Big news! The community will be moving to a new platform April 21. Read more.
Big news! The community will be moving to a new platform April 21. Read more.
Absent Member.
Absent Member.
512 views

SAP GRC-Suite Connector

I'm looking forward to integrate SAP GRC-Suite.

Does Anyone know if this GRC-Suite is also logging through the "standard" audit log which would be read by the allready existing SAP-Audit-File Standard Connector of Arcsight?.

I don't know to much about this Governance, Risk & Compliance (GRC) Suite of Arcsight and would be happy gain some more informations if someone could tell.

Thanks in advance, tifoso

Labels (2)
0 Likes
2 Replies
Absent Member.
Absent Member.

GRC does not look at the audit logs in SAP as far as I know.  The primary product from the GRC suite is Access Control (provisioning and deprovisioning), Process Control and Risk Manger.  Currently ArcSight has a Web Service integration into Process control allowing us to pass events to the GRC Suite for follow up and remediation.  We have a very tight partnership with the GRC team and are working on a number of scenarios with them.

0 Likes
Absent Member.
Absent Member.

We have made very good progress with our SAP Monitoring Solution that can integrate with SAP GRC.  Below is a high level summary.  Please reach out to me direclty if you would like further detail curt.lockton@hp.com

ArcSight Enterprise View for SAP enables organizations to comprehensively monitor SAP security from the infrastructure layer up through transactions. The solution is composed of more than 100 use cases to address every facet of SAP security monitoring. The foundation for the solution is the use of the ArcSight Security Information and Event Management (SIEM) platform to monitor the entire infrastructure that supports an SAP implementation, from security and network devices to servers and databases, ensuring detection of attempts to breach SAP security both inside and outside of the application.

Working with SAP security experts and auditors, ArcSight has identified four key drivers for in-depth monitoring:

Fraud and Error: Whether malicious or unintentional, organizations lose millions of dollars each year due to fraud and errors. The Institute of Internal Auditors estimate that 0.1%–0.5% of all invoices are duplicate payments. These errors can be the result of overtasked personnel, changes in processes, mergers and acquisitions, temporary staff, or intentional fraud.

SAP BASIS and Misuse of Privilege: Privileged users (e.g., SAP Basis administrators and database administrators) have the highest level of access and permissions and can inflict significant damage to operations. This is one of the highest risk sources within an organization.

Audit and Compliance Automation: Various compliance and audit processes involve time-consuming, manual tasks, such as reporting on access to customer credit card data or monitoring segregation-of-duties exceptions. With appropriate integration and data analytics, many of these processes can be automated or streamlined.

360-Degree Security: Security threats to SAP can originate from within the application or can be completely external. An accounts payable user’s workstation may be compromised via a brute force attack or social engineering. That machine’s access to SAP now poses a security risk to SAP itself. These types of threats require monitoring not only of SAP, but also supporting infrastructure (servers, databases, network) and all points of access to SAP.

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.