 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAP Watch &#187; GRC</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sap-watch/tag/grc/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sap-watch</link>
	<description>A SearchSAP.com blog</description>
	<lastBuildDate>Tue, 21 May 2013 16:52:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>SAP and CA partnership boosts SAP’s position in GRC market</title>
		<link>http://itknowledgeexchange.techtarget.com/sap-watch/sap-and-ca-partnerships-boosts-sap%e2%80%99s-position-in-grc-market/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sap-watch/sap-and-ca-partnerships-boosts-sap%e2%80%99s-position-in-grc-market/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 15:47:31 +0000</pubDate>
		<dc:creator>CourtneyBjorlin</dc:creator>
				<category><![CDATA[GRC]]></category>
		<category><![CDATA[SAP]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sap-watch/?p=1350</guid>
		<description><![CDATA[Excel is the biggest competitor in the Enterprise GRC space, Gartner&#8217;s French Caldwell said to me on a call about SAP&#8217;s new IT GRC partnership with CA. That sentiment jived with a survey we recently conducted on SAP priorities on SearchSAP.com. Most of our readers said they weren&#8217;t using SAP&#8217;s GRC applications, either because they [...]]]></description>
				<content:encoded><![CDATA[<p>Excel is the biggest competitor in the Enterprise GRC space, Gartner&#8217;s French Caldwell said to me on a call about SAP&#8217;s new IT GRC partnership with CA.</p>
<p>That sentiment jived with a survey we recently conducted on SAP priorities on SearchSAP.com. Most of our readers said they weren&#8217;t using <a href="http://searchsap.techtarget.com/report/Special-Report-SAP-GRC-software" target="_blank">SAP&#8217;s GRC applications</a>, either because they weren&#8217;t aware of them or they didn&#8217;t need them.</p>
<p>But Caldwell&#8217;s clients are finding that managing everything in Excel leads to &#8220;spreadsheet chaos,&#8221; he said. Therefore, he&#8217;s seeing more interest in buying one platform to automate these processes.</p>
<p><span id="more-1350"></span></p>
<p>And to that end, they&#8217;re looking for something to manage both Enterprise GRC and IT GRC.  Enterprise GRC software automates the process of collecting data related to risk and compliance. IT GRC applies controls around the infrastructure and validates the controls enabled by these applications are working properly.</p>
<p>SAP isn&#8217;t ready to meet all of their needs, but it took a step in that direction last week with a <a href="http://www.ca.com/us/partners/spotlight.aspx?cid=30432" target="_blank">partnership announcement with CA</a>.</p>
<p>SAP has steadily been boosting its GRC platform, Caldwell said. Last year, SAP enabled integration between the compliance management piece (controls and testing of controls) and the risk management piece (risk assessments are a very important part of planning and scoping where put compliance efforts)</p>
<p>Now, SAP&#8217;s looking at how improve the visibility and integration of both audit management and the policy management, Caldwell said. SAP&#8217;s doing the development work now, and the software should be in ramp-up by the end of the year sometime in 2011.</p>
<p>With CA, SAP plans to sell customers integrated tools to manage IT GRC and Enterprise GRC.</p>
<p>In turn, the partnership with CA is not exclusive &#8211; and that is a good thing. SAP customers already have other products to manage IT GRC &#8212; such as Symantec and McAfee &#8212; and SAP needs to make it easier to integrate with those products, Caldwell said.</p>
<p>Yet it&#8217;s still playing catch-up &#8211; vendors such as Oracle and best-of-breeds like OpenPages still lead the way.</p>
<p>But SAP&#8217;s making headway here &#8211; including against its &#8220;next largest competitor,&#8221; according to a blog by <a href="http://corp-integrity.blogspot.com/" target="_blank">Michael Rassmussen.</a></p>
<blockquote><p>&#8220;To date, Oracle has had the broadest ala carte GRC offering. But customers regularly complain to Corporate Integrity about the lack of integration between the breadth of Oracle GRC solutions. SAP and CA offer a deeper suite of GRC solutions but have already demonstrated interesting integration between critical products. If you consider SAP&#8217;s additional partnership with Greenlight Technologies &#8211; SAP extends into the Oracle environment for managing GRC.&#8221;</p></blockquote>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sap-watch/sap-and-ca-partnerships-boosts-sap%e2%80%99s-position-in-grc-market/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automated GRC management for SAP security administrators</title>
		<link>http://itknowledgeexchange.techtarget.com/sap-watch/automated-grc-management-for-sap-security-administrators/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sap-watch/automated-grc-management-for-sap-security-administrators/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 13:41:49 +0000</pubDate>
		<dc:creator>Pastepotpete</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[SAP administration]]></category>
		<category><![CDATA[security management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sap-watch/?p=1181</guid>
		<description><![CDATA[Producing the records that auditors need in order to certify a company&#8217;s books and its processes can take up to months if done manually. Automated governance, risk and compliance (GRC) management solutions offer two major benefits: they can substantially reduce the cost of an audit, and auditors tend to look less deeply into automated record [...]]]></description>
				<content:encoded><![CDATA[<p>Producing the records that auditors need in order to certify a company&#8217;s books and its processes can take up to months if done manually. Automated <a href="http://searchsap.techtarget.com/topics/0,295493,sid21_tax314709,00.html">governance, risk and compliance (GRC) </a>management solutions offer two major benefits: they can substantially reduce the cost of an audit, and auditors tend to look less deeply into automated record reports.</p>
<p>This week I spoke to Jeff Rishel, vice president of IT at <a href="http://www.grahampackaging.com/">Graham Packaging Co</a>., a manufacturer headquartered in York, Pa., about his company&#8217;s <a href="http://searchsap.techtarget.com/news/article/0,289142,sid21_gci1371101,00.html">GRC efforts</a>. The company, which has 80 plants in 16 countries, has been an SAP user since 1999.</p>
<p>Rishel said that Graham purchased SAP Virsa in the early 2000s to help with Sarbanes-Oxley compliance. But even with Virsa, he said, there was one big problem: His team still had to gather all the information manually from various sources to give to the auditors.</p>
<p>Graham eventually replaced Virsa with ControlPanelGRC from SymSoft Corp.,  hoping to reduce the time spent on audit preparation, attain better SOX compliance and to streamline the Segregation of Duties (SOD) process.</p>
<p>All three goals were accomplished. The two weeks spent preparing for the audit process was reduced to one, and Rishel said that he personally no longer has to spend two hours a month doing SOD reporting. Much of the savings in time are because of the workflow engine embedded in ControlPanelGRC. The engine automates not just SOD but many IT business processes, allowing repetitive manual tasks to be done automatically with a workflow that tracks who requested changes, who developed, who tested, who approved, etc.</p>
<p>But the product has other features, including a bunch of utilities that make the day-to-day lives of security administrators and SAP technical administrators easier. &#8220;It&#8217;s not software you dust off once a year to get through an audit,&#8221; said <a href="http://www.corporatecomplianceinsights.com/authors/dan-wilhelms">Dan Wilhelms, president and founder of SymSoft, and a leading Basis consultant</a>.</p>
<p>At <a href="http://searchsap.techtarget.com/news/article/0,289142,sid21_gci1368378,00.html">SAP TechEd 2009</a>, I attended a session on compliance tips for security administrators given by Maria Jenkins, SAP&#8217;s GRC senior technical architect. During her presentation, she said, &#8220;Auditors are like accountants, they always say, ‘Show me the money.&#8217;&#8221; She went on to say that there&#8217;s really only one way to keep the auditors happy, and that&#8217;s documentation. &#8220;Documentation is the most important thing that a security administrator can provide for SOX and security compliance.&#8221;</p>
<p>I asked Rishel about that, and he agreed that documentation is vital. &#8220;If we have SODs we can&#8217;t resolve, they require a lot of documentation,&#8221; he said.</p>
<p>SAP recently announced that it will work more closely with Novell to <a href="http://searchsap.techtarget.com/news/article/0,289142,sid21_gci1371421,00.html">extend GRC to more of the IT infrastructure</a>. If you&#8217;re an SAP security administrator, what do you think of that? I&#8217;d like to hear from other SAP administrators about the GRC issues they&#8217;re facing.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sap-watch/automated-grc-management-for-sap-security-administrators/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
