Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 12

ComplianceNow

Part of Nagarro

© Nagarro Confidential
Thinking Compliance Breakthroughs

Supported by thousands of SAP


professionals
• 17.000 Colleagues represented in 26 countries
Simplicity over complexity
• Constant market feedback
• Dedicated SAP-focused GRC suite
• Over 15 years of software development experience
built for small & medium The Business
enterprises
• Wide network with global support
• SAP Certified any-premise &
extended cloud

• Compliance operations tools


serving small, medium & large Solving Challenges
enterprises

• Optimizing & automating


processes

• Accelerate your SAP compliance in Best-in-class customer service


your S4/HANA transformation with
a S4/HANA ready solution • 250 customers in 12 countries

Customer Value • Global reach & global delivery model

• Low total cost of ownership

• 2-3 days installation with a low customer investment

© Nagarro Confidential
Selection of our more than 250 references

Retail Healthcare & Life Airport & Defence Public Sector


Sciences

Automotive Energy Manufacturing Bank & Insurance

© Nagarro Confidential
The ComplianceNow Suite
Proactive Risk Management Compliance Operation

Prevent Resolve Mitigate Analyse Test Support

Privileged Access Authorization


Access Control Internal Control Usage Monitor Password Reset
Management Process Manager

• SoD mitigation in SAP • Self-service firefighting • Centralize internal controls • SAP Access analysis • Remove project risks • 24/7 self-service
• Preventive workflow • Audit trace & logging • Control library – SoD risks • Enable data driven • Reduce testing time by 75% • Lower admin costs
decisions
• Fast implementation / Low • Audit management process • Workflow & logging in a • Improve quality and • Improve user experience
operation costs trusted system • Optimize & reduce costs satisfaction

Empower Your Organization: Risk Detection, Management & Mitigation Optimize & Test SAP User & Role Access

Your Assurance Handholding Through Installation Facilitated Adoption Low Total Cost of Ownership - Why?

SAP certified any-premise & ext. cloud Hosted / On-premise Fair pricing
CN specific extended services
Fixed price installation support Dedicated support center in DE / DK
ISAE 3402 Type II Certified CN devoted managed services
Full CN Suite installation in 2-3 weeks 3 yearly releases with updates & innovation

19.000 colleagues in 33 countries Global network with local partners


SAP compliance maturity ladder

Improvements
Maturity Investment
Stakeholders/drivers for ext. Compliance
technology, management, business, legal
requirements, internal & external audit
Test –
auditor input
Mitigating
Controls
Enterprise
IC
Risk
Segregation Management
of Duties IC / ERM
Privileged
Access AC
User Management
provisioning AC / PAM
Authorization
concept UM / PWR
SAP_ALL
APM ComplianceNow
deliver tools driving the process and speed
UM up the individual stages
Time
Compliance Operation: Risk Management:
APM: Authorization Process Manager PAM: Privileged Access Management
UM: Usage Monitor AC: Access Control
PWR: Password Reset IC: Internal Control

© Nagarro Confidential
Privileged Access Management
Self service Privileged Access handling

© Nagarro Confidential
The Process

Starting an Privileged Access User session:

Introduction & Document Select Privileged Describe the


Privileged Access reference to Log on to SAP with
Step 1 Access user for problem & expected
group overview external ticket Privileged Access
the current activities
User
session

Closing the emergency user session:

Exit Privileged Exit PAM wizard &


Revise documented
Access User
Step 2 problem & actual release the
session & return to Privileged Access
activities
PAM wizard User

Auditing the emergency user session:


Approve user
Review the
Privileged Access Review relevant session
Step 3 User session SAP logs
Ask for more Approve user
documentation
documentation session
Key Challenges

Process Challenges Manual Handling Challenges Organisational Challenges


• In case of an emergency, no users • A manual process is slow and • Loss of productivity due to the lack
have sufficient access rights unsuitable in case of privileged of instant Privileged Access
access
• No standardized processes for
• Wide access or SAP_ALL is allocated
• Unstructured approach results in evaluating who is granted broad
with no process for how to remove
inefficient processes Privileged Access
access
• Complex and time-consuming audit • Lack of communication when
• Critical delays in resolving the handling Privileged Access is ready to be
emergency withdrawn again
• Manual handling does not create
sufficient documentation and • Challenges with time-sensitive
• Privileged access‘ accesses are
transparency matter that need to be resolved ASAP
undocumented and constitute a risk

© Nagarro Confidential
Key Challenges

Automated Process Process Efficiency Includes the Business


• A standardized and structured process • Document and trace all activities and • Self-service for predefined Privileged
that increases the level of compliance in changes that are done with the Access users
emergency situations Privileged Access User
• Protect business data
• Automatic documentation • Monitor the usage of the Privileged
Access Uuser live • Organize & mature organization by involving
& delegating Privileged Access Users
• Ensures transparency & simplifies
documentation requests • Supports internal and external user
access • Fast & efficient case handling will minimalize
business interruption
• Efficient audits – audit trace, logs
document all in one system • Instant notification when Privileged
Access Users are opened • Single point of entry for audit and reporting

© Nagarro Confidential
Live Demo

© Nagarro Confidential
Implementation

• Easy implementation with only few steps to be configured

• Access is controlled by standard SAP roles & authorizations

• Takes less than 1 day per SAP system to be fully up and running

• Integrated directly within SAP

© Nagarro Confidential
The Approval process

The emergency User Access Approval process will be introduced with version
5.2.10 of the ComplianceNow suite and will be available H2

Starting an emergency user session:

Introduction & Document Select Privileged Describe the


Privileged Access reference to Send request for
Step 1 Access User for problem & expected
group overview external ticket approval
the current activities
session

Approving/Rejecting request by admin


Approve request
Logon with
Step 2 Privileged Access
Reject request User

You might also like