What is the difference between ECC security and RAR security
when GRC (RAR<SPM<CUP) is used, when similar functionality can
be performed SAP R3 level(ECC)?
Answers were Sorted based on User's Feedback
Answer / itsgaurav151
The things ECC security and RAR security are different. ECC
is a system whereas RAR is a tool. ECC security involves
securitg data, t-code access, report access and maintaining
the suthorizations. RAR(Risk analysis and Remediation) is a
tool that is used for analysis of risk analysis and its
remeduation as name suggests. Rhis tool determines all
potential risks that arises if a t-code/object/role/auth is
assigned to a user. Also this tool helps to remediate that
risk using mitigation technique.
Is This Answer Correct ? | 6 Yes | 1 No |
Answer / rahman shaik
Simply we can say one thing like In Ecc system you cant find any risk while assigning the roles but in RAR tool it will check the RISK of that particular assignment and if risk is their then we can mitigate and simulate to that risk
I mean its purely for SOD(segregation of duties)
Is This Answer Correct ? | 4 Yes | 0 No |
what is the procedure for deleting a role?
what do you mean by profile and obeject
What is sap internet transaction server?
how to secure the customizing Tcodes in sap
authorization issue. We had asssigned company codes 'BUKRS' in range for example 4000-4220 some come company code is working some are not working means in between ranges . could you please post the answer as early as possible.
What does the account assessment category specify in a purchasing order in SAP Materials Management?
Hi Experts, can any one explain me the step by step process to implement security in BI/BW and what are the authorization objects we use to BI/BW , How can the security is different between R/3 and BI/BW, I appreciate your help
What are suim t-codes used for?
can we restrict access through tcode added manually in authorisation data in creating a role?
hOW many users limit in su10
3 Answers Accenture, Cap Gemini, Hexaware,
What is the maximum number of authorization objects in a role?
How to control user only can schedule immediate background job but cannot schedule period background job?