Solution:
SAP GRC Solutions
GRC: Governance, Risk and Compliance

Our Practice capability includes
Advisory / Review & Recommendations on
- Security process & organizational readiness
- Authorization concepts & processes
- Baseline Security Policies and Procedures
- Identifying potential vulnerabilities & risks
- Planning – Establishing assessment and test strategy
- Documenting Compliance Initiative – Defining compliance structure and identifying all relevant organizations, processes, risks & controls
- Assessments & Tests – Performing assessments, verifying configuration and establishing adequacy of controls
- SAP security, including SAP security parameters, technical configuration and patch management
Implementation
- Implementation SAP GRC12 – Access Control, Process Control & Risk Management Module
- Access Risk Analysis – Review of configuration and effectiveness of Segregation of Duties
- Access Request Management – Review of user provisioning process, configuration and adequacy of controls
- Business Role Management – Review of role management process, configuration and adequacy of controls
- Emergency Access Management – Review of access of users performing emergency activities, its configuration and adequacy of controls
- Recommending controls for mitigating risks
- Implementation of Rode design / Role Design
- Implementation of SAP GRC Access Control
- Upgrading from older to newer version
Support
- L1/L2/L3 Support Services on Security / SAP GRC
- Support for upgrading from older to newer version
- Addressing questions from internal and external security audits and assessments
- Managing security requirements with third parties
- Remediating Issues – Review remediation of issues and establish adequacy of controls
- Managing Internal & external audit processes, audit planning, monitoring effectiveness of controls and corrective actions with the control owners and senior stakeholders
- Managing gap analysis, compliance readiness, and compliance monitoring activities
- Partnering with Compliance teams to ensure compliance with regulatory security requirements