Vous êtes sur la page 1sur 4

SAP Solution Brief

mySAP ERP

SAP® COMPLIANCE
CALIBRATOR BY VIRSA
SYSTEMS
Meeting the Challenge of Regulatory Mandates
Through Continuous Compliance

SAP® Compliance Calibrator Acts of fraud, data tampering, privacy violations, theft of
by Virsa Systems software intellectual property, and exposure of trade secrets have become
commonplace in today’s corporate world. These acts, whether
automates the real-time detec-
large or small in scale, are taking a tremendous toll on businesses
tion and prevention of security worldwide. They reduce profitability, destroy shareholder trust,
and controls violations to undermine the company’s ability to compete, and erode market
deliver continuous compliance capitalization. In some cases, top executives are faced with
criminal punishment.
with regulatory mandates and
prevent internal fraud. The
Governments have responded by enacting a series of legislative
software reduces IT and audit mandates. While the Sarbanes-Oxley Act is the highest-profile
costs and makes possible high mandate for businesses working in the United States, it is just one
standards of corporate gover- of a growing list of current and proposed regulatory requirements.
The healthcare industry must now comply with the U.S. Health
nance. The only solution of its
Insurance Portability and Accountability Act (HIPAA) to protect
kind embedded in SAP systems, patient privacy rights, and financial firms are faced with the U.S.
it enhances the extensive Gramm-Leach-Bliley Act and Basel II. Increasingly stringent
compliance capabilities already corporate governance policies and privacy regulations are leading
found in mySAP™ ERP. companies to conduct more careful analyses of business risk and
tighten internal controls.

The CIO and members of the IT organization play an essential


role in helping the enterprise meet the requirements of these
mandates. They are the people who put in place the tools, sys-
tems, and control mechanisms to ensure corporate compliance.
But there are problems. For example, most IT organizations are allows you to reduce the cost of compliance, freeing up funds
faced with tight budgets – and Sarbanes-Oxley compliance is not for strategic developments that contribute to your company’s
inexpensive. In fact, U.S. companies will spend well over competitiveness.
US$6.5 billion in 2005 on Sarbanes-Oxley compliance, according
to AMR Research. In many enterprises, major development Your 24/7, Real-Time Solution
projects will be put on hold while IT focuses on meeting this SAP® Compliance Calibrator by Virsa Systems software is one
mandate. of the only solutions on the market today that is embedded in
SAP systems to provide real-time, 24/7 security and controls
As your business evolves, the interrelationships between finance, compliance. The software automates the real-time detection and
sales, and operations can grow in complexity, while the number prevention of ERP security and controls violations by delivering
of employees, departments, and business units are expanding. round-the-clock, continuous compliance with regulatory
The combination of these two factors can make your internal mandates. SAP Compliance Calibrator by Virsa Systems helps
auditing procedures very demanding. you reduce internal fraud, lower IT and audit costs, and reinforce
high standards of governance.
For that reason, some companies assess risk after the fact through
detection solutions that operate on downloaded data. Others Your SAP landscape is constantly in motion, an environment
invest in incomplete segregation of duties (SoD) solutions that characterized by dynamic data and a high degree of flexibility
can’t cope with the logic of enterprise resource planning (ERP) and scalability. As a result, real-time interfaces are the only way
systems and the subtle moves of a motivated perpetrator. Also, to ensure compliance integrity. With SAP Compliance Calibrator
compliance solutions sitting outside the ERP system cannot by Virsa Systems, you are able to test your entire SAP landscape
detect transactions hidden in custom code, or vulnerabilities for SoD violations and monitor critical transactions, continuously
in custom tables that give users unauthorized access. and in real time. The software’s simulation capabilities allow you
to take a proactive approach to compliance.
At the most fundamental level, you must be able to secure data
across the enterprise, control access to applications and databases, SAP Compliance Calibrator by Virsa Systems enhances the
secure and monitor critical transactions, and guard against SoD compliance solutions already found in the mySAP™ ERP solution.
violations. An SoD violation might involve something as seem- The software enhances the mySAP ERP audit information system
ingly innocent as allowing an employee to execute conflicting by adding the following capabilities:
transactions – for example, creating a vendor record in the system • Automatic SoD testing as part of your internal-control
and then paying the same vendor. What you need are ways to testing program
automate the ongoing process of complying with Sarbanes-Oxley • Object-level SoD analysis
and other externally imposed mandates. • Authorization administration
• Simulation (proactive compliance)
Ideally, your solution should provide a low-cost, sustainable • Risk mitigation and remediation
automatic process that ensures compliance and protects your • Real-time, drill-down analysis and reporting
organization in real time, 24 hours a day. This level of protection • Management reporting
• Analytical reporting
SAP Compliance Calibrator by Virsa Systems enhances • Effective reporting tailored to all audiences. You can
mySAP ERP management of internal control capabilities by provide regularly scheduled, simple status reports for auditors,
adding the following functions: e-mail alerts for management, and detailed drill-down for IT,
• Automated tests of SoD controls and reporting including SAP transaction codes for the more technically
• Simulation of SoD controls minded. Top executives responsible for the entire corporation,
• SoD mitigation and remediation or business unit managers concerned with a particular geo-
graphic and functional area, are able to receive and analyze
Key Product Highlights pertinent information without getting deluged by data.
Here’s how SAP Compliance Calibrator by Virsa Systems can • Library of best-practices SoD rules. You have access to the
turn your compliance headaches into a highly automated, largest and most comprehensive database of SoD rules at the
routine application that frees up your time for other more transaction and authorization-object levels for SAP solutions.
proactive IT activities: The library is constantly updated.
• Real-time risk assessment. Risk assessment is executed in • Simple, efficient implementation. Because SAP Compliance
real time with live data; you don’t have to wait for downloads. Calibrator by Virsa Systems is embedded in your SAP system,
Conflicts are identified immediately at both the transaction no additional hardware or software is required. Installation is
and authorization-object level. This reduces false positives and complete in a manner of minutes, and the entire deployment,
allows your administrators to resolve conflicts on the spot. including configuration and training, takes less than a week.
You clean your system with real-time scanning and keep it The compliance software consumes a minimum of resources
clean with real-time simulation. SAP Compliance Calibrator and has been optimized to ensure that there is no impact
by Virsa Systems executes cross-systems analysis to assess risk on mySAP ERP performance. In addition, you can expect
across multiple systems, such as customer relationship manage- significant savings from reduced human resources costs due
ment, human capital management, and so forth. to automation.
• Remote simulation with cross-system analysis. Any changes
due to remediation or role creation can be simulated in the Why SAP Compliance Calibrator by Virsa Systems?
production system and across multiple systems before a role Among the many business benefits that your company will
is generated or an assignment is made to a user. Your adminis- realize with SAP Compliance Calibrator by Virsa Systems are
trators can identify potential new SoD conflicts throughout faster internal-control testing cycles and reduced time to
the SAP landscape before changes are migrated to production compliance. If your organization is like many other enterprises,
by conducting “what-if” analyses at the development stage. you have more than 50,000 internal control processes that require
• Automated rule building. SAP Compliance Calibrator by testing, evaluation, and remediation. Many of these might be
Virsa Systems automates the SoD rule-building process to match authorization and access controls. Automation of the testing
system configuration settings, eliminating manual work and procedure for these controls makes it easier to achieve complete
significantly accelerating the process and reducing error. Sarbanes-Oxley compliance.
• Comprehensive analysis. Includes automated cross-system
analysis of customer code and custom tables that can give users
unauthorized access to the system. The compliance solution
also identifies another risk: reference user violations.
www.sap.com /contactsap

The real-time, continuous operation of SAP Compliance Compliance Made Easy


Calibrator by Virsa Systems stops authorization violations before Sarbanes-Oxley and other mandates impacting corporate gover-
they occur. The software’s extensive set of validated rules and nance are not going to go away any time soon. In fact, over time
detailed SoD analysis capabilities have been developed over there probably will be more legislation rather than less. That is
nearly a decade with deployments at hundreds of customer sites. why a proactive, real-time, 24/7 automated solution such as
These customers include some of the world’s largest companies. SAP Compliance Calibrator by Virsa Systems is essential to stop
authorization violations before they occur. SAP Compliance
ERP authorization compliance checking is simple, immediate, Calibrator by Virsa Systems brings years of SAP security domain
and extensive; violations are caught in development before experience into a product with the largest set of validated rules
you commit to production. Automated, detailed SoD analysis and detailed SoD analysis. The solution is a powerful supplement
and monitoring of critical transactions provide business users, to the extensive compliance capabilities provided by mySAP ERP.
auditors, and IT security with an instantaneous assessment
of authorization risk. SAP Compliance Calibrator by Virsa Systems allows you to
implement compliance practices that can result in better business
Because the automated analysis is complete and accurate, you practices, lower compliance costs, and the assurance that your
avoid wasting time on false positives and manual checking. company is proactively combating security and controls violations
Preventative measures keep your systems clean on a continuous on a 24/7, continuous, real-time basis.
basis.
Find Out More

Effective Corporate Governance/


To learn more about how SAP Compliance Calibrator by
Compliance with SAP® Solutions Virsa Systems can help ensure regulatory compliance at your
company, call your SAP representative or visit us online at
SAP® Compliance Calibrator by Virsa Systems www.sap.com/company/press/press.epx?PressID=2514.
Segregation of Duties Testing

mySAP™ ERP

Risk Management

Audit Management of
Information System Internal Controls

Consolidated Financial Reporting

Foundational Process Controls (ERP)

50 074 019 (05/04) Printed in USA.


2005 by SAP AG. All rights reserved. SAP, R/3, mySAP, mySAP.com, xApps, xApp, and other SAP products and services mentioned
©herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and in several other
countries all over the world. All other product and service names mentioned are the trademarks of their respective companies. Data contained
in this document serves informational purposes only. National product specifications may vary. Printed on environmentally friendly paper.
These materials are subject to change without notice. These materials are provided by SAP AG and its affiliated companies (“SAP Group”) for
informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with
respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty state-
ments accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty.

Vous aimerez peut-être aussi