Soterion의 SAP 액세스 위험/GRC 진단

귀사의 노출 위험을 즉시 확인하세요.

.

 

Soterion Logo

많은 기업과 마찬가지로, 귀사의 주요 과제는 사기, 데이터 유출, 감사 실패를 예방하는 것입니다. 그러나 귀사의 특정 요구사항에 적합한 GRC 솔루션을 찾는 일은 쉽지 않습니다. 그렇기 때문에 당사는 전문가 팀이 제공하는 무료, 무의무(no-obligation) 액세스 위험 진단을 강력히 권장합니다.
당사는 귀사의 SAP 시스템에 숨겨진 직무 분리(SoD) 위험과 중요 트랜잭션 위험을 식별하고, 사용자 접근 권한이 실제 요구사항과 일치하는지 점검해 드립니다.

별도의 비용이나 의무 없이, SAP 액세스 리스크를 손쉽게 점검해 보세요.

Play video
Welcome to an overview of Soterion's SAP Access Risk Assessment process. Soterion offers select organizations running SAP the opportunity to perform an SAP Access Risk Assessment on their data. In this video, we will explain the process at a high level and discuss the benefits of performing this assessment. Here's what we'll cover: How much effort is required from you or your team's side? What data is used from SAP for this Access Risk Assessment? How is this data extracted? The Process: What are the benefits to my organization? What happens to our data after the assessment? How secure is our data? And lastly, connecting to your Soterion hosted database. How much effort is required from you or your team's side? Your effort involves a few straightforward tasks. Downloading the Data Extractor from our website will take approximately five minutes. Installing the Soterion Data Extractor on a desktop or laptop will take roughly five minutes. Initiating the download from SAP will take ten minutes. The extraction may take up to sixty minutes to run, but it will run-in the background. And lastly, uploading the files to Soterion's data center in your geographic region will take approximately five minutes. What data is used from SAP for this access risk assessment? Soterion extracts SAP authorization related tables such as USR02 and AGR_Define. We also download user transaction logs to determine whether any remediation or role cleanup opportunities exist. A full list of tables downloaded can be found in Soterion's Data Extractor Guide. How is this data extracted? Soterion has created a Data Extractor utility that uses standard SAP functionality to read the SAP authorization tables. No custom function modules or transports need to be installed on your SAP system. The person performing the data extract will need the SAP authorization for the tables being downloaded. Soterion can provide an SAP role with the necessary authorization if required. The Process: Download the Soterion Data Extractor from the Soterion website. Install the Soterion Data Extractor on a desktop or laptop. The person performing the data extraction uses their SAP credentials to initiate the extraction process. Upload the downloaded files to the Soterion Data Center. Soterion will prepare a database with this data. The client will be notified on completion, and the next steps will be communicated, which could include a demonstration or providing logon details to review the SAP Access Risk results. What Are the Benefits to my organization? A Soterion SAP Access Risk Assessment allows your organization to understand its access risk exposure. Soterion presents this information in a business friendly manner to enhance effective decision making. Powerful risk remediation functionality helps address access risk violations, which is especially beneficial before impending audits. It also offers a mini proof of concept using data that you are familiar with. What happens to our data after the assessment? After the assessment, Soterion will delete the data upon request. How secure is our data? Soterion adheres to the latest security protocols, including annual ISO27001 certification, a SOC 2 Type 2 report, and annual penetration testing. We do not download personal data such as email addresses. SAP Usernames are downloaded but can be masked to hide this information if needed. All data can be viewed via Soterion's Data Extractor before being uploaded, and it is zip-locked for added protection during the upload process. Connecting to your Soterion-hosted database Accessing the Soterion database requires a username and password that comply with your SAP password policy. Two factor authentication can also be set up if needed. Thank you for watching this overview of Soterion's SAP Access Risk Assessment process. We hope this video has provided valuable insights into how the assessment works and its benefits to your organization.
이 비디오에는 한국어 자막이 있습니다

Gradient line

Soterion 진단에서는 무엇을 확인할 수 있나요?

Bullet1 Bullet2 Bullet3 Bullet4
직무 분리(SoD) 충돌 및 중요 트랜잭션 액세스를 보유한 사용자 사용자가 해당 액세스를 부여받는 역할/프로필 사용자가 실제로 해당 트랜잭션 코드를 실행하고 있는지 여부 조직의 액세스 위험 노출을 줄이기 위해 수행할 수 있는 역할 정비 또는 위험 완화 방안 제안

 

Gradient line

How Soterion Works

진행 방식은 다음과 같습니다:

  • SAP 시스템에서 데이터를 손쉽게 추출할 수 있습니다(ABAP 또는 트랜스포트 불필요).
  • 데이터 추출 과정은 빠르고 간단하며, 고객 측에서 해야 하는 유일한 작업입니다.
  • 민감한 데이터는 내보내기 시 마스킹 할 수 있습니다.
  • 데이터는 귀하의 지역에 위치한 안전한 데이터 센터로 업로드됩니다.

귀사의 데이터를 공유하기 전, 표준 데모 데이터베이스를 먼저 보여드릴 수 있습니다:
오른쪽의 양식을 작성하여 무료 Soterion 진단을 요청해 주세요.

무상 진단보고서 받기