Expertise
Make the controls make sense.
Security decisions must work in the system, make sense to the business, and stand up to audit. My work sits where SAP authorisations, risk and control evidence meet.
01 / Access
SAP access controls
Reviewing roles and authorisations to understand who has access, why, and where exposure remains.
- Role concepts and role design
- Authorisation objects, profiles and the profile generator
- User access provisioning and emergency access processes
02 / Risk
Segregation of duties
Assessing conflicting activities and the practical controls needed to manage them.
- SoD rule sets: defining functions, actions and conflicts
- Access risk analysis at user and role level
- Mitigating controls where a conflict has to remain
03 / Assurance
IT & application controls
Examining change management, application security and control effectiveness through an audit lens.
- Change and transport management controls
- Application security configuration
- Control design and the evidence behind it
04 / Tooling
SAP GRC & technical depth
- SAP GRC Access Control: Access Risk Analysis, Access Request Management, Emergency Access Management, Business Role Management
- ABAP for security analysis and tooling
- LDAP and Active Directory integration