Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

SAP

Welcome to the SAP topic!

In this topic you may collaborate with your peers by participating in discussions, adding links and documents, and starting or contributing to wikis.

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

 
This Topic Has:
758 Members
1 Online
7358 Visits

 Recent Discussions

SAP ECC 6.0 DDIC account. Posted by Rich.Ludwig.
SAP GUI Scripting. Posted by Benjamin638.
SAP B101 8.8. Posted by SamVarghese.

Community Leader

Leon
Sangram Dash

Sangram Dash

Title: Manager - Technology Process and Controls

Points: 232

NEW! Participate in Discussions Via Email. 

You can now respond to discussions by simply replying to the email alert. Just enable this feature in discussions on this topic. Learn more

Discussions: 31 total

Must be a Topic member to contribute
View All »
I have noticed that the DDIC account does not exist in my company's SAP ECC 6.0 installation.  Does anyone know what if any account in SAP ECC 6.0 has replaced the DDIC account?  Thank you in advance for your responses.
Rich.Ludwig | 3/14/2013 8:56:02 AM | COMMENTS(2)
We have just implemented SAP and there is a consideration for scripting to  be enabled on the SAP GUI Client side and SAP Server side GUI Scripting. Can anyone tell me the potential risk of enabling this and possible mitigation available.
Benjamin638 | 2/12/2013 9:22:08 AM | COMMENTS(1)
SAP for medium and small organizations.
SamVarghese | 1/31/2013 4:42:36 AM | COMMENTS(1)
My office is looking at options for documenting our audits, creating reports, etc. We are already familiar with TeamMate, AutoAudit, et al. Our quality assurance group uses the QM module for their audits, and it looks like it might work for internal audit...
Richard Fowler | 1/14/2013 1:39:10 AM | COMMENTS(9)
Can Anyone share the SAP GRC 10 Support documents as required for training the new users ?
Tariq296 | 12/21/2012 9:01:43 AM | COMMENTS(0)
Hello I belong to a tax authority that is deploying the SAP-TRM (Tax Revenue Management) module of SAP. Whilst there is an audit programme (ISACA) available as a download that relates to the  SAP-ERP module there doesn't appear to be anything similar th...
pauld | 12/18/2012 11:29:55 PM | COMMENTS(3)

Documents & Publications: 17 total

Must be a Topic member to contribute
View All »
In this document, I have listed some of the most common risks and the recommended controls for each of those risks. Although this would be applicable for any ERP, it is particularly well suited for SAP.
Posted by Bala_Krishnan_CISA_CIPP 131 days ago
Books
Posted by ISACA 135 days ago
Access controls and other areas traditionally focused upon by security professionals are no longer the only major risks to SAP systems. Today, SAP is confronted with a growing landscape of threats that include injection attacks, cross site scripting, session hijacking and denial of service. For the most part, business owners and security professionals are unaware of profound vulnerabilities laying in the technical components of SAP. Many of these vulnerabilities can be exploited by remote, external attackers without requiring a user account. These risks have arisen from the gradual shift towards open source languages, protocols, standards and Web-enabled services, as well as the increasing size and complexity of SAP. When combined with inherent weaknesses in existing network controls and the sophistication of attacks targeted at corporate applications and data, such a rare combination of circumstances should be viewed as a sinister perfect storm. Vulnerabilities in critical SAP components and services could be exploited by external attackers to interrupt SAP services, implement malicious changes to programs and files, intercept and alter data in transit, and corrupt or modify data directly in databases. If left unattended, these vulnerabilities raise serious concerns over the ability of companies to comply with SOX, PCI and other standards. This white paper discusses some of the methods used by hackers to attack and compromise SAP systems. It also addresses some lesser known risks to raise awareness within the community and improve the overall posture of SAP security.
Posted by Aman1974 319 days ago
Books
The revised and expanded second edition of this best-selling book describes all requirements, basic principles and best practices of security for an SAP system.
Posted by ISACA 325 days ago

Events & Online Learning: 1 total

30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!

Journal Articles: 32 total

Volume 1, 2013
by Gregory Zoughbi, CISM, CGEIT, PMP, TOGAF9, ITIL Expert, COBIT 4.1 (F)
Many organizations choose to acquire an enterprise resource planning (ERP) system to serve as a common system for their wide range of daily operations.
Volume 4, 2012
by Filip Caron and Jan Vanthienen, Ph.D.
This article aims to introduce business process analytics and mining to the information systems (IS) audit and control community.
Volume 4, 2012
by Jose Espin, CISA, CISSP, MCP, SAP
This article focuses on the application-level risk that arises from inappropriate implementation of access controls.
Volume 4, 2012
by Vasant Raval, DBA, CISA, and Greg Dyche
In this article, the term “governance” is used in the sense of information governance to discuss certain myths or misunderstandings of governance.
Volume 3, 2012
by ISACA | Reviewed by Shasikanth Malipeddi, CISA
Oracle PeopleSoft HCM is one of the most commonly used human capital management (HCM) system found in medium to large companies in the US.
Volume 3, 2011
by Stefan Wenig and Kyung-Hee Anita Kim-Reinartz
This article discusses ways to standardize data extraction and audit routines.

Wikis: 2 total

Blog Posts: 3 total

Must be a Topic member to view blog posts
Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
20 Jun 2012
The increased complexity and diversity in the information systems and the inability to rebuild the information systems from scratch is forcing enterprises to look at EAI as an alternative solution that will help extend the life of the existing application...
Posted By : Kannan | 0 comments
Converting to IFRS poses a significant challenge to organizations globally.  Many companies initially view the conversion process as solely an accounting challenge and fail to take into consideration the significant roleplayed by IT systems and processe...
Posted By : Iwan A | 0 comments