PATRICK
DIEZ NAVARRO

Expertise

Make the controls make sense.

Security decisions must work in the system, make sense to the business, and stand up to audit. My work sits where SAP authorisations, risk and control evidence meet.

01 / Access

SAP access controls

Reviewing roles and authorisations to understand who has access, why, and where exposure remains.

  • Role concepts and role design
  • Authorisation objects, profiles and the profile generator
  • User access provisioning and emergency access processes

02 / Risk

Segregation of duties

Assessing conflicting activities and the practical controls needed to manage them.

  • SoD rule sets: defining functions, actions and conflicts
  • Access risk analysis at user and role level
  • Mitigating controls where a conflict has to remain

03 / Assurance

IT & application controls

Examining change management, application security and control effectiveness through an audit lens.

  • Change and transport management controls
  • Application security configuration
  • Control design and the evidence behind it

04 / Tooling

SAP GRC & technical depth

  • SAP GRC Access Control: Access Risk Analysis, Access Request Management, Emergency Access Management, Business Role Management
  • ABAP for security analysis and tooling
  • LDAP and Active Directory integration

Discuss your SAP security challenges.