Access Control For Midmarket Companies Protect Information and Prevent Fraud (A4)

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

SAP Solution Brief

SAP BusinessObjects Solutions for


Small Businesses and Midsize
Companies
SAP BusinessObjects Access Control,
Version for Midsize Companies

Protect Information and The SAP® BusinessObjects™


Access Control application,
­Prevent Fraud with SAP® version for midsize compa-
­BusinessObjects™ Access Control, nies, enables efficient pro-
version for midsize companies tection of information and
prevention of fraud by con-
trolling access and authori-
zations. It minimizes time
Companies are struggling to protect authorization risk across your company.
themselves from fraud and to fulfill com- This, in turn, results in proper segrega-
and cost of enforcing segre-
pliance required by internal policies and tion of duties (SoD), reduced access gation of duties across
regulatory mandates. The results are risk, and better business performance.
­often inefficient processes and rising
applications and prevents im-
costs, especially when trying to continu- By deploying the application to unify proper access to IT systems.
ously achieve compliance using a frag- your company-wide access compliance
mented approach that includes manual management approach, you also benefit
activities, point solutions, or disparate from lower costs and fewer resources
technologies. Fragmentation makes it needed to be compliant.
impossible to deal effectively with the
thousands of access rights−related Managing Compliance
rules and interdependencies that occur
in your business processes and IT sys- SAP recognizes that midsize companies
tems. A unified approach to managing must manage compliance with limited
access compliance helps increase resources and time while being ready to
transparency and reduce cost and com- scale for growth. SAP BusinessObjects
plexity from managing your controls with Access Control is a scalable application
a fragmented approach. that supports a rapid “get clean” phase
to address violations quickly. Using au-
SAP can help you protect information tomated control rules that can be set up
and prevent fraud with software that au- by IT or business managers, the respon-
tomates the process of analyzing and sibility of preventing controls violations
comparing access rules, detects poten- can be established in places where it
tial risks, and gives your IT and manage- works best for the company. The key
ment teams the information they need functions addressed by this application
to make decisions that ensure compli- are access risk analysis and remedia-
ance. The SAP® BusinessObjects™ Ac- tion and privileged user access manage-
cess Control application creates a uni- ment, all with access review and audit
fied, efficient, automated control (see Figure 1).
environment to help you manage segre-
gation of duties in SAP and non-SAP Access Risk Analysis and Remediation
environments, reducing access control SAP BusinessObjects Access Control
management costs across implementa- supports real-time compliance around
tion and operations. the clock and prevents security and
controls violations. Upon implementa-
Compliance Automation Across tion, you can:
Your Company • Analyze live data – Use live data to
assess access risk rather than rely on
SAP BusinessObjects Access Control, data downloads from disparate appli-
version for midsize companies, sup- cations. This way, you can identify
ports you in achieving end-to-end auto- conflicts immediately, drill down into
mation for detecting, mitigating, reme- root causes, and achieve resolutions
dying, and preventing access and swiftly.
• Find hidden issues in real time – vendor solutions and comes with • Provide complete audit trail and
Uncover potential regulatory viola- a rules library to address core ­activity tracking – The application
tions that might otherwise go unde- processes. tracks, monitors, and logs every
tected until an audit. Address hidden ­activity a user performs with a privi-
user access issues in real time be- SAP BusinessObjects Access Control leged superuser ID and provides com­
fore they impact the business, and addresses SoD issues and detects, prehensive Web-based reporting.
help ensure effectiveness of access removes, and prevents access and
and authorization controls at any authorization risks across two dimen- Take Control of Access and
time, across any system. sions: breadth of business processes Authorization Risk
• Ensure segregation of duties – covered and depth of integration with
Increase efficiency by leveraging company-wide, legacy, and custom SAP BusinessObjects Access Control
the most comprehensive database software applications. is one of the most comprehensive ap-
of SoD rules available for applica- plications in the industry for managing
tions from SAP, Oracle Corporation, Privileged User Access Management and preventing user access and autho-
PeopleSoft, and JD Edwards. On How can you give users privileged rization risk. It dramatically reduces the
top of this, SAP BusinessObjects emergency access to company-wide time, cost, and risk of managing SoD
Access Control allows non-IT securi- systems without committing regulatory compliance and is now packaged and
ty experts to build custom rules using violations? You can: priced for midsize companies. The appli-
common language for risk and com- • Provide fast, secure superuser cation offers a high level of automation
pliance (see Figure 2). logons – In emergencies, SAP and a best-in-class SoD rules database
• Manage risk across the company – BusinessObjects Access Control to continuously enforce compliant ac-
Stop deploying different compliance lets users perform activities outside cess to assets, even within non-SAP
software for each business function their role under superuser privileges applications.
or software application. Instead, take in a controlled, auditable environment
full advantage of an application that using a temporary ID. SAP: Delivering IT-Powered
immediately works across software Business Innovation

As the world’s leading provider of busi-


Effective ness software, SAP delivers products
Minimal Time to Access Management Access Oversight
Compliance and services that help accelerate busi-
and Audit
ness innovation for our customers. We
Risk Analysis and Superuser Privilege Periodic Access believe that doing so will unleash growth
­Remediation Management Review and Audit and create significant new value – for
Ensure rapid, Close the number 1 audit issue Focus on ­remaining our customers, SAP, and, ultimately,
cost-effective, with emergency access ­challenges ­during
comprehensive recurring audits
entire industries and the economy at
cleanup and large. Today customers in more than
monitoring 120 countries run SAP applications –
from distinct solutions addressing the
Risk analysis, remediation, and prevention services
needs of small businesses and midsize
Cross-software library of best-practice segregation of duties rules companies to suite offerings for global
organizations.
Figure 1: Establishing Compliance Across the Company via SAP® BusinessObjects Access Control
From Walldorf to Wall Street: across all aspects of their business,
The SAP Success Story which allows them to act quickly with
Founded in 1972, SAP has a rich history increased insight, efficiency, and flexi-
of innovation and growth that has made bility. By using SAP solutions, com­
us a true industry leader. SAP has panies of all sizes – including small
sales and development locations in businesses and midsize companies –
more than 50 countries worldwide and can reduce costs, optimize perfor-
is listed on several exchanges, includ- mance, and gain the insight and agility
ing the Frankfurt Stock Exchange and needed to close the gap between strat-
NYSE under the symbol “SAP.” egy and execution. To help our custom-
ers get the most out of their IT invest-
Helping Companies Become Best-Run ments so that they can maximize their
Businesses business performance, our profession-
Our vision is for companies of all sizes als deliver the highest level of service
to become best-run businesses. In and support.
today’s challenging business environ-
ment, best-run companies have clarity

Find Out More


SAP® BusinessObjectsTM Access Control Application Works Across Software Solutions
For more information, contact your
SAP Oracle Corporation PeopleSoft JD Edwards SAP representative or visit us online at
• HR and payroll • HR and payroll • HR • HR and payroll
www.sap.com/sapbusinessobjects/grc.
• Procure to pay • Procure to pay • Procure to pay • Procure to pay
• Order to cash • Order to cash • Order to cash • Order to cash
• Finance • Finance • Finance • Finance
– General – General – General – General
­accounting ­accounting ­accounting ­accounting
– Project systems – Project s­ ystems – Fixed assets • Consolidations
– Fixed assets – Fixed assets • System
• Basis, security, • System ­administration
and ­system ­administration
­administration • Materials
• Materials ­management
­management • Supplier relation-
• Advanced ­planning ship management
and ­optimization
• Supplier relation-
ship ­management
• Customer relation-
ship management
• Consolidations

Figure 2: A Solution That Works Across Software Vendor Solutions


Quick facts www.sap.com /contactsap

Summary
The SAP® BusinessObjects™ Access Control application, version for midsize companies,
supports you in achieving end-to-end automation for detecting, remedying, mitigating,
and preventing access and authorization risk across your company. This results in proper
segregation of duties (SoD), lower costs, reduced risk, and better business performance.

Business Challenges
• Identify and proactively mitigate and manage SoD violations
• Eliminate costly, time-consuming, and risky fragmented and complex processes for
establishing and managing access and authorization definition
• Increase visibility using documentation and monitoring capabilities to effectively manage
user access changes and updates, including emergency user access management

Key Features
• Control access and authorization across the company – Achieve rapid SoD violation
cleanup using comprehensive, best-practice, cross-application SoD rules for SAP and
non-SAP systems
• Efficient compliance management – Reduce your cost of compliance and audits using
centralized SoD controls, automated audit trails and documentation, automated rule-
building and analysis, and “what if” simulation capabilities
• Effective oversight and predictability – Manage access effectively by using company-
wide oversight into SoD violations and critical transaction access, transaction monitoring
with alerts, and enhanced control and audit tracking for superuser activity

Business Benefits
• Proactively protect information and prevent fraud by enforcing SoD rules across
applications and departments and preventing improper access
• Optimize operations and minimize cost of compliance by using an SoD rules database
to clean up violations, streamlining SoD management and enforcement using automated
review and approval processes
• Obtain visibility and documentation to manage SoD access activity and changes by
using complete audit trails and control tests that provide proof and reliability.
50 096 199 (09/07)
For More Information ©2009 by SAP AG.
All rights reserved. SAP, R/3, SAP NetWeaver, Duet, PartnerEdge,
Call your SAP representative, or visit us online at www.sap.com/sapbusinessobjects/grc. ByDesign, SAP Business ByDesign, and other SAP products and
services mentioned herein as well as their respective logos are
trademarks or registered trademarks of SAP AG in Germany and
other countries.

Business Objects and the Business Objects logo, BusinessObjects,


Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and
other Business Objects products and services mentioned herein as
well as their respective logos are trademarks or registered trademarks
of Business Objects S.A. in the United States and in other countries.
Business Objects is an SAP company.

All other product and service names mentioned are the trademarks
of their respective companies. Data contained in this document
serves informational purposes only. National product specifications
may vary.

These materials are subject to change without notice. These materials


are provided by SAP AG and its affiliated companies (“SAP Group”)
for informational purposes only, without representation or warranty of
any kind, and SAP Group shall not be liable for errors or omissions with
­respect to the materials. The only warranties for SAP Group products
and services are those that are set forth in the express warranty
­statements accompanying such products and services, if any. Nothing
herein should be construed as constituting an additional warranty.

You might also like