Hi ,
Currently i am working in an MNC company as an SAP
Security tier1 member , we will take care of User
Administration , Profile/authorization administration
activities .Could any one tell me , is i am eligible to
apply for an SAP Security job for 2 years experience .
Could any one tell me about SOD , SOX Audit and Virsa tool ,
i have never worked before .
Prakash
Answers were Sorted based on User's Feedback
Answer / reddy
What is GRC ?
Governance, Risk, and Compliance.
The goal of GRC is to help a company efficiently put
policies and controls in place to address all its
compliance obligations while at the same time gathering
information that helps proactively run the business.
This means Ethical Business Process should comply with
Effective Process controls as per the related industry
Business Process and accounting Process and Govt Policy .
This GRC process finally Can Conculded with respect to Govt
Orgasnisations and Public Orgaanisation which are
Registered in Local Stock Markets are accountable to have
Effective Governance and Process Controls to Protect the
Share holder rights and Prevent Organised Corporate Fruads
and scams.
GRC Tools and IT applications
There are many GRC AUDIT tools in the Market to Facilitate
Internal and External Audit of the Companies .
What is SAP VIRSA Tool.
focused on 1) Access controls , 2) Process Controls.
It Has 4 Sections to Audit the system.
1. Compliance Caliberator
2. Role Expert
3. Firefighter
4. Access enforcer .
VIRSA systems is now takenover by SAP AG.
It has been aprt of Netwever and add on now .
| Is This Answer Correct ? | 9 Yes | 0 No |
Answer / shiva
SOD and SOX are used for SAP Audit purposes in the company
and Virsa tool is a 3rd party tool integrated with SAP,used
for finding of the risks before applying the roles (new) to
a user.
| Is This Answer Correct ? | 9 Yes | 1 No |
Answer / geethu
Hi Prakash,
If you are very strong in Security you can apply for
Security job for 2years..If you are not please dont
experiment in new company it wil a big problem for you.
And for SOD and SOX is very Important topic. SOD
Sagregation of Duty Analysis is fully automated tool which
is used for auditing.
SOD and SOX is very huge topic. You cannot understand until
you read relevant books and start practice
| Is This Answer Correct ? | 7 Yes | 7 No |
How to approach as a security consultant when a custom t code is created?
As a SAP security consultant what is the most challenged you faced in previous company?
what is the user table including account number and cost center in one table?
1.why we use derived role in sap security?2.what is the technical difference between master and derived role?
Give one example of master data that is shared between AC, PC and RM? (grc 10)
how can u assign firefighter ids from one firefighter admin to another firefighter admin if current admin leaves from organization without told to any body?
How can we Lock transaction ? What happens exactly ?
1) Explain me about your SAP Career? 2) Tell me your daily monitoring jobs and most of them you worked on? 3) which version of SAP are you working on? Is it a java stack or abap stack? 4) Tell me about derived role? 5) what is the main difference between single role and a derived role 6) Does s_tabu_dis org level values in a master role gets reflected in the child role?? 7) Tell me the steps to configure CUA? 8) Is RAR a java stack or Abap Stack? 9) What is the report which states the critical T-codes? and also What is the T-code? 10) What is the T-code to get into RAR from R/3? 11) Explain about SPM?
How to get the list of tcodes having by all users(EX-20 users)at a time?(through SUIM or TABLE) [we can get single user through SUIM->TRANSACTIONS- >EXECUTABLE USER....but same thing i want for multiple users at a time)
User is not there in User master record. Then how to trace the user?
Is it possible to have a request type by which we can change the validity period of a user? If possible, then what are the actions?
what is centralize FFID?
SAP Basis (1262)
SAP ABAP (3939)
SAPScript (236)
SAP SD (Sales & Distribution) (2717)
SAP MM (Material Management) (912)
SAP QM (Quality Management) (99)
SAP PP (Production Planning) (523)
SAP PM (Plant Maintenance) (252)
SAP PS (Project Systems) (138)
SAP FI-CO (Financial Accounting & Controlling) (2766)
SAP HR (Human Resource Management) (1180)
SAP CRM (Customer Relationship Management) (432)
SAP SRM (Supplier Relationship Management) (132)
SAP APO (Advanced Planner Optimizer) (92)
SAP BW (Business Warehouse) (896)
SAP Business Workflow (72)
SAP Security (597)
SAP Interfaces (74)
SAP Netweaver (282)
SAP ALE IDocs (163)
SAP Business One (110)
SAP BO BOBJ (Business Objects) (388)
SAP CPS (Central Process Scheduling) (14)
SAP GTS (Global Trade Services) (21)
SAP Hybris (132)
SAP HANA (700)
SAP PI (Process Integration) (113)
SAP PO (Process Orchestration) (25)
SAP BI (Business Intelligence) (174)
SAP BPC (Business Planning and Consolidation) (38)
SAP BODS (Business Objects Data Services) (49)
SAP BODI (Business Objects Data Integrator) (26)
SAP Ariba (9)
SAP Fiori (45)
SAP EWM (Extended Warehouse Management) (58)
Sap R/3 (150)
SAP FSCM Financial Supply Chain Management (101)
SAP WM (Warehouse Management) (31)
SAP GRC (Governance Risk and Compliance) (64)
SAP MDM (Master Data Management) (0)
SAP MRS (Multi Resource Scheduling) (0)
SAP ESS MSS (Employee Manager Self Service) (13)
SAP CS (Customer Service) (0)
SAP TRM (Treasury and Risk Management) (0)
SAP Web Dynpro ABAP (198)
SAP IBP (Integrated Business Planning) (0)
SAP OO-ABAP (Object Oriented ABAP) (70)
SAP S/4 HANA Finance (Simple Finance) (143)
SAP FS-CD (Collections and Disbursements) (0)
SAP PLM (Product Lifecycle Management) (0)
SAP SuccessFactors (33)
SAP Vistex (0)
SAP ISR (IS Retail) (28)
SAP IdM (Identity Management) (0)
SAP IM (Investment Management) (0)
SAP UI5 (59)
SAP SCM (Supply Chain Management) (51)
SAP XI (Exchange Infrastructure) (49)
SAP Cloud Platform (34)
SAP Testing (89)
SAP SolMan (Solution Manager) (63)
SAP MaxDB (116)
SAP GUI (15)
SAP AllOther (329)