English   Deutsch

Product Report: SAP Business Objects GRC Access Control

The SAP BusinessObjects GRC Access Control (in short AC) solution is a powerful set of tools that help to automate risk analysis and mitigation for user and authorization management in SAP and non-SAP systems. It is a strong product for the SAP ABAP world, and is able to cover non-SAP systems using real-time adapters from Greenlight. It covers a substantial subset of the overall GRC requirements – it provides a leading-edge solution for SAP environments, which are at the centre of many IT environments and is able to perform as a realtime cross-platform solution.

The core of the product suite - Risk Analysis and Remediation (RAR) - is the most valuable part and helps effectively to reduce risks in ABAP-based SAP systems - and correspondingly in the implemented business processes - mostly by the set of predefined risks delivered with the product. RAR also supports non-SAP systems in real time due to the risk definition at business process level and the mapping to technology-specific controls through a number of OEMed adapters from Greenlight. Mitigating controls need to be added per project, which is in general appropriate, but a few predefined elements would be of great help to customers. The existing guidelines and offerings from SAP such as the Customer Advisory Office can help implementing the mitigation, as there is no best practice available because of the massive customization of the role assignment processes in customer organizations.
 
An important aspect of AC is the possibility to automate access rights assignment with Compliant User Provisioning (CUP), since this enables real-time risk analysis of planned authorization assignments. A critical factor for success is an appropriate and intelligent definition of the workflows. There are templates and standard workflows - pre-filled with  e.g. HR master data - to start from.

Role creation is the objective of the Enterprise Role Management component. It benefits from the integration with RAR and CUP, from an enterprise-wide methodology making especially naming consistent and from a capability of role mass maintenance. Detailed role creation is not the focus of ERM, experts prefer the standard transactions - which are actually supported from within ERM - or specialized non-SAP tools.

Integration with Identity Management systems is state-of-the-art, all major LDAP based directory service products are supported, as well as HR systems, including a user mapping functionality.

Finally, Superuser Privilege Management (SPM) allows to create specific IDs for short-term remediation firefighter activities requiring elevated privileges. The application is well conceived and simple to use, the emergency access through the SPM interface ensures fine-grained audit, which makes it a quick win. Yet, the privileged user concept should be developed and planned in advance. The integration with the other AC tools is limited, it does support non-SAP privileged account management through the Greenlight adapters.

Herunterladen
Datum Titel Preis
15.04.10 Product Report: SAP Business Objects GRC Access Control

von Sachar Paulus
sp@kuppingercole.com

€95.00 BESTELLEN 
Information
Newsletter
Das Wichtigste im Überblick - der Kuppinger Cole Identity Management Newsletter.
Services
KCP berät Sie in allen Fragen des Identity & Access Management von der Konzeptionsphase bis zum fertigen Rollout.
Reports
Nutzen Sie KCP als unabhängige, objektive und neutrale Instanz im Markt für Identity Management Produkte und Lösungen.
Podcasts
Kostenlose Audio- und Video-Präsentationen zu aktuellen IAM Themen
Aktuelle Umfragen
IAM-Studie 2010
MITMACHEN 
Virtualization Security Trends & Insights
MITMACHEN 
Blogs
Tim Cole
28.08.2010 11:53
Not Just Any Port in a Storm
LESEN 
European Identity Conference Blog
27.08.2010 04:45
Google authentication support
LESEN 
Martin Kuppinger
12.08.2010 11:34
Diving down to the details of access controls
LESEN 
Sachar Paulus
11.08.2010 10:05
The GRC Marketplace is shaking up: SAP and CA partnering on GRC
LESEN 
Sebastian Rohr
04.08.2010 20:18
Your token to VISA…
LESEN 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
LESEN 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
LESEN 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Impressum AGB Vertraulichkeit
© 2003-2010 Kuppinger Cole