Sunday, 16 November 2025
Wednesday, 8 October 2025
#4 GRC phases - Managing Risk by SOD
3 Phases:
| Phase one (Recognize) | Phase two (Analysis) | Phase 3 |
| 1. Risk Recognition | 3.Analysis | 6.Continuous complience |
| 2.Rule Building & Validation. | 4.Remediation | |
| 5.Mitigation |
identify risks in each role.
we will Remediation or Mitigation discussion.
2.Rule building & Validation:
1. Validates the risks in the role.
2.Ensure Phase1( Risk Recognition & Rule buildings validation) is correct as per the business needs or not.
eg: Swipe in & Swipe out in office to avoid risk of unauthorized people entering in to office.
5.Mitigation:
Compensation control.
- Monitoring the present configuration.
- Adopt for the changes as per the business.
- Alert Mechanism.
- Monitoring the mitigation control.
#5 GRC -ROLES
if there is mitigation, Then we need to monitor continuously.
why user need exception access & business requirements.
From the below screen, Multiple action / permissions combined toghether Function.
Multiple functions combined toghether Risk.
Analysis to identify risk:( best way)
object --> Fields --> Values --> Single role --> Composite role --> User.
1.preventive control and
2.detective control.
* Need to monitor logs in detective conntrol mitigation. * Sometime mitigation of risk. may be taking insurence.
or
Configuring automatic alert mechanism.
Sunday, 21 September 2025
Active and configure audit in SAP HANA
Auditing: To Track the record of changes in roles of SAP HANA database.
why do we need to setup auditing:
1. Accountability - User are responsibile for the actions they do.
2.Discourage unauthorized access.
3.Monitoring any suspicious activities.
4.To find the source of breach.
To configure Audits in SAP HANA:
* Need AUDIT ADMIN - system privilege is required.
1. Select the target system, where we need to configure Aduit policy --> 1.expand -->2.Security --> 3.Security as highlighted below.
Wednesday, 27 August 2025
#3. Authorization in GRC SYSTEM.
Authorization in GRC SYSTEM.
* SAP_GRAC_BASE is the base authorization role.
* SAP_GRAC_NWBC is for base authorization for launching NWBC.
* In GRC system, Access T-code - PFCG
role: SAP_GRAC*
Copy all standard SAP given roles in to customize name space --> then use them for operations.
* To view list of authorization objects of GRC --> SU24(T-code) --> Authorization objects tab --> Authorization objects --> GRAC*
Understanding Authorization Risks:
* Segregation of Duties(SOD) is a concept of separating "incompatible duties".
Example one person doesn't have all three duties.
1. Authorization = approving.
2.Safe keeping = holding the asset (or) Access to the asset.
3.Record keeping = keeping track of the asset /liability.
👇
Then more men power is needed for SOD.
👇
However many stakeholders, did not accept SOD segregation. Which may leads to cost increase.
👇
Conclusion is without increase the cost, need to maintain best risk avoid protocols.
Saturday, 19 July 2025
Life cycle of SAP
| Life cycle of SAP | |
| Phases | Describtion of phase |
| Evalution | In the phase, SAP team will sits with product based company and Analysis their business. |
| Project prepartion | In this phase, Project planning will be done.Goals,scope,timeline,budget & establishing the project team. |
| Business blue print | Business processes mapping to corresponding SAP processes. |
| Realization | in this phase, actual configuration and customization of the system. only Development server will be designed here. |
| Testing | What ever the development they did in above, tests will be done. |
| Final preparation | Production server starts building. |
| Go-live | Few configurations where are specifically to production server can be done in this phase. |
| Sustain/support | To few errors in case of any and to adopt new features. |
| End of maintainence | SAP dont support for this versions. |
| Evalution | In the phase, SAP team will sits with product based company and Analysis their business. |
Monday, 30 June 2025
External SAP HANA PSE File and Certificate Management
Saturday, 31 May 2025
SAP HANA Security -cretificate management inside DB
Friday, 23 May 2025
GRC add ons List #2
GRC intro#1
Sunday, 20 April 2025
Enqueue wp
Thursday, 17 April 2025
Import TR in sap
- In the quality server, Access the T-code: stms_import.
- 1.Select the Request column.
- 2.click on filter button.
- 3. Provide client details.
- 4.select immediate option.














