Answer Posted / krishna pradeep
SOX Defines Sarbanes Oxley Act
Its is the base for creating GRC In sap.
The main intention of this is to prevent the total access to a person or authority in an industry or organisation.
It is used to segregate the duties.
Ex: if a person having the authority for creating a PO(purchase order) and approving the PO and Transfer the Funds,he can do illegal activities by giving it to his own people.
| Is This Answer Correct ? | 3 Yes | 0 No |
Post New Answer View All Answers
Differentiate between derived role and composite role
what is centralize FFID?
what is the process to find that one consultant had removed a table from sap tables
What are st01 t-codes used for?
Explain document transfer-level security?
when performing client copies what steps you need to take from CUA point of view?
In Agr_1251 we are able to see 100 roles but in SUIM we are able to see 120 roles what's the reason behind this ? why is the difference between the SUIM and the AGR table ?
how we Set up Central User Administration (CUA) to manage 4 systems/clients
What every changes done exist role in development system that changes are not reflected in quality system, but transport is successfully moved?
what is sod in sap security?
How to update risk id in rule set?
1) Explain different type of Users? Explain specifically Service User? 2) Difference between System and Communication User?Explain in Context of Profile Parameter? 3) There are 5 systems say BI, SOLMAN, CRM, PI, SRM etc etc. Which system will act as a satellite system in CUA and Why? HOw CUa system works? 4) State different types of Transactions & Tables in Strutural Authorization Profile in HR Security? 5) What is L0 , L1 , L2 , L3 , L4 code called in HR Security? 6) What fields are required to create Strutural Authorization Profile in HR Security? State significance of Evaluation Path? 7) What is Structural Authorization Profile in HR Security? When required Role has already been assigned to User then why Structural Authorization Profile is required by user? 8) How are structural Authorization Profile are created? 9) Important Authorization Object in HR Security? 10) Fields in P_ORGIN A.O? 11) Important infotypes and What is PA? 12) How access is provided for tables to user? Significance of Authorization Group in TDDAT table? 13) Difference between SU22 and SU24? 14) Explain Authorization Structure? 15) Which table stores the Authorization Object of a User? 16) What we do to keep Roles consistent in DEV QAS and PRD? 17) A User has create and display access? Will he have access to change as well? 18) How User can have access to view salary slip of other employees(HR Security)?Explain in detail. 19) In HR security does we add Employee ID anywhere in Roles? 20) Any issue you have faced while Transport? 21) Have you faced any issue in Upgrade? Expalain how to compare Roles from older version of SAP to new version of SAP? 22) Any typical issue you have resolved in HR Security?
How do you check background jobs?
What are su25 t-codes used for?
How would you do the 'a user logge into production system, changes a table and logged out'. How would you track him?