Skip to Content
SAP® GRC For Dummies®
book

SAP® GRC For Dummies®

by Denise Vu Broady, Holly A. Roland
May 2008
Beginner to intermediate
342 pages
9h 3m
English
For Dummies
Content preview from SAP® GRC For Dummies®

Chapter 16. Top Ten GRC Strategies

Are you eager to get started with GRC? This chapter details the strategies used in the most successful GRC projects.

Evaluate Which of the Most Prevalent GRC Issues Apply to You

The most prevalent GRC issues facing companies include audit compliance, segregation of duties, and internal productivity and resource availability.

For audit compliance, you should

  • Establish an approach and process to manage risks.

  • Pinpoint sources of deficiencies and data sources to identify preventative measures.

  • Eliminate conflicting testing methods and reconciliations.

For segregation of duties, you'll want to

  • Identify business functions that produce risks when executed by one person.

  • Gain risk visibility on 100 percent of user population.

  • Perform risk analysis before committing and approving changes to access controls.

To improve internal productivity and resource availability

  • Focus on prevention. It's better to prevent bad things from happening in the first place than to simply detect them after the fact.

  • Document test results and violations by business process and organization. Doing so will give you a scorecard of what's happening in various business processes and units.

  • Select controls and tolerances concurrent with organization policies, procedures, and regulations. In other words, you don't want alarms going off all the time — just when something warrants further investigation.

Adopt Best Practices

The 2006 SAP GRC Benchmarking Survey identified seven best practices for GRC: ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Moodle® For Dummies®

Moodle® For Dummies®

Radana Dvorak

Publisher Resources

ISBN: 9780470333174Purchase book