Enabling working copies
SAP authorizations are only checked on the basis of active SAP functions. When you enable the working copy, the changes are transferred to the function definition. An active function definition is added to a new working copy.
To transfer changes from a working copy to a function definition
- Select the Identity Audit | SAP Functions | Function definition working copies category.
- Select the function definition in the result list.
- Select the Enable working copy task.
- Confirm the security prompt with OK.
Mitigating controls
Mitigating controls can be stored with SAP functions. These reduce the effects on the company when SAP users match with SAP functions. At the same time, you specify how to deal with SAP users or SAP groups that match the SAP function. For example, changing a user assignment to an SAP role in the SAP system can be used as a mitigating control for an SAP function.
Mitigating controls can also be used as controlling measures for compliance rules. Mitigating controls assigned to the SAP functions for testing are automatically transferred into compliance rules about SAP functions.
Prerequisites:
- Active rules are assigned to a functional area and a department.
- The SAP functions for testing are assigned to the same functional area and then associated variable set of the same department.
To edit mitigating controls
- In the Designer, set the "QER | CalculateRiskIndex" configuration parameter.
Detailed information about this topic
Assigning mitigating controls
To assign mitigating controls to a function definition
- Select the Identity Audit | SAP Functions | Function definition working copies category.
- Select the working copy in the result list.
- Select the Assign mitigating controls task.
- In the Add assignments pane, assign mitigating controls.
– OR –
In the Remove assignments pane, Remove mitigating control assignments.
- Save the changes.
Creating mitigating controls
To create a mitigating control for SAP functions
- Select the Identity Audit | SAP functions | Function definition working copies category.
- Select a working copy in the result list.
- Select the Assign mitigating controls task.
- Select the Create mitigating controls task.
- Enter the master data for the mitigating control.
- Save the changes.
- Select the Assign function definitions task.
- In the Add assignments pane, double-click the function definitions you want to assign.
- Save the changes.
Detailed information about this topic