preview

Nt1310 Unit 9 Final Paper

Decent Essays

Access refers to the inflow or exchange of information between a subject(person) and a resource which could be a system, it could also be seen as the unrestricted activity an individual is allowed to perform within any given scenario or environment. Access control limits an individual to view only the set of information or data in which he or she is permitted to come in contact with. In an SAP system how do we restrict access to sensitive data within the system? We make use AUTHORIZATIONS. When talking about authorizations; we are simply referring to those set of activities which an individual or a subject is permitted to perform within any given scenario. The following questions would guide you on your way to implementing a good authorization concept. 1. Do you have a …show more content…

Among those activities stated is there anyone which would be performed once in a while? 5. Do you have a way to ascertain if a user is capable of performing conflicting actions in your system? 6. Have you ever checked if your role provides excessive authorization? 7. How do you monitor users with powerful authorization in your system? 8. Do you think your roles provide the minimum access needed for a user to sufficiently perform his/her job function for the period of time in which they are expected to carry out that activity? 9. How do you manage the access of users who have terminated their contracts with the company? If you don’t have the answers to some of the questions pointed above, I believe there is a need to carryout a redesign of the authorizations within your system. The benefits of a better authorization concept would; a. Minimizes the loss the company would incur b. Minimizes the risk associated with SOD violations c. It gives an assurance that the business information is secured. i.e. users have access to only what they are permitted to use or view d. It adds value to the business i.e. it enhances the business operations which would inturn have a positive impact on the business

Get Access