Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

SAP IS-Media SoD Rule Set

ricardo_jimenez4
Explorer
0 Kudos

Hi Everyone

I would like to know if anyone have a rule set for the IS-Media SAP solution, specially for the M/SD and M/PS modules

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi Ricardo,

A few years ago I was looking for IS specific rule sets also, but it seems that there is no SAP standard developed version openly available. I know some GRC implementing specialists (and audit companies) have built up so called "Starter" rule sets for IS solutions, but to get your hands on it, you would have to involve them in your project and allow them to devise a custom governance framework and rule set for your company (i.e. pay for their services and intellectual property).

From personal experience, if you have a confident understanding of the SAP standard rule set, you could relate IS specific t codes to the standard ECC tcodes and make custom functions and risks similar to the ones in the SAP standard rule set.

In addition, I would also get function specialists, Internal and External Audit involved and see if any risks have been reported in regards to your IS-Media transactions/processes and see if you can write your own rules up with the information at hand.

If you feel you have little confidence in trying to device your custom rules and instead need the professional help, it may be worth reaching out to your auditors or the GRC specialists to help you devise the ruleset.

Hope that helps.

2 REPLIES 2

Former Member
0 Kudos

Hi Ricardo,

A few years ago I was looking for IS specific rule sets also, but it seems that there is no SAP standard developed version openly available. I know some GRC implementing specialists (and audit companies) have built up so called "Starter" rule sets for IS solutions, but to get your hands on it, you would have to involve them in your project and allow them to devise a custom governance framework and rule set for your company (i.e. pay for their services and intellectual property).

From personal experience, if you have a confident understanding of the SAP standard rule set, you could relate IS specific t codes to the standard ECC tcodes and make custom functions and risks similar to the ones in the SAP standard rule set.

In addition, I would also get function specialists, Internal and External Audit involved and see if any risks have been reported in regards to your IS-Media transactions/processes and see if you can write your own rules up with the information at hand.

If you feel you have little confidence in trying to device your custom rules and instead need the professional help, it may be worth reaching out to your auditors or the GRC specialists to help you devise the ruleset.

Hope that helps.

0 Kudos

Hi Harinam

Thanks for your response, right now we are working on that way, trying to relate IS specific tcodes to standard tcodes

thanks