← Back to Controls

APP-05

Layer:
Application
Category:
Access to Programs and Data
Control Type:
Preventative
Execution Type:
Manual
Effective Date:
July 29, 2026

Control Description

SAP user security role assignments are reviewed and approved by authorized management via automated GRC workflows or documented ticketing systems prior to provisioning

Risk

Inadequate restriction of user access or failure to enforce the principle of least privilege may result in users obtaining unauthorized access to sensitive application functions or data, leading to inappropriate modifications, data breaches, or fraudulent activity.

Implementation Details

Automated Provisioning via SAP GRC:
• Standard role assignments and modifications are requested, evaluated for SoD risks, and approved through automated SAP GRC Access Request workflows. Upon final approval, GRC automatically provisions the roles to the user ID in the target SAP system.

Manual/Exception Provisioning via Ticketing Systems:
•For urgent requests, break-fix scenarios, or areas not integrated into GRC, role assignments performed directly in SAP (via transactions SU01 or SU10) require an approved IT service management ticket (e.g., ServiceNow) attached as evidence before or concurrently with the change.

Test Procedures

Population Extraction (SUIM / Change Documents):
• The auditor uses transaction SUIM -> Change Documents - > For role assignment , to extract the complete population of new role assignments made during the audit period across

Sample Selection:

• The auditor selects a representative sample of role assignments across both GRC workflows and manual SU01/SU10 executions.

Testing for Approval (The "ToE"):

• For GRC Sample Items: Inspect the GRC audit log to verify that the request was approved by the designated manager/role owner prior to provisioning.

• For Manual (SU01/SU10) Sample Items: Trace the user role assignment to an associated ticketing system (e.g., ServiceNow). Inspect the ticket to confirm that an authorized manager or system owner approved the specific role assignment before the Basis or security administrator executed the change in SAP.