN-US;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN is a Singapore-based leading information security consulting and training company with primary focus on SAP security and controls. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun Kumar is the founder and a Director with MANTRAN Consulting Pte. Ltd. Barun was previously an Associate Director with IT Advisory practice of KPMG LLP in Singapore, AVP with Technology Risk Services practice of EXL Service and Manager with IT Advisory practice of KPMG in India. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun is an engineer, MBA, CISA, Approva Certified Professional (ACP) and ITIL v3 certified professional. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has delivered many SAP trainings – both external trainings to corporate clients as well as internal trainings. This includes a large automobiles company in Pune, an engineering conglomerate in Bangalore, an airlines company in Singapore, an IT consulting company in Bangalore, and an agribusiness in Jakarta. Barun has also conducted many public trainings, which includes one with ISACA local chapter in Mumbai and independent trainings in Singapore.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has more than 10 years of experience (including more than 8 years with Big 4) in SAP security services and has performed SAP security projects in India, Singapore, South Africa, Belgium, France, Switzerland, UK and US. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has designed and audited SAP authorizations, SoD and BASIS controls for many large companies.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-6760199641340835027?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/6760199641340835027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/02/sap-security-training-22-23-april-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6760199641340835027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6760199641340835027'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/02/sap-security-training-22-23-april-2011.html' title='SAP Security Training | 22 - 23 April 2011 | Bangalore, India'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-7178767397972219070</id><published>2011-01-26T10:26:00.001+08:00</published><updated>2011-01-26T10:27:00.899+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>SAP Security Training | 24 - 25 Feb 2011 | Singapore</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN is conducting a SAP security training on 24 - 25 Feb in Singapore. The training covers various topics related to SAP authorizations and BASIS security and is very useful for anyone interested in SAP security. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Visit &lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/sap_sc_training.html"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://www.mantranconsulting.com/sap_sc_training.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&amp;nbsp;for details. Alternatively, em&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;ail me at &lt;/span&gt;&lt;/span&gt;&lt;a href="mailto:barunkumar@mantranconsulting.com"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;barunkumar@mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; for details/ registration forms.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Some of the topics covered in the training are as follows:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;1. SAP architecture:&lt;/strong&gt; A typical SAP system is based on three-tier architecture. SAP provides flexibility in designing system landscape, which can be very complex for large organizations. SAP is compatible with all major hardware, OS, and database. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;2. Authorizations: &lt;/strong&gt;SAP authorization concept allows users to perform their work while securing transactions and programs from unauthorized access. It is a complex and scalable concept where approximately 2,000 authorization objects controls access to more than 100,000 transactions. The authorization components include user master records, roles (single and composite), profiles, authorizations, authorization objects and field values (activity, organization value, etc) and can be customized to organization’s requirement. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;3. Segregation of Duties (SoD): &lt;/strong&gt;SoD ensures that no one individual has complete control over major phase of a process and is enforced through a combination of authorizations and mitigating controls. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;4. Profile parameters: &lt;/strong&gt;Profile parameters control various security functionalities such as password controls, session security, auditing, etc. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;5. Super users: &lt;/strong&gt;SAP is shipped with many default super users, which serve specific purpose. It is important to secure these users. In addition to changing default passwords, additional measures are required for some super users like SAP*. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;6. Auditing: &lt;/strong&gt;Auditing is an important tool and SAP provides multiple auditing options. Some of the auditing features are change documents, document flow, security audit logs, table logs, transaction usage logs, etc. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;7. Change management: &lt;/strong&gt;Client setting and transport path are important to control unauthorized changes in SAP. Client setting can help ensures that changes cannot be made directly in SAP production system. &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-7178767397972219070?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/7178767397972219070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2011/01/sap-security-training-24-25-feb-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7178767397972219070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7178767397972219070'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2011/01/sap-security-training-24-25-feb-2011.html' title='SAP Security Training | 24 - 25 Feb 2011 | Singapore'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-8816958272419559821</id><published>2010-11-08T16:45:00.000+08:00</published><updated>2010-11-08T16:45:15.388+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>SAP Security Online Training</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN announces dates for SAP security training series. Please visit &lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://www.mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; for details.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You can directly visit &lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/sap_sec_online_training.html"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://www.mantranconsulting.com/sap_sec_online_training.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;for course details, schedule, trainer profile and registration details.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-8816958272419559821?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/8816958272419559821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/11/sap-security-online-training.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8816958272419559821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8816958272419559821'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/11/sap-security-online-training.html' title='SAP Security Online Training'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2952307738873462293</id><published>2010-11-03T10:54:00.000+08:00</published><updated>2010-11-03T10:54:42.454+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security Training'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran Consulting'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran'/><title type='text'>SAP Security Online Training Series</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Mantran Consulting Pte Ltd (MANTRAN) provides customized SAP security trainings that assist in understanding various technical, operational and financial risks associated with using SAP system and identifying controls to address these risks. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;These trainings are useful for SAP security professionals including user administrators, change managers, BASIS administrators, IT auditors, operational/ financial auditors, ABAP professionals, business analysts, and any other users with interest in SAP security.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN conducts regular classroom trainings in Singapore and India. Based on feedback and regular requests, MANTRAN has decided to conduct online SAP security trainings to suit participants who are unable to attend classroom trainings. The training has been divided into following three modules:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TNDMmVf0VwI/AAAAAAAAEyo/e_1Gh7hCVrY/s1600/Picture1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;img border="0" height="100" nx="true" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TNDMmVf0VwI/AAAAAAAAEyo/e_1Gh7hCVrY/s400/Picture1.jpg" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Each module is independent and can be taken individually. However, participants are encouraged to take SAP-OL-001 (Authorizations – design and review) before taking SAP-OL-002 (Segregation of Duties – design and review).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;These are Instructor Led Training (ILT) using presentation slides and demonstrations. Trainings will be conducted by Barun Kumar (Director, Mantran Consulting Pte Ltd), who is an experienced SAP security consulting professional and trainer &lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;, &amp;quot;sans-serif&amp;quot;; mso-ansi-language: EN-US; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: EN-US; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-language: EN-US;"&gt;with approximately 10 years of SAP security experience. He has conducted multiple SAP security trainings in Singapore, India and Indonesia&lt;/span&gt;. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;All participants will also be provided complimentary MANTRAN SAP security flashcard and self-learning aids through email upon successful registration.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;‘Certificate of Completion’ will be awarded upon successful completion of training and passing of online quiz after training.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Payment can be made using Paypal or direct bank transfer. Details of the payment options will be available soon on Mantran website (&lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://www.mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The detailed course content, schedule and fee are provided below.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;SAP-OL-001. Authorizations – Design and Review (SAP-OL-001)&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Date and time: 30 November 2010, 9:00 PM Singapore/ 6:30 PM India/ 4:00 PM Qatar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Duration: 4 hours (4 CPE hours)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Course content:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Importance of SAP authorizations &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP authorizations concept&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Authorization object and field&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Authorization&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Profile and role&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User master record&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Manual profile and generated profile&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Single and composite profile&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Single and composite role&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Authorization checks in SAP&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User buffer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Profile generator&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Prerequisites&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;How to use profile generator&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Advantages and concerns&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Important tables and transactions&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Important transactions, tables and reports&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Secure SAP authorization design&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP authorizations review&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Objectives&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Manual vs automated&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Native tools&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Commercial tools&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;SAP-OL-002. Segregation of Duties – Design and Review (SAP-OL-002)&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Date and time: 16 December 2010, 9:00 PM Singapore/ 6:30 PM India/ 4:00 PM Qatar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Duration: 2 hours (2 CPE hours)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Course content:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;What is Segregation of Duties (SoD)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Importance of SoD&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Underlying causes of SoD&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SoD framework&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Designing SoD framework&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Business rules&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Authorizations&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Other manual or automated controls&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Compensating controls&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Reviewing SoD&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Objectives&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Manual vs automated&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Native tools&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Commercial tools&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Compensating controls&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Participants are encouraged to complete SAP-OL-001 before taking this module.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;SAP-OL-003. BASIS/ Technical Controls in SAP (SAP-OL-003)&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Date and time: 20 January 2011, 9:00 PM Singapore/ 6:30 PM India/ 4:00 PM Qatar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Duration: 4 hours (4 CPE hours)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Course content:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Information security fundamentals&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;System parameters&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Access controls&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Password controls&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User types&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Standard users – SAP*, DDIC, SAPCPIC, EARLYWATCH&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Privileged profiles – SAP_ALL and SAP_NEW&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Standard user reports and tables&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Change controls&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP landscape, system and client&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;System and client settings&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Segregation of environments&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Transport organizer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Transport management system&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Developer Access Key&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Important authorizations and tables&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Scheduled jobs&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Audit logs&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Security audit logs&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Table logs&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Securing tables and reports&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Locking transactions&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Important transactions&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Please email at &lt;a href="mailto:trainings@mantranconsulting.com"&gt;trainings@mantranconsulting.com&lt;/a&gt; for details and registration.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2952307738873462293?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2952307738873462293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/11/sap-security-online-training-series.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2952307738873462293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2952307738873462293'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/11/sap-security-online-training-series.html' title='SAP Security Online Training Series'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_8Kwl4QcnngQ/TNDMmVf0VwI/AAAAAAAAEyo/e_1Gh7hCVrY/s72-c/Picture1.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-5875044898952511247</id><published>2010-10-30T14:59:00.000+08:00</published><updated>2010-10-30T14:59:55.439+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mantran Consulting'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>What is '&amp;NC&amp;' in authorization groups</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Access to specific tables and reports can be restricted using authorization groups. For example, if we consider that user 'JOHN' has access browse table using transaction SE16 but as user administrator, you want to restrict the access to only 10 specific tables. In SAP, these 10 tables can be assigned to one authorization group (let's say the authorization group 'ABCD'). When you create the role to be assigned to JOHN, you assign value 'ABCD' in the authorization group field for authorization objects S_TABU_DIS and S_TABU_CLI. This will ensure that JOHN can browse only these 10 tables which belong to authorization group 'ABCD'.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The same concept applies to reports as well. Table TRDIR stores the authorization groups for all tables while table TDDAT stores the authorization groups for all reports in SAP.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You may notice that some tables have no authorization groups - which basically means that any user with authorizations to browse tables can browse these tables. The user does not need any authorization group in her profile to browse these tables.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You may also notice that some tables have an authorization group '&amp;amp;NC&amp;amp;'. '&amp;amp;NC&amp;amp;' is slightly better from having a BLANK authorization group since only users with any authorization groups in their profile can access these tables. So, it doesn't matter what authorization group is specified in the user's profile - as long as there is an authorization group in the user profile, the user can access tables assigned to authorization group '&amp;amp;NC&amp;amp;'.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;So, it is best to have specific authorization groups assigned to each table you want to protect against unauthorized access. For others, at least have the authorization group as '&amp;amp;NC&amp;amp;' (Not the best option but still better than leaving it blank!)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-5875044898952511247?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/5875044898952511247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/10/what-is-in-authorization-groups.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5875044898952511247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5875044898952511247'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/10/what-is-in-authorization-groups.html' title='What is &apos;&amp;NC&amp;&apos; in authorization groups'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-6238192483476876326</id><published>2010-10-29T07:55:00.000+08:00</published><updated>2010-10-29T07:55:51.779+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP authorizations'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran Consulting'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>Restriction on number of roles assigned to users</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Many people ask me if there are any restriction on number of roles that can be assigned to a user and&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;whether this is a configurable setting.&lt;/span&gt; &lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP actualy does not restrict number of roles that can be assigned to a user. However, due to data structure of the table USR04 (which stores the profiles assigned to a user), maximum 312 profiles can be assigned to a user.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The maximum length of the field PROFS in table USR04, which stores profiles assigned to a users is 3750 characters. Out of this, first 2 characters are used for 'change indicator' ad therefore 3748 fields are available to store rofile names. The profile name can be 12 characters long and therefore, maximum profile that can be stored for a user is 312.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Change indicator indicates informatin about the status of the user (i.e., user created 'C' or user changed 'M'). &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Earlier, function module GET_AUTH_VALUES assumed that a user can be assigned maximum 300 profiles (although actually 312 profile assigments is technically possible). When more than 300 profiles were assigned to a user, the function module discarded all found profiles. This limitation was solved by SAP Note 841612, whcih provided a solution for increasing the number of usable profiles per user from 300 to the maximum value of 312.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;BTW, there is no restrictions on number of transactions that can be assigned to a role - just use the '*' wild character and you can assign all transactions to a role!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-6238192483476876326?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/6238192483476876326/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/10/restriction-on-number-of-roles-assigned.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6238192483476876326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6238192483476876326'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/10/restriction-on-number-of-roles-assigned.html' title='Restriction on number of roles assigned to users'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-8341186022678672750</id><published>2010-09-30T21:29:00.002+08:00</published><updated>2010-09-30T21:30:47.733+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BASIS controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>Developer Access Key</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP developers require two things before they can actually do development work in SAP - right authorizations and a developer access key. As with everything else in SAP, when a developer tries to execute a transaction, she will need the required authorizations in her profiles. In addition, she needs to be assigned a developer access key. The authorizations can be checked in the user master records while the developer access key can be checked using table DEVACCESS. Table DEVACCESS will show the user ID and the developer key assigned to the user ID. You should only expect to see name of developers in this table.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;But what happens when the entry for a developer is deleted in the DEVACCESS table but the developer continues to use the same user ID? The answer is that the developer can still use the old developer access key. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The reason: Developer access key is nothing but an algorithm based on system number and SID and some other system values (SAP does not reveal the information). The developer access key is validated by SAP using a Kernel level C system program ''CHECK_DEVELOPER_KEY'. So, even if the developer access key has been deleted for a user ID in the DEVACCESS table, she can still use the same developer access key.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;So the control should be to:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. If the developer still works in the company and only the job role has changed, remove the developer authorizations in the user master records.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. You may also want to assign a new user ID with the required access instead of using the existing user ID - just in case she gets the authorizations by mistake!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;One more suggestion, turn on table logging for table DEVACCESS to review all the changes.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-8341186022678672750?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/8341186022678672750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/09/developer-access-key.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8341186022678672750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8341186022678672750'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/09/developer-access-key.html' title='Developer Access Key'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-3119200259525388031</id><published>2010-09-26T13:57:00.000+08:00</published><updated>2010-09-26T13:57:23.280+08:00</updated><title type='text'>Logistics Invoice Verification - Blocking of Invoices</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;When an invoice is entered into SAP in purhcasing, the invoice may be blocked either manually or automatically. The automati block may be due to any of the following reasons:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. &lt;strong&gt;Variances&lt;/strong&gt; - Invoice may be blocked due to variance between invoice, goods receipt and purchase order. These variances are defined as 'Tolerance Keys' (refer IMG&amp;nbsp;&amp;gt; Materials Management&amp;nbsp;&amp;gt; Logistics Invoice&amp;nbsp;&amp;gt; Verfication Invoice Block&amp;nbsp;&amp;gt; Set Tolerance Limits). Each tolerance key defines the permissible variances for difference in quantity, price, schedule, etc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;2. &lt;strong&gt;Amount of an invoice item &lt;/strong&gt;- Invoice may be blocked if any item contains a large amount (refer IMG&amp;nbsp;&amp;gt; Materials Management&amp;nbsp;&amp;gt; Logistics Invoice&amp;nbsp;&amp;gt; Verfication Invoice Block&amp;nbsp;&amp;gt; Item Amount Check)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;3. &lt;strong&gt;Stochastic Block &lt;/strong&gt;- SAP can be configured to block automatically a random sample of invoices processed via invoice verification. This is referred to as ‘stochastic blocking’ and can be configured to block a specified percentage of all invoices or a percentage of all invoices above some threshold value (refer IMG&amp;nbsp;&amp;gt; Materials Management&amp;nbsp;&amp;gt; Logistics Invoice&amp;nbsp;&amp;gt; Verfication Invoice Block&amp;nbsp;&amp;gt; Set Stochastic Block)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When an invoice is blocked, it cannot be paid. Blocked invoice needs to be released before they can be paid.&lt;/span&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-3119200259525388031?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/3119200259525388031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/09/logistics-invoice-verification-blocking.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/3119200259525388031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/3119200259525388031'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/09/logistics-invoice-verification-blocking.html' title='Logistics Invoice Verification - Blocking of Invoices'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-6499048142873302066</id><published>2010-07-15T09:40:00.000+08:00</published><updated>2010-07-15T09:40:08.527+08:00</updated><title type='text'>SAP Security &amp; Controls Training | Bangalore, India | 11 - 12 Sep 2010</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN (&lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;www.mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;) is conducting SAP Security &amp;amp; Controls training workshop in Bangalore, India on 11 and 12 September 2010. The workshop is being organized in partnership with with CPA iRisk Advisors Pvt Ltd (&lt;/span&gt;&lt;a href="http://www.cpairiskadvisors.com/"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;www.cpairiskadvisors.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The workshop will primarily cover three areas – authorizations, segregation of duties and BASIS controls. The detailed content is as follows:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #20124d; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Module I: SAP authorizations and Segregation of Duties&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TD5l-wbKI9I/AAAAAAAAEyM/B-L1-FdTEhw/s1600/Module+I.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" rw="true" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TD5l-wbKI9I/AAAAAAAAEyM/B-L1-FdTEhw/s320/Module+I.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="color: #20124d; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Module II: BASIS Controls&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TD5mFZHEGxI/AAAAAAAAEyU/rW131ELYwVM/s1600/Module+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" rw="true" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TD5mFZHEGxI/AAAAAAAAEyU/rW131ELYwVM/s320/Module+2.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The workshop will be conducted by Barun Kumar, who is the founder and a Director with MANTRAN Consulting Pte. Ltd. Before starting MANTRAN, Barun was an Associate Director with IT Advisory practice of KPMG LLP in Singapore. Barun has previously worked as an AVP with Technology Risk Services practice of EXL Service and as Manager with IT Advisory practice of KPMG in India.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun is an engineer, MBA, CISA, Approva Certified Professional (ACP) and ITIL v3 certified professional.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has delivered many SAP trainings – both external trainings to corporate clients as well as internal trainings. The external training includes a large automobiles company in India, an engineering conglomerate in India and an airlines company in Singapore.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has more than 9 years of experience (including more than 8 years with Big 4) in SAP security services and has performed SAP security projects in India, Singapore, South Africa, Belgium, France, Switzerland, UK and US.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Barun has designed and audited SAP authorizations, SoD and BASIS controls for many large companies.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Apart from the SAP security and controls training slides, the participants will also receive the following &lt;span style="color: #660000;"&gt;complimentary deliverables&lt;/span&gt;:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• One-page SAP security flash card&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• SAP R/3 Report Navigator tool (summary of various useful SAP reports in a HELP file format)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• SAP Table Reference tool (summary of various useful SAP tables and their interrelationship with hyperlinks between tables for easy navigation)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Participation certificate will be provided to all participants.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Other details:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Date: &lt;span style="color: #660000;"&gt;11 and 12 September 2010&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Location: &lt;span style="color: #660000;"&gt;Bangalore&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Course fee: &lt;span style="color: #660000;"&gt;INR 15,000 per participant&lt;/span&gt; (Early bird discount of INR 1,500 applies for registration before 15 Aug 2010)&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Contact details:&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India: +91 (124) 435 4214 ( CPA iRisk Advisors Pvt Ltd, Level 4, Augusta Point, Golf Course Road, Gurgaon- HR- 122002)&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Singapore: +65 8118 9972 (Mantran Consulting Pte Ltd, 14 Robinson Road, #13-00 Far East Finance Building, Singapore 048545)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Email us at &lt;a href="mailto:trainings@mantranconsulting.com"&gt;trainings@mantranconsulting.com&lt;/a&gt; for registration form.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Visit &lt;/span&gt;&lt;a href="http://www.mantranconsulting.com/sap_sc_training.html"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://www.mantranconsulting.com/sap_sc_training.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; for further details.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-6499048142873302066?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/6499048142873302066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/sap-security-controls-training.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6499048142873302066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/6499048142873302066'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/sap-security-controls-training.html' title='SAP Security &amp; Controls Training | Bangalore, India | 11 - 12 Sep 2010'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_8Kwl4QcnngQ/TD5l-wbKI9I/AAAAAAAAEyM/B-L1-FdTEhw/s72-c/Module+I.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2529518751351428813</id><published>2010-07-14T22:37:00.000+08:00</published><updated>2010-07-14T22:37:11.750+08:00</updated><title type='text'>USer group 'SUPER'</title><content type='html'>The SUPER user group has a special status in the predefined user profiles. The users that are assigned to group SUPER can be maintained or deleted only by the new superuser that you define, provided that:&lt;br /&gt;&lt;br /&gt;1. You use the predefined profiles&lt;br /&gt;2. You follow SAP's other user and authorization maintenance recommendations.&lt;br /&gt;Authorizations can be restricted to specific user groups. &lt;br /&gt;&lt;br /&gt;User group SUPER: Assign all user and authorization administrator user IDs to the group SUPER. If you use the predefined user maintenance authorizations, this group assignment ensures that user administrators cannot modify their own user master records or those of other administrators. Users in group SUPER can be maintained only by administrators that have the predefined profiles S_A.SYSTEM or SAP_ALL.&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2529518751351428813?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2529518751351428813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/user-group-super.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2529518751351428813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2529518751351428813'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/user-group-super.html' title='USer group &apos;SUPER&apos;'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-731081636375210996</id><published>2010-07-12T16:58:00.000+08:00</published><updated>2010-07-12T16:58:46.650+08:00</updated><title type='text'>SAP Security Practices Survey 2010 Report - Protecting SAP*</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Here is another extract from the MANTRAN SAP Security Practices Survey Report 2010:&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP* is a special super user in SAP and has system-wide access. It is hard-coded in SAP, cannot be deleted and has special properties. These properties also create security issues, which needs to be addressed. Most organizations use multiple controls to secure SAP*. Surprisingly, only 54% organizations have changed the default password of SAP* and only 57% have disabled special property of SAP* (using parameter 'login/no_automatic_user_sap*').&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TDrZDaW91DI/AAAAAAAAEyE/H7pabUD0ZBc/s1600/Table+Logging.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" rw="true" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TDrZDaW91DI/AAAAAAAAEyE/H7pabUD0ZBc/s320/Table+Logging.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;There is no absolute ‘right’ way of securing SAP*. Usually it takes a combination of security controls to completely secure SAP*. Mantran recommends the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Configure parameter 'login/no_automatic_user_sap* to ‘Y’&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Remove powerful profiles from SAP*&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Change default password and lock the user ID.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-731081636375210996?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/731081636375210996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/sap-security-practices-survey-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/731081636375210996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/731081636375210996'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/07/sap-security-practices-survey-2010.html' title='SAP Security Practices Survey 2010 Report - Protecting SAP*'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_8Kwl4QcnngQ/TDrZDaW91DI/AAAAAAAAEyE/H7pabUD0ZBc/s72-c/Table+Logging.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-7136191512215982720</id><published>2010-06-24T00:48:00.003+08:00</published><updated>2010-07-14T22:32:27.906+08:00</updated><title type='text'>SAP Security &amp; Controls Training | 22 - 23 July | Singapore</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Mantran Consulting Pte Ltd is conducting a 2-day SAP security &amp;amp; controls workshop in Singapore on 22 and 23 July 2010. Please find attached the details in the attached brochures.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Course Content: &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The workshop will primarily cover three areas – authorizations, segregation of duties and BASIS controls. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Module I: SAP authorizations and Segregation of Duties&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_8Kwl4QcnngQ/TCI5fEtkjWI/AAAAAAAAExM/ZLodRjAY6no/s1600/Day1.jpg" imageanchor="1" style="cssfloat: left; margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="276" ru="true" src="http://1.bp.blogspot.com/_8Kwl4QcnngQ/TCI5fEtkjWI/AAAAAAAAExM/ZLodRjAY6no/s400/Day1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Module II: BASIS Controls&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TCI5u-KjprI/AAAAAAAAExU/1ihkP9AaRgk/s1600/Day2.jpg" imageanchor="1" style="cssfloat: left; margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="147" ru="true" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/TCI5u-KjprI/AAAAAAAAExU/1ihkP9AaRgk/s400/Day2.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Deliverables&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Apart from the SAP security and controls training slides, the participants will also receive the following complimentary deliverables:&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• One-page SAP security flash card&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• SAP R/3 Report Navigator tool (summary of various useful SAP reports in a HELP file format)&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• SAP Table Reference tool (summary of various useful SAP tables and their interrelationship with hyperlinks between tables for easy navigation)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Participation certificate will be provided to all participants.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Registration Details&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Date: 22 and 23 July 2010&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Course fee: SGD 1,200 per participant&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Payment options: Payment can be made by crossed cheque to Mantran Consulting Pte. Ltd. or direct transfer to the following account:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Account Name: Mantran Consulting Pte Ltd&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Bank Name: OCBC/ Bank Code: 7339/ Branch Code: 612&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Swift Code: OCBCSGSG&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;Account Number: 612860379001&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Cancellation and refund policy&lt;/strong&gt;: Mantran Consulting Pte Ltd reserves the right to change the venue, date, speakers, and program or cancel the program. A full refund of fees will be made in the event of cancellation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;If you are interested in the training, please contact us at &lt;a href="mailto:training@mantranconsulting.com"&gt;training@mantranconsulting.com&lt;/a&gt; or Barun Kumar at +65 8118 9972.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Mantran Consulting Pte. Ltd.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;14 Robinson Road #13-00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Far East Finance Building&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Singapore 048545&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Tel. +65 6401 5160&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Fax. +65 6323 1839&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Web. www.mantranconsulting.com &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-7136191512215982720?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/7136191512215982720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/06/sap-security-controls-training-22-23.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7136191512215982720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7136191512215982720'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/06/sap-security-controls-training-22-23.html' title='SAP Security &amp; Controls Training | 22 - 23 July | Singapore'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_8Kwl4QcnngQ/TCI5fEtkjWI/AAAAAAAAExM/ZLodRjAY6no/s72-c/Day1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-4496750852302837978</id><published>2010-06-05T13:43:00.000+08:00</published><updated>2010-06-05T13:43:09.020+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP security survey'/><title type='text'>SAP Security Practices Survey Report - 2010</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN has released its first SAP Security Practices Survey Report. The are being sent to the participants. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;One of the main findings from the survey is that the general awareness about business process controls in SAP is less compared to technical controls (i.e., BASIS and authorizations). &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;For example, 'stochastic block' for invoice checks and 'PMIN' for pricing are not used by a large number or organizations. 81% organizations are not using 'stochastic block' for invoice checks. This included 16% organizations, which said that they do not need this functionality. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TAnjV81boxI/AAAAAAAAEwo/pdWSvgq6o7s/s1600/StochasticBlock.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" gu="true" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TAnjV81boxI/AAAAAAAAEwo/pdWSvgq6o7s/s320/StochasticBlock.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Vendor invoices can be randomly blocked for further checks. If the stochastic block is active and an invoice, which is not subject to any other blocking reason, is posted, it can be randomly selected for blocking. Stochastic block is not set at item level, but for the whole invoice. If a stochastic block is set when the invoice is posted, SAP automatically sets an ‘R’ in the field ‘Payment Block’ in the document header data. There is no blocking indicator in the individual items.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;84% organizations do not use 'PMIN' for pricing. This includes 24%, who said that they do not need this functionality.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TAnjb5P7MaI/AAAAAAAAEww/eMBb0CRoy2M/s1600/PMIN.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" gu="true" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/TAnjb5P7MaI/AAAAAAAAEww/eMBb0CRoy2M/s320/PMIN.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;When pricing is done for a sales document line item, if the net price of the item falls below the minimum, the system should automatically compute a surcharge to bring the price up to the minimum price. The minimum price can be defined using condition type PMIN. The system compares the minimum price with the net price calculated to that point in the pricing procedure. If the minimum price is not met, the system computes the necessary surcharge and assigns it to the PMIN condition line.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;I will continue to bring more snippets from the survey report in my blogs in coming weeks. If you wish to receive a copy of the report, please email me at &lt;a href="mailto:barunkumar@mantranconsulting.com"&gt;barunkumar@mantranconsulting.com&lt;/a&gt;. Visit &lt;a href="http://www.mantranconsulting.com/survey.html"&gt;http://www.mantranconsulting.com/survey.html&lt;/a&gt; for more details on the survey.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-4496750852302837978?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/4496750852302837978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/06/sap-security-practices-survey-report.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4496750852302837978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4496750852302837978'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/06/sap-security-practices-survey-report.html' title='SAP Security Practices Survey Report - 2010'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_8Kwl4QcnngQ/TAnjV81boxI/AAAAAAAAEwo/pdWSvgq6o7s/s72-c/StochasticBlock.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-3992506985524085369</id><published>2010-05-19T10:28:00.000+08:00</published><updated>2010-05-19T10:28:53.761+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security Training'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran Consulting'/><category scheme='http://www.blogger.com/atom/ns#' term='Mantran'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>SAP Security and Controls Training Schedule for 2010</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Security and controls in SAP is a complex area and requires specialized knowledge and training. SAP provides highly granular and detailed security and controls functionalities, which can be configured as per organization’s requirements. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Some of the key concepts in SAP security &amp;amp; controls are as follows: &lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;SAP architecture&lt;/span&gt;: A typical SAP system is based on three-tier architecture. SAP provides flexibility in designing system landscape, which can be very complex for large organizations. SAP is compatible with all major hardware, OS, and database. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Authorizations&lt;/span&gt;: SAP authorization concept allows users to perform their work while securing transactions and programs from unauthorized access. It is a complex and scalable concept where approximately 2,000 authorization objects controls access to more than 100,000 transactions. The authorization components include user master records, roles (single and composite), profiles, authorizations, authorization objects and field values (activity, organization value, etc) and can be customized to organization’s requirement. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Segregation of Duties (SoD)&lt;/span&gt;: SoD ensures that no one individual has complete control over major phase of a process and is enforced through a combination of authorizations and mitigating controls. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Profile parameters&lt;/span&gt;: Profile parameters control various security functionalities such as password controls, session security, auditing, etc. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Super users&lt;/span&gt;: SAP is shipped with many default super users, which serve specific purpose. It is important to secure these users. In addition to changing default passwords, additional measures are required for some super users like SAP*. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Auditing&lt;/span&gt;: Auditing is an important tool and SAP provides multiple auditing options. Some of the auditing features are change documents, document flow, security audit logs, table logs, transaction usage logs, etc. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Change management&lt;/span&gt;: Client setting and transport path are important to control unauthorized changes in SAP. Client setting can help ensures that changes cannot be made directly in SAP production system. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Our SAP security and controls training covers all these concepts and more.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/font&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Why attend this training? &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;As more and more organizations use SAP to support their business processes, there is a growing need for SAP security &amp;amp; controls professional. Global demand for SAP security &amp;amp; controls professionals is increasing and this workshop is a big step in becoming one. &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;This SAP Security &amp;amp; Controls workshop covers various key concepts in SAP security &amp;amp; controls. This workshop aims to equip participant with in-depth understanding of key aspects of SAP security and controls. The workshop includes live demo and hands-on exercises to assist participant in applying the learning. &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Some of the benefits of attending this workshop are as follows: &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Gain in-depth knowledge of SAP security and controls functionalities &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Simulate real life scenarios in dealing with security and controls issues in SAP &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Real-time demos and exercises to demonstrate key concepts &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Complementary SAP security &amp;amp; controls aids. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;All participants will receive a certificate of attendance upon successful completion of the training.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Training Schedule &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #660000;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The training schedule for June – Aug 2010 is as follows: &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Singapore: 17 – 18 June 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Bangalore: 25 – 26 June 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Pune: 9 – 10 July 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Mumbai: 23 – 24 July 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – New Delhi: 6 – 7 Aug 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Coimbatore: 29 – 30 June 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Cochin: 27 – 28 July 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;India – Kolkata: 9 – 10 August 2010&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Malaysia – Kuala Lumpur: 16 – 17 July 2010&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #660000;"&gt;Notes&lt;/span&gt;: &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;The training does not cover the controls related to various business processes such as sales, purchase and financial accounting. The schedule for SAP business process controls training will be released separately.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;We also provide in-house corporate SAP security &amp;amp; controls trainings covering these areas and various business process controls. Please email us at trainings@mantranconsulting.com for in-house corporate trainings.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Mantran Consulting Pte Ltd reserves the right to change the venue, date, speakers, and program or cancel the program. A full refund of fees will be made in the event of cancellation.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Registration/ Inquiry &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;To ensure good learning environment and allow participants to interact with the trainers, we restrict the number of participants for each training. Training seats are awarded on first come first serve basis. Therefore, please register at the earliest. Registration can be confirmed only after receipt of payment. &lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Please contact us at &lt;a href="mailto:trainings@mantranconsulting.com"&gt;trainings@mantranconsulting.com&lt;/a&gt; to receive detailed information about the training course content, fees and registration.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-3992506985524085369?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/3992506985524085369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/sap-security-and-controls-training.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/3992506985524085369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/3992506985524085369'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/sap-security-and-controls-training.html' title='SAP Security and Controls Training Schedule for 2010'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-8836015991019454352</id><published>2010-05-18T16:11:00.002+08:00</published><updated>2010-05-18T16:14:44.342+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='Segregation of Duties'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SOD'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><title type='text'>Who is responsible for SoD - business or IT?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Who is responsible for Segregation of Duties (&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt;) - business or IT? Most of the organizations debate this some point of time in their journey to establish a sustainable &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; framework. And it is often a difficult question to answer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP authorizations are maintained by SAP team (i.e., IT team) - so, some say, &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; should also be their responsibility. But the authorizations are decided and approved by business - SAP team only implements what is told to them by business. Therefore, other say, &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; is the responsibility of business.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;And it is not unusual for anyone to be willing to take up the responsibility. After all, &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; is one of the most common audit issues these days. And whoever takes the responsibility is sure of getting some flak for the issues. &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; is not a simple thing to implement - it takes a lot of planning, continuous monitoring and improvement to sustain. Therefore, the results take time to show up. The flak, in most cases, will come faster than the result. And that's the reason no one wants to be &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;responsi&lt;/span&gt;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;ble&lt;/span&gt; for &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt;, in my view,&amp;nbsp;is a techno-functional area, which requires close coordination between business/ functional&amp;nbsp;and IT/ SAP teams. The organization need to understand the concerns of each party involved in implementing and managing &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; and ensure that their concerns are addressed. The business team should be provided enough time and resources to come up with a good &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; rule/ matrix and the IT team to implement it. There are no quick fixes to &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; - not only takes lots of resources and time to implement, it takes continuous support from both business and IT to sustain it. Business needs to take decisions regarding the potential conflicts - whether to accept the risk or &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;remediate&lt;/span&gt; it. They often need to decide the right remediation - change in user access rights or change in business process or a new mitigating control. IT need to continuously monitor user access rights to identify any potential conflict. This requires strict adherence to user and role management.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Here is my prescription to the problem.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_8Kwl4QcnngQ/S_JMLcDzOpI/AAAAAAAAEkk/ljaY8g351z8/s1600/SoD.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="271" src="http://1.bp.blogspot.com/_8Kwl4QcnngQ/S_JMLcDzOpI/AAAAAAAAEkk/ljaY8g351z8/s400/SoD.jpg" width="400" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The last box can be a dedicated role, which can be assigned to business, IT or a separate team.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;Mantran&lt;/span&gt; Consulting &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;Pte&lt;/span&gt; Ltd provides specialized &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; consulting services. Visit &lt;a href="http://www.mantranconsulting.com/segregation.html"&gt;http://www.&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;mantranconsulting&lt;/span&gt;.com/segregation.html&lt;/a&gt; for details.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-8836015991019454352?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/8836015991019454352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/who-is-responsible-for-sod-business-or.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8836015991019454352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8836015991019454352'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/who-is-responsible-for-sod-business-or.html' title='Who is responsible for SoD - business or IT?'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_8Kwl4QcnngQ/S_JMLcDzOpI/AAAAAAAAEkk/ljaY8g351z8/s72-c/SoD.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-1112793611818101773</id><published>2010-05-06T12:10:00.000+08:00</published><updated>2010-05-06T12:10:42.278+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP GRC tool'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Auditing'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP CAM'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit Tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Monitoring'/><title type='text'>CAM for SAP - some screenshots</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Here are some screenshots of Mantran's Continuous Auditing/ Monitoring (CAM) for SAP tool.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_8Kwl4QcnngQ/S-AcFsdcduI/AAAAAAAAEjs/4KHY-cXDW7I/s1600/Slide1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_8Kwl4QcnngQ/S-AcFsdcduI/AAAAAAAAEjs/4KHY-cXDW7I/s320/Slide1.JPG" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AcHwmVECI/AAAAAAAAEj0/pb5W8luWNVM/s1600/Slide2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AcHwmVECI/AAAAAAAAEj0/pb5W8luWNVM/s320/Slide2.JPG" tt="true" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_8Kwl4QcnngQ/S-AcJhiPWRI/AAAAAAAAEj8/fmuug6HRiJ8/s1600/Slide3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_8Kwl4QcnngQ/S-AcJhiPWRI/AAAAAAAAEj8/fmuug6HRiJ8/s320/Slide3.JPG" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AcLPIjd9I/AAAAAAAAEkE/ZKyBgMKimRE/s1600/Slide4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AcLPIjd9I/AAAAAAAAEkE/ZKyBgMKimRE/s320/Slide4.JPG" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AcWKifeEI/AAAAAAAAEkM/gEOakw0iPyY/s1600/Slide5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AcWKifeEI/AAAAAAAAEkM/gEOakw0iPyY/s320/Slide5.JPG" tt="true" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AcYHZs04I/AAAAAAAAEkU/VPHDw3Cevfk/s1600/Slide6.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AcYHZs04I/AAAAAAAAEkU/VPHDw3Cevfk/s320/Slide6.JPG" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-1112793611818101773?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/1112793611818101773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/cam-for-sap-some-screenshots.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/1112793611818101773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/1112793611818101773'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/cam-for-sap-some-screenshots.html' title='CAM for SAP - some screenshots'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_8Kwl4QcnngQ/S-AcFsdcduI/AAAAAAAAEjs/4KHY-cXDW7I/s72-c/Slide1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-1467737908381577172</id><published>2010-05-05T09:19:00.001+08:00</published><updated>2010-05-05T09:28:54.714+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP GRC tool'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Auditing'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP tool'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security and Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP GRC'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Monitoring'/><title type='text'>Continuous Auditing/ Monitoring (CAM) for SAP</title><content type='html'>&lt;span style="color: #660000; font-family: Verdana, sans-serif; font-size: x-small;"&gt;As promised in my blog on 5 Mar, we are ready to launch the Continuous Auditing/ Monitoring (CAM) tool. Here is a snapshot of the tool. The official website: &lt;a href="http://www.mantranconsulting.com/products.html"&gt;http://www.mantranconsulting.com/products.html&lt;/a&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AaFTRiClI/AAAAAAAAEjk/B7uaQdqyojQ/s1600/CAM_Logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AaFTRiClI/AAAAAAAAEjk/B7uaQdqyojQ/s320/CAM_Logo.jpg" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Organizations are under increased pressure to cut costs and improve efficiencies. Internal audit is no different – audit committees and management increasingly expect their internal audit teams to do more with even lesser resources. CAM for SAP is an effective tool to enhance audit coverage (scope as well as frequency) without adding additional manpower. CAM also enables organizations to audit and monitor their key risk areas more frequently without too much of additional effort. This is possible due to use of technologies, which considerably reduces the cost of automating recurring audit procedures. CAM can also act as an early warning system to detect control failure earlier than under traditional audit approaches.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Both transaction processing and controls can be audited/ monitored using CAM. Examples of transaction processing auditing/ monitoring include the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Billing documents blocked for accounting&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Changed bank account numbers in vendor master&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Open purchase orders&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Invoice numbers allocated twice, etc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Examples of controls auditing/ monitoring include the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. GL accounts where manual postings are allowed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. One time vendors&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Material masters with unlimited over delivery tolerance&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Customers without credit limit, etc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Unlike most of the commercially available tools, which are complex, require lots of resources to implement/ manage/ use and are very expensive, CAM for SAP is an easy to use, easy to manage and no security hassles tool.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AZ-D3ok3I/AAAAAAAAEjc/vqLi7WhhQv4/s1600/CAMBenefit.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_8Kwl4QcnngQ/S-AZ-D3ok3I/AAAAAAAAEjc/vqLi7WhhQv4/s320/CAMBenefit.jpg" tt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;CAM is a useful tool for SAP auditors who want to focus on auditing and don’t want to be distracted by technical details of a complex commercial tool. CAM is intuitive to use tool and does not require any specialized training to use. It also does not require a separate hardware and can be installed on any PC or laptop.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;It comes with a ready-to-use configuration and auditors can start using it from day one. At the same time, the tool is highly customizable and can be easily and quickly customized, when required. Further, it works in an offline mode (i.e., without directly connecting to your SAP system).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Most important, CAM is very cost effective and caters to small and medium size enterprises using SAP.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The tool consists of two main areas:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Import Table(s) - ‘Import Table(s)’ function allows users to upload various tables required for audit/ monitoring. These tables can be downloaded from SAP using transaction code SE16. No external formatting is required to use these tables in CAM. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Reports - ‘Reports’ function allows users to view various reports highlighting potential exceptions in transaction processing and controls. The reports are arranged process-wise and can be downloaded for further analysis and follow up.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;SPECIFICATIONS&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #20124d;"&gt;&lt;u&gt;OS:&lt;/u&gt;&lt;/span&gt; Windows XP Service Pack 2 and above&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="color: #20124d;"&gt;&lt;u&gt;Software required:&lt;/u&gt;&lt;/span&gt; Microsoft Access 2007 Runtime or Microsoft Access 2007 (Microsoft Access 2007 Runtimes can be downloaded directly from Microsoft website.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;There are five modules within ‘Reports’ tab. These are as follows:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Master Data &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Purchasing &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Sales &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Financial Accounting (FI)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. Others&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The following four modules will be added in the next version of the tool:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Inventory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Human Resources – Payroll (HR-PY)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Authorizations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Configurations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;BENEFITS&lt;/strong&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In addition to ever-increasing technology and regulatory requirements, organizations are looking to remove excess costs from operations and improve efficiency, improve controls and processes, and prevent and detect fraud and misconduct. CAM offers following benefits to support these requirements:&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Regular insight into status of transaction processing and controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Early detection and monitoring to expedite response&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Test a broader range of transactions and controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Improved audit efficiency and effectiveness&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. Better internal controls.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;DEMO/ PURCHASE&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;If you are interested in demo of CAM for SAP or need a quotation, please contact us.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Email – CAM@mantranconsulting.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Phone - +65 6401 5160&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Our team will contact you within three working days to arrange for a demo/ discussions.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-1467737908381577172?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/1467737908381577172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/continuous-auditing-monitoring-cam-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/1467737908381577172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/1467737908381577172'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/continuous-auditing-monitoring-cam-for.html' title='Continuous Auditing/ Monitoring (CAM) for SAP'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_8Kwl4QcnngQ/S-AaFTRiClI/AAAAAAAAEjk/B7uaQdqyojQ/s72-c/CAM_Logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-5152245338116268539</id><published>2010-05-04T15:37:00.000+08:00</published><updated>2010-05-04T15:37:27.841+08:00</updated><title type='text'>Deadline for SAP Security Practices Survey 2010 extended till 10 May</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The deadline for Mantran's first SAP Security Practices Survey has been extended to 10 May 2010. This is the last opportunity for those who have not yet submitted their responses. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;SAP Security Practices Survey 2010 aims to identify the most successful practices in managing and reviewing SAP security controls. The result will be an important aid to anyone trying to &lt;span style="font-family: Verdana, sans-serif;"&gt;design, manage, review or fix security controls in their SAP system. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;How to participate?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Online: If you prefer to complete the questionnaire online, please click HERE. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Interview: You can request one of our consultants to meet you to complete questionnaire. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Email: You can request us to send the questionnaire through email.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Post: You can request us to send a printed questionnaire for completion.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;All the information provided will be on ‘no name’ basis and will not be disclosed without your prior permission.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-5152245338116268539?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/5152245338116268539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/deadline-for-sap-security-practices.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5152245338116268539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5152245338116268539'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/05/deadline-for-sap-security-practices.html' title='Deadline for SAP Security Practices Survey 2010 extended till 10 May'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-4706776711343640168</id><published>2010-04-26T11:45:00.000+08:00</published><updated>2010-04-26T11:45:45.731+08:00</updated><title type='text'>SAP Security Practices Survey 2010</title><content type='html'>&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;How do organizations manage security in their SAP implementation? What are the major SAP security concerns faced by organizations? Are SAP security personnel adequately trained? &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP Security Practices Survey 2010 aims to identify the most successful practices in managing and reviewing SAP security controls. &lt;span style="color: #660000;"&gt;The survey is fast approachig its deadline for participation. We are encouraged by the responses so far and would urge all SAP security practitioner to spend 10-15 minutes completing the survey form.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Security controls in SAP is one of the more complex areas and requires special focus to implement, manage and review. Organizations have varying perception of risks and therefore, they have a range of practices to manage SAP security. This survey aims to understand the most common SAP security practices and will attempt to identify the most successful practices in this area. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;What is the optimal size of SAP security team? How often should the SAP security controls be reviewed? Do organizations enable table logging in SAP? What kinds of changes are performed directly in production environment? How many organizations use PO/ PR approval in SAP? Do organizations use ‘dual control’ for changes to vendor and customer master? How many organizations have documented SoD matrix? &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;These are some of the questions that many SAP security practitioners ask and often fail to get an answer. MANTRAN’s SAP Security Practices Survey 2010, which is first such survey, aims to find answers to such questions related to SAP security controls. The result will be an important aid to anyone trying to design, manage, review or fix security controls in their SAP system. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Specifically, the SAP Security Practices Survey 2010 aims to understand the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• Risks and threats faced by organizations using SAP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• Industry perception of required SAP security controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• SAP security practices&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;• How auditors perceive and review SAP security controls?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;How to participate?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Online: If you prefer to complete the questionnaire online, please click &lt;a href="http://spreadsheets.google.com/viewform?formkey=dGpiMUY4NjQzQlY1WFB1ZzFYSURaMXc6MA"&gt;HERE&lt;/a&gt;. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Interview: You can request one of our consultants to meet you to complete questionnaire. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Email: You can request us to send the questionnaire through &lt;a href="mailto:survey2010@mantranconsulting.com"&gt;email&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Post: You can request us to send a printed questionnaire for completion.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;All the information provided will be on ‘no name’ basis and will not be disclosed without your prior permission.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Why participate?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Whether you are SAP professional, SAP security practitioner, SAP auditor or other stakeholder in your organization’s SAP system, you are interested in having a secure SAP system. The survey results will enable you to make more informed decisions about the security practices that you deploy for your SAP system. You can also benchmark your SAP security practices against other organizations. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Apart from receiving a copy of survey report, as a participant, you will receive the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Complimentary invitation to special ‘breakfast talk’, where the results of the survey will be presented and analyzed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Customized survey report – with special focus on areas relevant for your organization&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Specially printed SAP Security Flashcards (free shipment only in Singapore and India).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue; font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;About MANTRAN&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN’s SAP Consulting Services address risks across all phases of the SAP lifecycle and focus on business process, SAP security, data integrity and SAP administration. We also provide SAP security and controls trainings. Visit us at &lt;a href="http://www.mantranconsulting.com/"&gt;http://www.mantranconsulting.com/&lt;/a&gt;for more details.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-4706776711343640168?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/4706776711343640168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/04/sap-security-practices-survey-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4706776711343640168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4706776711343640168'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/04/sap-security-practices-survey-2010.html' title='SAP Security Practices Survey 2010'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-9007150112396376385</id><published>2010-03-28T01:20:00.002+08:00</published><updated>2010-03-28T01:21:47.547+08:00</updated><title type='text'>Segregation of Duties - What, Why and How?</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Segregation of Duties (&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt;) requires that no one individual or related individuals should have complete control over a major phase of a process. Work should proceed from one person to another so that, without duplication, the work of the second acts as a recorded verification of the work of the first. Examples include&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Person authorizing the use of an asset should not be responsible for its custody or derive any real or conceived benefits from the use of the asset &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Record keeping and bookkeeping activities should be separated from handling and/ or custody of assets&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; is a key component of any effective internal control environment. It is preventive as well as a detective internal control. It reduces the likelihood of errors and irregularities.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In the context of SAP system, existence of &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; should be checked at the following levels:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Definition of roles/ composite roles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Assignment of roles/ profiles to user master record&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Underlying causes of &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; conflicts&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Some of the underlying causes of &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; conflicts in SAP system are as follows:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Lack of understanding&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Lack of&amp;nbsp;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; framework&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Permission creep&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Complexity of SAP authorization concept&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Failure of security administration process&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Poor design of user access request form&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Dynamic pace of organizational change&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Security is not first thing on mind of business managers/ users&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Lack of security ownership (falls in gap between IT and business)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Lack of business knowledge of security administrators&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Limited delivered SAP &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; security reporting&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP provides native tools for &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; check in form of transactions SU98/ SU99, which only checks access at transaction code.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Mitigate &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; risk&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Organizations should create a comprehensive &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; framework, which should include&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Business rules (&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; Matrix)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; checks&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Real time – when access is granted&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Review – regular basis&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Conflict resolution&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Remove conflicting access&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Compensating controls&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Clearly defined roles and responsibilities&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;It is important to ensure that ‘compensating controls’ are appropriate and they work. Compensating controls require close coordination between IT and business. It should be &lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Based on risk exposure (critical/ high/ medium/ low)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Document and assign to business owners&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;System-based/ automated where possible, to maximize use of SAP and minimize manual intervention&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Tested regularly&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;Tools - how helpful are they?&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;There are many automated tools, which assists organization is managing &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; in SAP system access. While these are very useful tools and goes a long way in making the process more efficient and transparent, they do not in themselves present a solution.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Organizations still need to come up with a &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; framework. Once the framework is there, these tool help them implement and sustain the framework. Remember, the tools (as usual!) are just enablers - they are the solution to your &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; problems.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Verdana;"&gt;&lt;strong&gt;Final words&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Please note that there are no Silver bullet to prevent &lt;span class="goog-spellcheck-word" style="background: yellow;"&gt;SoD&lt;/span&gt; in SAP system access. As long as organizations identify the cause and fix them (instead of addressing the symptoms), they should be able to control any risks. &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-9007150112396376385?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/9007150112396376385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/segregation-of-duties-what-why-who-and.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/9007150112396376385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/9007150112396376385'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/segregation-of-duties-what-why-who-and.html' title='Segregation of Duties - What, Why and How?'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2782808135561251230</id><published>2010-03-22T11:20:00.001+08:00</published><updated>2010-03-22T11:21:32.026+08:00</updated><title type='text'>Some useful BASIS reports</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Here are some of the not so popular, but useful BASIS reports that I recently came across&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;PFCG_AGRS_WITH_MANUAL_S_TCODE&lt;/strong&gt;: List All Roles with Manual S_TCODE Authorization&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;AGR_CHECK_AUTHS_DUPLICATES&lt;/strong&gt;:&lt;strong&gt; &lt;/strong&gt;Checking Duplicate Authorizations in Profiles&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;AGR_CHECK_ALL_ACTIVITY_GROUPS&lt;/strong&gt;: Old roles check report&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;PFCG_MASS_DOWNLOAD&lt;/strong&gt;: Bulk role download&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;PFCG_MASS_IMPORT&lt;/strong&gt;: Bulk role import&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope you find them useful.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2782808135561251230?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2782808135561251230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/some-useful-basis-reports.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2782808135561251230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2782808135561251230'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/some-useful-basis-reports.html' title='Some useful BASIS reports'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-5543890700916425648</id><published>2010-03-18T17:35:00.001+08:00</published><updated>2010-03-18T17:36:10.818+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit Logs'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>Monitoring business transactions and controls in SAP</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;How does SAP compare with other ERP systems when it comes to its functionalities to let users monitor business transactions?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The broad answer, it seems, is that it is the better ERPs in this sense. SAP provides lots of logging and audit trails. In addition, the table structure is quite transparent and an organization can easily develop ABAP programs to read data from respective tables and generate reports for monitoring. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP prpvides very granular transaction and controls monitoring functionalities. The key functionalities are as follows:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Change documents&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Docuemtn flow&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Security audit logs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. System logs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. CCMS&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;6. Table logs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;7. Transaction usage logs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;8. System trace&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;These functionalities together lets a user keep complete track of everything that goes on inside SAP system. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Here is a brief introduction to these functionalities:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Change documents - SAP maintain change documents for many information. These are maintained by default and can be accessed via reports or direct table access. Some example include changes to user master records&amp;nbsp;(report RSUS100), changes to material master records (transaction MM04). Also,&amp;nbsp;tables CDHDR and CDPOS together captures changes to most of the transactional and master data in SAP.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Document flow - SAP maintains and lets user view the flow of documents in certain areas. For example, for a sales document, user can view the entire cycle (i.e., order, delivery document, invoice, clearing and reversal, if any) using a simple document flow feature.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Security audit logs - It keeps record of all security related activities in SAP. These can be turned on/ off and the extent of audit logs can be determined by organizations. This will typically log activiites like user logon/ log off, transactin start, RFC logons, etc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. System logs - It records all system errors, warnings, user locks due to failed log-on attempts and process messages.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. CCMS - It provides a range of monitors for monitoring the SAP environments and its components. It includes early diagnosis of potential problems, such as resource problems in a host or database system, which could affect the SAP system.&lt;br /&gt;6. Table logs - Logging for changes to specific tables can also be logged. This is an optional feature in SAP.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;7. Transaction usage logs - SAP maintains log pf all transactions started by users.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;8. System trace - It records the internal SAP system activities, use the function SAP System Trace. Recording the processes in your application server enables you to monitor the system and facilitates troubleshooting.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;---------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Mantran provides detailed trainings about various auditing functionalities in SAP and how they can be used for audits, forensics, etc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Please contact us at &lt;/span&gt;&lt;a href="mailto:trainings@mantranconsulting.com"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;trainings@mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; for more details or any enquiries on SAP security and controls trainings.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-5543890700916425648?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/5543890700916425648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/monitoring-business-transactions-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5543890700916425648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5543890700916425648'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/monitoring-business-transactions-and.html' title='Monitoring business transactions and controls in SAP'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-7785420563594128218</id><published>2010-03-05T09:45:00.001+08:00</published><updated>2010-03-05T09:45:21.608+08:00</updated><title type='text'>Continuous Auditing/ Monitoring (CAM) tool - suggestions required!</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I am working on a tool to assist internal audit/ SAP security teams in transaction, process and controls auditing. The tool is 75% complete and I am currently finalizing the reports section. Some e&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;xamples of the reports included in the tool are as follows:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Transaction and process monitoring/ auditing:&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Billing documents blocked for accounting&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Changed bank account numbers in vendor master&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Open purchase orders&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Invoice numbers allocated twice, etc.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Controls monitoring/ auditing:&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;GL accounts where manual postings are allowed&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;One time vendors&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Material masters with unlimited over delivery tolerance&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Customers without credit limit, etc.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I would like to invite suggestions from internal audit/ SAP security community for various reports, whcih should be included. I would appreciate any suggestions - just drop a note with the report requirements and I will work on the logic and how to get the report running for you.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Feel free to contact me at &lt;a href="mailto:barunkumar@mantranconsulting.com"&gt;barunkumar@mantranconsulting.com&lt;/a&gt; for any discussions.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-7785420563594128218?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/7785420563594128218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/continuous-auditing-monitoring-cam-tool.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7785420563594128218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/7785420563594128218'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/03/continuous-auditing-monitoring-cam-tool.html' title='Continuous Auditing/ Monitoring (CAM) tool - suggestions required!'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-4536081259364565145</id><published>2010-02-27T13:10:00.002+08:00</published><updated>2010-02-27T13:19:41.577+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BASIS controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SOD'/><title type='text'>Restrict SAP user administration from managing his own access and Segregation of Duties in user administration</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;How to protect from one's protector? In other words - &lt;strong&gt;&lt;em&gt;how to restrict the access of its user administrators&lt;/em&gt;&lt;/strong&gt;? This is the question faced by most of the organizations. The answer is quite simple in SAP system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The access can be easily controlled using an authorization object called S_USER_GRP. This authorization object has two fields – user groups and activity. The activity code can have following values:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;01: Create user master records, add profiles to new or existing records, and set user defaults for the Basis System and applications&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;02: Change user master records&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;03: Display a user master record with the information system&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;05: Lock or unlock a user (prevent or allow logons); change passwords&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;06: Delete user master records&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;08: Display change documents&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;22: Record users in activity groups&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;24: Archive change documents.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You need to segregate the user administrator user ID into a separate user group and other users into other user groups. The user administrator should not be assigned the user group that he belongs to.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Havig said that, it will also need some segregation of duties in user adminstration activities. If the user administrator has access to create a new user and assign him a user group, he may be able to bypass this control. Ideally, the following three group of functions should be segregated:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User administration - Create and delete user master records&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Authorization administration - Create roles (select transactions and maintain authorization data) and generate profiles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User maintenance - Assign roles/ profiles to user master records and change user master records (except own user master records)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Depending on the size of BASIS/ user administration team, you can have the following three scenarios:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Segregate User Administrator, Authorization Administrator and User Maintenance&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;User Administrator and Authorization Administrator is same and is segregated from User Maintenance&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;No segregation possible – establish mitigating controls (e.g., regular review of all user administration activities)&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The last point also highlights the importance of detective controls. Small organizations, who cannot have the required segregation, can always establish strong detective controls to ensure that lack of segregation cannot be misused.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Other important authorization objects related to user adminstration are as follows:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;S_USER_AGR - roles &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;S_USER_TCD - transactions&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;S_USER_PRO - profiles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;S_USER_AUT - authorization objects and authorizations&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;S_USER_VAL - fields in authorization objects&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The detective controls shoudl include regular review of user authorizations by relevant business owners. This should include:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span id="goog_1267246468712"&gt;&lt;/span&gt;&lt;span id="goog_1267246468714"&gt;&lt;/span&gt;&lt;span id="goog_1267246468716"&gt;&lt;/span&gt;&lt;span id="goog_1267246468718"&gt;&lt;/span&gt;&lt;span id="goog_1267246468720"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Current roles assigned to users&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Current authorizations within roles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Changes in roles assigned to users&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Changes in authorizations within roles&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Inactive users (i.e., users with no system activities for a prolonged period of time)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Segregation &lt;span id="goog_1267246468721"&gt;&lt;/span&gt;&lt;span id="goog_1267246468719"&gt;&lt;/span&gt;&lt;span id="goog_1267246468717"&gt;&lt;/span&gt;&lt;span id="goog_1267246468715"&gt;&lt;/span&gt;&lt;span id="goog_1267246468713"&gt;&lt;/span&gt;of Duties – at role and user levels&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;There are various standard reports and tools available in SAP to support these review.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Mantran Consulting Pte Ltd (MANTRAN) provides end-to-end services in the areas of SAP authorizations, Segregation of Duties and BASIS controls. The services covers design, implementation, maintenance and review of controls in these areas. Please contact MANTRAN at &lt;/span&gt;&lt;a href="mailto:SAP@mantranconsulting.com"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP@mantranconsulting.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; for more information.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-4536081259364565145?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/4536081259364565145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/restrict-sap-user-administration-from.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4536081259364565145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/4536081259364565145'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/restrict-sap-user-administration-from.html' title='Restrict SAP user administration from managing his own access and Segregation of Duties in user administration'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-5365782557529336436</id><published>2010-02-23T16:55:00.000+08:00</published><updated>2010-02-23T16:55:53.728+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Survey'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP security survey'/><title type='text'>SAP security practices survey</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Security controls in SAP is one of the more complex areas and requires special focus to implement, manage and review. Organizations have varying perception of risks and therefore, they have a range of practices to manage SAP security. This survey aims to understand the most common SAP security practices and will attempt to identify the most successful practices in this area. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;What is the optimal size of SAP security team? How often should the SAP security controls be reviewed? Do organizations enable table logging in SAP? What kinds of changes are performed directly in production environment? How many organizations use PO/ PR approval in SAP? Do organizations use ‘dual control’ for changes to vendor and customer master? How many organizations have documented SoD matrix? &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;These are some of the questions that many SAP security practitioners ask and often fail to get an answer. MANTRAN’s SAP Security Practices Survey 2010, which is first such survey, aims to find answers to such questions related to SAP security controls. The result will be an important aid to anyone trying to design, manage, review or fix security controls in their SAP system. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Specifically, the SAP Security Practices Survey 2010 aims to understand the following: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Risks and threats faced by organizations using SAP &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;2. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;Industry perception of required SAP security controls &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;3. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;SAP security practices &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;4. H&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;ow auditors perceive and review SAP security controls? &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;How to participate?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You can participate using any of the following channels:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. &lt;strong&gt;Online&lt;/strong&gt;: If you prefer to complete the Questionnaire online, please click HERE to participate. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;2. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;Interview&lt;/strong&gt;: If you prefer to talk to one of our consultants, please contact us at survey2010@mantranconsutling.com or +65 6401 5160/ +65 8118 9972. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;3. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;Email&lt;/strong&gt;: If you prefer to receive the questionnaire through email, please send us an email at survey2010@mantranconsutling.com. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;4. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;Post&lt;/strong&gt;: If you prefer to complete a printed questionnaire, please contact us at survey2010@mantranconsutling.com or +65 6401 5160/ +65 8118 9972 and we will send you a printed questionnaire. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;Notes: &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;em&gt;1. All the information provided will be on ‘no name’ basis and will not be disclosed without your prior permission. &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;em&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;2. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;The survey is open till 30 April 2010. &lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;Why participate? &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Whether you are SAP professional, SAP security practitioner, SAP auditor or other stakeholder in your organization’s SAP system, you are interested in having a secure SAP system. The survey results will enable you to make more informed decisions about the security practices that you deploy for your SAP system. You can also benchmark your SAP security practices against other organizations. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Apart from receiving a copy of survey report, as a participant, you will also receive the following: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;1. Complimentary invitation to special ‘breakfast talk’, where the results of the survey will be presented and analyzed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;2. Customized survey report – with special focus on areas relevant for your organization &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;3. Specially printed SAP Security Flashcards (free shipment only in Singapore and India). &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;--------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;MANTRAN Consulting Pte Ltd is conducting this survey. Please visit &lt;a href="http://www.mantranconsulting.com/"&gt;http://www.mantranconsulting.com/&lt;/a&gt; for details.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-5365782557529336436?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/5365782557529336436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/sap-security-practices-survey.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5365782557529336436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/5365782557529336436'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/sap-security-practices-survey.html' title='SAP security practices survey'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-2375974176549924691</id><published>2010-02-09T18:08:00.000+08:00</published><updated>2010-02-09T18:08:17.339+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='CA/ CM'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Auditing'/><category scheme='http://www.blogger.com/atom/ns#' term='Continuous Monitoring'/><title type='text'>Continuous Auditing under SAP environment</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;&lt;em&gt;Old wine in a new bottle!&lt;/em&gt;&lt;/strong&gt; That's the typical reaction from most people when they hear of CA. They are not entirely wrong - the concept is nothing new. We have been talking of using CA to improve efficiency, coverage and reach of audits for many years now. What has really changed are the tools available to realize the concept in real life.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Internal auditors in many companies have been practicing CA in some form or other for many years now. Some use CAATS like ACL to increase their sample size (or to test the entire population). However, in many cases, it is not easy to even obtain the data required to perform such testing.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;SAP, on the other hand, provides vast amount of data for any kind of testing and analysis. And there are many commercial tools, which claim to provide CA (or Continuous Monitoring (CM)) functionalities in SAP system. Most of these tools started as authorizations/ Segregation of Duties (SoD) tools and kept on adding functionalities to evolve as CA/ CM tools. However, these functionalities are like food in a flight. While the food on flights are not bad, the flights still are meant to take people from one place to another and do not compete with restaurants for food. Similrily, most of these tools are very good in authorizations and SoD - but when it comes to CA/CM, they are not as good.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Unlike authorizations and SoD, which require lots of technical understanding, CA/CM requires understanding of business risks. Most of the existing CA/CM tools overwhelm users with amount of information contaied in them. But, is this information really useful to the users? These tools are also too complex to use and may require specialised trainings just to use them. It's like learning to cook when you just want to go to a restaurant and have your dinner! And it takes long time to implement these tools - sometime makes you wonder whether its worth the effort with speed of changing system landscape at most of the companies.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;What do most auditors want from their CA/CM tool? They require a simple tools, which focuses on business risks, is easily and quickly customizable to their need, intuitive to use, easy to manage, not very complex and most importantly, economical.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;-------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;MANTRAN Consulting Pte Ltd offers a simple and easy to use CA/CM tool for SAP users. This is an intuitive tool, which does not require a separate hardware and can be installed on any normal PC or laptop. This MS Access based tool captures process-wise risks and corresponding controls/ analysis to be monitored on a regular basis. This is highly customizable tool - requires less than a week to configure, install and be ready to use. No separate training is required to use the tool. It works in an offline mode - which makes it easier to use without getting on the wrong side of your SAP/ BASIS team.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Please contact us at &lt;a href="mailto:CACM@mantranconsulting.com"&gt;CACM@mantranconsulting.com&lt;/a&gt; for more details or any enquiries on this tool.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-2375974176549924691?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/2375974176549924691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/continuous-auditing-under-sap.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2375974176549924691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/2375974176549924691'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/continuous-auditing-under-sap.html' title='Continuous Auditing under SAP environment'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8842082917241702221.post-8063187063470060762</id><published>2010-02-02T16:54:00.001+08:00</published><updated>2010-02-02T16:59:23.657+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAP Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Singapore'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Training'/><category scheme='http://www.blogger.com/atom/ns#' term='SAP Security'/><title type='text'>Internal Auditors – what prevents them from integrating SAP security and controls in their audits?</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;One of my favorite dialogs from ‘Spiderman’ is “&lt;strong&gt;&lt;em&gt;With great power come greater responsibilities&lt;/em&gt;&lt;/strong&gt;”. An apt statement when we think of auditors who suddenly find themselves moving from traditional audit to auditing under SAP environment. SAP system brings great power to business – through its wonderful support for most of the common business processes, SAP makes life simpler and work more efficient. However, this also burdens the internal auditors (and to large extent financial auditors also!) with greater responsibilities – auditing something which happens inside a big black box (i.e., SAP server) is much harder than auditing stuff you can see in black and white. The auditors need to understand what happens inside that big box to shoulder this responsibility.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In my experience, auditors (just like any other business users!) are comfortable with their traditional and time tested ways of auditing. When a company using a basic accounting system (and may be a few other legacy discrete systems) decides to implement SAP, it brings about a generational shift in the way business is done. And auditors need to adapt to these changes. Reconciliations done by finance department, which may have been key controls in legacy environment, can no longer be a key control. Not because business has changed – it just that certain work is done automatically by SAP. Some of these automatic controls are inherent in SAP while others can be turned on and off (just like the switches). Auditors need to understand and utilize these automated controls. Not only does automated controls provide better assurance, it also let’s auditors increase their audit scope – instead of sample check of 25, they may be able to check a larger sample or in some cases, entire population. Only thing standing between the auditors and such a scenario is lack of understanding of security and controls in SAP system.&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I find big reluctance on the part of internal auditors to adapt and utilize these controls functionalities in SAP. One of the prime reasons for this reluctance is a perception that SAP controls are technical in nature and require IT specialists to deal with. This, in my view, is a misconception. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;SAP security and controls can be separated into two categories – technical and functional, with some overlap. While, internal auditors may be correct in not getting involved in entirely technical areas of BASIS controls, other controls related to authorizations, business process configurations, exception reports, functional procedures, etc can and should be dealt with by the internal auditors. While these areas also require some technical understanding, business process understanding is of much more importance to understand these areas. For example, if an auditor wants to audit procurement process, he can rely on many automated controls in SAP (such as three-way match, PO approval hierarchy, changes to vendor master records, etc). While there is a need to understand some technical aspects to review these configurable controls, these are easy-to-follow with some basic understanding and training. The key still remains the knowledge of process and associated risks. &lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;How do we bridge this knowledge gap in the internal auditors? There are many SAP security and controls trainings available – but most of them focus on the technical aspects. What internal auditors need is a focused training, which understands this gap and equip them to get comfortable with controls in SAP system.&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Such training should provide an understanding of what goes inside SAP at a level, which is not too technical for the auditors and yet tell them just enough to do their work. It should provide them with the tools and techniques, which are important for working with these automated controls. The key is to get the right balance between technical aspects and functional aspects – so that auditors are not scared to understand the SAP security and controls.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;-------------------------------------------&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;strong&gt;MANTRAN Consulting Pte Ltd &lt;/strong&gt;provides many focused SAP security and controls trainings for internal audit teams. These trainings go beyond and also assists auditors integrate these automated controls in their normal audit work – to enhance the efficiency, assurance and coverage of the audits. The trainings are provided by an experienced SAP security and controls professional, who has conducted more than 20 SAP post-implementation reviews, 30 audits under SAP environment and have been involved in design of authorizations and Segregation of Duties for many clients.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;http://www.mantranconsulting.com/eacademy/index&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8842082917241702221-8063187063470060762?l=mantranconsulting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mantranconsulting.blogspot.com/feeds/8063187063470060762/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/internal-auditors-what-prevents-them.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8063187063470060762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8842082917241702221/posts/default/8063187063470060762'/><link rel='alternate' type='text/html' href='http://mantranconsulting.blogspot.com/2010/02/internal-auditors-what-prevents-them.html' title='Internal Auditors – what prevents them from integrating SAP security and controls in their audits?'/><author><name>Barun</name><uri>http://www.blogger.com/profile/10027018723215744876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_8Kwl4QcnngQ/S2fjvtlAZ0I/AAAAAAAAD8M/RmIh1KYPZBw/S220/Varun+Passport+Pic+Oct07.JPG'/></author><thr:total>2</thr:total></entry></feed>
