a detailed guide to the available reporting options with sap grc and compliance 10.0 solutions

Upload: sapgrcsme

Post on 03-Nov-2015

19 views

Category:

Documents


1 download

DESCRIPTION

A Detailed Guide to the Available Reporting Options with GRC AC 10.0

TRANSCRIPT

  • A Detailed Guide to the Available Reporting

    Options with SAP Governance, Risk, and

    Compliance 10.0 Solutions SAP GRC Solution Management

  • 2012 SAP AG. All rights reserved. 1

    Safe Harbor Statement

    This document is intended to outline future product direction, and is not a

    commitment by SAP to deliver any given code or functionality. Any statements

    contained in this document that are not historical facts are forward-looking

    statements. SAP undertakes no obligation to publicly update or revise any

    forward-looking statements. All forward-looking statements are subject to various

    risks and uncertainties that could cause actual results to differ materially from

    expectations. The timing or release of any product described in this document

    remains at the sole discretion of SAP. This document is for informational purposes

    and may not be incorporated into a contract. Readers are cautioned not to place

    undue reliance on these forward-looking statements, and they should not be relied

    upon in making purchasing decisions.

  • 2012 SAP AG. All rights reserved. 2

    Agenda

    1. Options for GRC 10.0 Reporting

    2. Technical Prerequisites to GRC 10.0 Reporting

    3. License Options

    4. Wrap-up

  • 2012 SAP AG. All rights reserved. 3

    Reporting Within GRC 10.0 In the News

    GRC 10.0 is said to include more powerful analytics Information Week

    Upgrades to core compliance capabilities include new embedded business

    intelligence capabilities ComputerWeekly

    Business intelligence capabilities will factor more prominently in customers GRC purchase decisions Chris McLean, Forrester Research

  • Options for GRC 10.0 Reporting

  • 2012 SAP AG. All rights reserved. 5

    Reporting Within GRC 10.0

    Overview

    GRC 10.0 reporting provides a range of options that brings impact across all user types

    Custom reporting on extracted data

    Extracted data will enable creation of custom reports/dashboards using

    SAP BusinessObjects Business Intelligence (BI) solutions

    Integration with SAP NetWeaver Business Warehouse (BW)

    GRC 10.0 integrated with BW delivers a tightly integrated data warehousing

    infrastructure for driving business intelligence predicated on a single version of

    the truth

    Standard reports ABAP List Viewer (ALV) and SAP Crystal Reports integration

    GRC 10.0 ships with standard reports

    GRC 10.0 enables users to create and modify reports within the application

  • 2012 SAP AG. All rights reserved. 6

    Reporting Within GRC 10.0 Standard ABAP List Viewer and Crystal Integration

    Standard ALV and

    Crystal Integration Ideal for Not as well suited for

    Is the reporting standard

    Provides real-time access to GRC data to create reports

    PC and RM also support data buffers to speed performance of large reports

    Crystal Reports native integration into ALV for pre-delivered GRC backend reports

    No additional license required to create custom ALV reports

    Day-to-day reporting needs, with personalization by user

    Creating canned reports embedded within the application

    Expert GRC users to create reports

    Tight application integration

    Real-time reporting and analysis

    Ad hoc query and analysis

    A user base that demands high interactivity

    Merging data from multiple sources

  • 2012 SAP AG. All rights reserved. 7

    Reporting Within GRC 10.0 Integration with SAP NetWeaver Business Warehouse

    Integration with SAP

    NetWeaver Business

    Warehouse Ideal for Not as well suited for

    Delivered with preconfigured BW content; role and task-related information models that are based on metadata in SAP GRC 10.0

    Offers advanced business analysis, as well as ad hoc reporting and analytics

    Serves as a template / example for customer-defined BI content

    Reporting and analysis of GRC data in an enterprise reporting structure

    Existing BW customers to leverage their investments

    Analytical reporting, such as trending over time, data analysis, and data mining

    Custom reporting

    Analysis and reporting on real-time data

  • 2012 SAP AG. All rights reserved. 8

    Reporting Within GRC 10.0 Custom Reporting on Extracted Data

    Custom reporting on

    extracted GRC data Ideal for Not as well suited for

    Provides a business add-in (BAdI) that customers can implement to extract GRC data from ALV

    The extracted data can be saved in any user-defined format (for example, as XML, CSV, or XLS)

    The extracted data will require an interpretation layer to enable users to create ad hoc reports and dashboards

    Creating custom dashboards, reports and perform Web-based ad hoc analysis

    Users looking for flexible BI reporting options

    Operational reporting to provide a snapshot of latest information

    Analysis and reporting on real-time data

    High-volume data analysis

  • GRC 10.0 Reporting Options ABAP List Viewer, Crystal Integration, and Dashboards

  • 2012 SAP AG. All rights reserved. 10

    Reporting Within GRC 10.0 Unified User Interface

    Reports for

    Evaluation and

    other assessment

    Reports for Policy

    setup audit Analysis

    and Compliance

    structure

  • 2012 SAP AG. All rights reserved. 11

    Reporting Within GRC 10.0 ABAP List Viewer

    SAP ABAP List Viewer (ALV) is a generic tool that outputs data in a table form (rows and columns)

    Provides integrated function to manipulate output (such as sort, totals, filter, column order, or hide) and export it (as Excel, Crystal Report, or CSV files)

    Provides flexibility to change default column order and availability

    More information on ALV can be found at: https://wiki.sdn.sap.com/wiki/display/ABAP/ALV

    View SAP Note 551605 for an ALV FAQ

    To create a new ALV report with customized output data, copy and modify an existing

    report.

    Refer to RKT material (resources) for more details on how to create a custom ALV report

  • 2012 SAP AG. All rights reserved. 12

    Reporting Within GRC 10.0 ABAP List Viewer

  • 2012 SAP AG. All rights reserved. 13

    Reporting Within GRC 10.0 Report Personalization

    Personalize report columns, sorts, and filters by user

    Customize your

    Report view

  • 2012 SAP AG. All rights reserved. 14

    Reporting Within GRC 10.0 Prerequisite for Crystal Integration

    All GRC 10.0 Reports** can be displayed in the Crystal Report format

    The following need to be installed to use ALV-based Crystal Reports:

    NET framework 2.0 The Crystal Reports ALV viewer is installed on the local client system. See SAP Note 1353044. For use in Web Dynpro: ACF (Active Components Framework) is installed automatically, when

    you switch to Crystal Reports for the first time, see SAP Note 766191

    Enable Crystal Report

    To enable Crystal Reports, go to SAP NetWeaver -> Application Server -> SAP List Viewer(ALV) -> Maintain Web Dynpro ABAP-Specific Settings

    ** GRC 10.0 dashboards do not support the Crystal Report viewer

  • 2012 SAP AG. All rights reserved. 15

    Reporting Within GRC 10.0 ALV Report with Crystal Integration Using Crystal Template

    Crystal templates can be customized for each report (see SAP Note 1538634)

  • 2012 SAP AG. All rights reserved. 16

    Reporting Within GRC 10.0 ALV Report with Crystal Integration Using Crystal Template

    Custom Crystal Template

  • 2012 SAP AG. All rights reserved. 17

    Reporting Within GRC 10.0

    Comparison

    ALV Generic Crystal

    Template

    Customized Crystal

    Template

    Personalizable Columns Available Available Not available

    Add Columns Via personalization Via personalization Via Crystal Designer

    Hierarchy Collapsible Static Static

    Drill-down Supported Not Supported Supported

    Graphics Not Supported Not Supported Supported

    Maintenance IMG IMG IMG + Crystal Designer

  • GRC 10.0 Reporting Options - Integration with

    SAP NetWeaver Business Warehouse (BW)

  • 2012 SAP AG. All rights reserved. 19

    Query

    SAP Back-End Systems SAP GRC 10 SAP NetWeaver BW System

    GRC Info Cube

    GRC Data

    GRC 10.0 Reporting SAP NetWeaver BW Integration

    RFC Connector

    The GRC PC/RM BI Content is part of BI

    Content 7.04 SP4+

    The GRC AC BI Content is part of BI Content

    7.07 (release to customer in June 2012)

    With SAP Business Explorer (BEx Browser),

    customers can create graphical charts and

    additional custom views of GRC data

    RFC Connector

  • 2012 SAP AG. All rights reserved. 20

    SAP NetWeaver BW Integration SAP Business Objects BI tools

    SAP NetWeaver BW

    BEx Query

    Crystal Reports, Web Intelligence, Dashboards, and Analysis

    InfoProviders

    Unified direct BI Consumer Service (BICS) access in SAP BusinessObjects BI 4.0

    BICS

  • 2012 SAP AG. All rights reserved. 21

    Process Control and Risk Management BI Content Features

    Common BI model uses standard R/3 data sources and pre-delivered BI content

    Full PC/RM model integration (timeframe concept)

    Robust extraction and performance improvements using reporting buffers

    BW data load scenarios (process chains) significantly improved to support refresh/reload of timeframe data in BW system (type of delta extraction)

    Extended integration of BI reports and GRC backend system (long text retrieval that is, Control Description and Issue Details fields)

    Built-in BW reporting authorizations

    Extraction support for user-defined fields for selected entities and built-in currency conversion

    PC 10.0 enables extractors to support Multi Compliance Framework which customers can extend to create their own BW content

  • 2012 SAP AG. All rights reserved. 22

    Process Control 3.0 BI Content Highlights*

    *compatible with Process Control 10.0

  • 2012 SAP AG. All rights reserved. 23

    Risk Management 3.0 BI Content Highlights*

    *compatible with Risk Management10.0

  • 2012 SAP AG. All rights reserved. 24

    Risk Management 3.0 BI Content Highlights (cont.)

  • 2012 SAP AG. All rights reserved. 25

    Access Control BI Content Features Planned features for BI_CONT 707

    Layered and scalable architecture design principles applied

    Delta extraction for large data volumes (for example, access risk violations)

    Built-in support for BW reporting authorizations

    Long text retrieval in BW Query from backend system for important entities (for example, mitigation and risk descriptions)

    A timeframe dependency concept does not exist in AC, thus trend analysis will require synchronized extraction of data from AC to BW system

    Custom field extraction support for select entities (for example, Role or Access Request)

    Note: The above is an outline of future product direction and is not a

    commitment by SAP for delivery.

  • 2012 SAP AG. All rights reserved. 26

    Access Control BI Content Features Planned features for BI_CONT 707 (Cont.)

    Access Control 10.0 BW Content plans to cover the following Access Control

    application data:

    Access Requests

    Access Risk Violations, SoD Alerts

    Mitigation Assignments and Control Details

    Management Summary Reports

    Roles, Profiles, Critical Roles, Critical Profiles

    Emergency Access Management Log Summary

    AC Managed Users (Application Users and Monitored Users)

    Reporting Authorizations (Object-Level Security)

    Long Text Metadata

    Access Control Workflow Transactions Details

    Note: The above is an outline of future product direction and is not a

    commitment by SAP for delivery.

  • 2012 SAP AG. All rights reserved. 27

    Access Control 10.0 BW Content Data Sources in SP8 RTC March 2012

    Access Risk Violations Alerts

    Management Reports (Summaries)

    SoD Master Data

    Risks, Actions, Functions, Mitigation Controls, Rules

    Business Role Management Master Data

    Roles, Users, Landscapes, Systems

    Access Request Master Data

    AC Workflow Master Data

  • GRC 10.0 Reporting Options Leveraging BI 4.0 Suite

  • 2012 SAP AG. All rights reserved. 29

    SAP BusinessObjects Business Intelligence (BI) Suite Overview

    SAP BusinessObjects BI 4.0

    SAP Crystal Reports 2011

    SAP BusinessObjects Dashboards (formerly Xcelsius)

    SAP BusinessObjects Web Intelligence

    SAP BusinessObjects Explorer

  • 2012 SAP AG. All rights reserved. 30

    SAP BusinessObjects BI 4.0 Suite Accessing GRC Data

    Existing BW content for GRC PC, RM and AC**

    Can be used without modifications

    Serves as a template or an example for customer-defined BI Content

    Integration

    with SAP

    NetWeaver

    Business

    Warehouse

    Custom

    reporting on

    Extracted

    data

    The ALV report data can be exported to any format by implementing the existing GRFN_REPORT_DATA BAdI in GRC reporting

    framework

    Might have performance issues with large volume of data

    Reporting/dashboard on offline data

    Custom

    Reporting on

    Extracted

    Data

    **AC content planned for June 2012 release, refer to BW Integration

  • 2012 SAP AG. All rights reserved. 31

    SAP BusinessObjects BI 4.0 Suite Crystal Reports 2011

    Crystal Reports Ideal for Not as well suited for

    Delivers highly formatted, pixel-perfect report design

    Provides complete data access including Universe queries

    Has a complete SDK for creation, modification, and delivery

    Is part of a complete BI solution: SAP BusinessObjects Enterprise

    Complex, highly formatted report design

    Creating report templates

    High-volume report distribution

    Tight application integration

    Offline/online report viewing

    Out-of-the-box Web-based design environment

    Ad hoc query and analysis

    User base that demands high interactivity

  • 2012 SAP AG. All rights reserved. 32

    SAP BusinessObjects BI 4.0 Suite Crystal Reports 2011 Example

  • 2012 SAP AG. All rights reserved. 33

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Dashboards (Formerly Xcelsius)

    Dashboards Ideal for Not as well suited for

    Instant visualization of key metrics

    Drag-and-drop segmentation analysis

    Pre-built templates expedite dashboard design and deployment

    Provides the ability to interact with dashboards within portals, reports, presentations, and PDFs

    Is part of a complete BI suite: SAP BusinessObjects BI 4.0

    Everyday business users

    Graphical representation of key metrics

    Sharing key operational metrics with multiple output formats

    Scaling dashboards to users inside and outside of the organization

    Broader and deeper analysis

    Standard report visualization

    Offline report viewing

  • 2012 SAP AG. All rights reserved. 34

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Dashboards Example

  • 2012 SAP AG. All rights reserved. 35

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Web Intelligence (WeBI)

    SAP BusinessObjects Web

    Intelligence Ideal for Not as well suited for

    Easy to use and design ad hoc reporting

    Build once and display anywhere mobile device or desktop

    Feature-rich environment for traditional BI users

    Flexibility for broader and deeper analysis

    Create reports, charts, tables, new calculations, change layout, format report content, mash up the data seen on the report with personally saved files

    Ad hoc query and analysis for users with an understanding of BI

    Web-based design environment

    Self-service reporting

    Creating canned report templates

    Offline/online report design and viewing

    Highly formatted operational reports

    Casual reporting users who need quick access

    High-volume report distribution

    Tight application integration

  • 2012 SAP AG. All rights reserved. 36

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Web Intelligence Example

  • 2012 SAP AG. All rights reserved. 37

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Explorer

    SAP BusinessObjects

    Explorer Ideal for Not as well suited for

    Innovative search and explore tool

    Self-service business intelligence for all users

    Simple and intuitive access to corporate data

    Fast access to relevant, quality information

    Combines the simplicity and speed of Internet searches with instant response times

    Analysts to perform ad hoc analysis of large volumes of data

    Searching and exploring data to discover relationships and uncover root cause

    Finding and analyzing corporate data on the fly, without needing to build reports or format charts

    Users who arent familiar with underlying data sources and how to formulate queries

    Easy access to up-to-date information

    BI experienced users who need a feature-rich environment

    Complex, highly formatted report design

    High-volume distribution of highly formatted, formal reports

    Canned report templates

  • 2012 SAP AG. All rights reserved. 38

    SAP BusinessObjects BI 4.0 Suite BusinessObjects Explorer Example

  • 2012 SAP AG. All rights reserved. 39

    SAP BusinessObjects BI On-Demand www.ondemand.com/businessintelligence/

  • Technical Prerequisites for GRC 10.0

    Reporting

  • 2012 SAP AG. All rights reserved. 41

    SAP NW Portal 7.01

    GRC Portal Content

    SAP NW BW 7.02

    BI Content 7.06

    GRC BI Content

    Identity Management Solutions (SAP or Non-SAP)

    optional

    optional

    http

    RFC

    Web

    services

    optional

    RFC

    RFC SAP NetWeaver

    Enterprise Search 7.0

    GRC Search

    optional

    SAP NW JAVA 7.01

    Adobe Document Server

    optional

    Non-SAP Business Applications Adapter

    optional

    SAP ERP (4.6C 7.1)

    NW Function Modules

    (Plugin: GRCPINW)

    HR Function Modules

    PC Automated Ctrls

    (Plugin: GRCPIERP)

    GTS Plugin

    (Plugin: SLL-PI)

    RFC

    optional

    SAP NetWeaver

    AS ABAP 7.02

    AC, PC & RM

    (Software Component: GRCFND_A)

    SAP GRC Suite 10.0

    GTS

    (Software Component: SLL-LEG)

    Content Lifecycle Management (CLM)

    Front-End Client

    DIAG http

    SAP GUI

    7.10

    Web Browser

    Adobe Flash Player

    SAP CR Adapter

    RFC SAP NetWeaver PI

    Nota Fiscal Content

    Required for Nota Fiscal E.

    Nota Fiscal Electronica

    (Software Component: SLL-NFE)

    Technical Prerequisites GRC 10.0 Reporting

    The front end needs a Web browser or a local installation

    of the SAP NetWeaver Business Client (NWBC 3.0)

    The browser can be used to access GRC 10.0 Suite

    through NWBC or SAP NetWeaver Portal

    An Adobe Flash Player (browser plug-in) is used for

    displaying dashboards, for example, a risk heat map

    The SAP Crystal Reports Adapter (CRA) and the Active

    Components Framework (ACF) are required for viewing

    GRC embedded SAP Crystal Reports. The CRA requires a

    client installation.

    Reports can also be displayed with the ABAP List Viewer

    (ALV)

    Front-End Client

    SAP

    GUI

    7.10

    Web Browser

    Adobe Flash Player

    CRA

    NWBC 3.0

  • License Options

  • 2012 SAP AG. All rights reserved. 43

    License Options Current Release

    For GRC 10.0, the following Crystal Reports, Dashboard Designer and Report Viewing licenses

    are included:

    1. License

    Licensee may use each licensed copy of Crystal Reports, SAP BusinessObjects Enterprise, and SAP Integration Kit only in conjunction with the SAP BusinessObjects Governance, Risk and Compliance

    (GRC) application with which it was provided. Accessing data that is not specifically created or used by

    the GRC application is in violation of this license. Only licensed Users of the GRC application may view

    Crystal Reports and Dashboard presentations content.

    2. Crystal Reports/Dashboard Designer

    Licensee may use the designer component included with Crystal Reports /Dashboard solely to (a) modify reports/reports provided by SAP as part of the GRC application, and (b) create reports/dashboards based

    on GRC application data.

    All GRC users will get viewing privileges, and authoring will be granted to GRC Expert Named Users, at

    no additional cost

    3. Report Viewing

    Crystal Reports viewer for ALV is a free download and dashboards are embedded within the application.

    Note: Not retroactive to any prior releases of these products

  • Wrap-up

  • 2012 SAP AG. All rights reserved. 45

    Resources

    General help with SAP Governance, Risk, and Compliance

    http://help.sap.com SAP Business Suite Solutions for Governance, Risk and Compliance

    http://help.sap.com Analytics Governance, Risk, and Compliance

    ALV Report Customization and Crystal Integration

    Add a new report to GRC Launch pad :

    http://help.sap.com/saphelp_nw70ehp2/helpdata/en/78/08fcd9fa454adb89792f0556f5d712/frameset.htm.

    Create a modify/create ALV report and Crystal integration :

    https://websmp207.sap-ag.de/~sapidb/011000358700000536722011E

    https://websmp207.sap-ag.de/~sapidb/011000358700000522042011E

    BW version support for GRC BI Content:

    http://help.sap.com/bicontent

    SAP Ramp-up Knowledge Transfer (RKT)

    https://service.sap.com/RKT *

    * Requires login credentials to the SAP Service Marketplace

  • 2012 SAP AG. All rights reserved. 46

    Key Takeaways

    SAP GRC solutions offer a variety of reporting options

    SAP GRC 10.0 harmonizes reporting access to one user interface

    SAP GRC 10.0 offers BusinessObjects BI reporting embedded in the application

    The option of modifying reports within GRC 10.0 exists with the SAP

    BusinessObjects BI 4.0 Suite

    ALV reports are highly customizable

    SAP GRC 10 includes the Designer and Report Viewing Licenses

    Clear how-to-guides available in SMP

  • Thank You!

    Swetta Singh

    [email protected]

  • 2012 SAP AG. All rights reserved. 40

    No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information c ontained herein may be changed without pr ior notice.

    Some software products marketed by SAP AG and its distributors contain proprietary software c omponents of ot her software vendors.

    Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation.

    IBM, DB2, DB2 Universal Database, System i, System i5, System p, System p5, System x, System z, System z10, System z9, z10, z9, iSeries, pSeries, xSeries, zSeries, eServer, z/VM, z/OS, i5/OS, S/390, OS/390, OS/400, AS/400, S/390 Parallel Enterprise Server, PowerVM, Power Architecture, POWER6+, POWER6, POWER5+, POWER5, POWER, OpenPower, PowerPC, BatchPipes, BladeCenter, System Storage, GPFS, HACMP, RETAIN, DB2 Connect, RACF, Redbooks, OS/2, Parallel Sysplex, MVS/ESA, AIX, Intelligent Miner, WebSphere, Netfinity, Tivoli and Informix ar e trademarks or r egistered trademarks of IBM Corporation.

    Linux is the registered trademark of Linus T orvalds in the U.S. and other countries.

    Adobe, the Adobe logo, Acrobat, PostScript, and Reader are ei ther trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries.

    Oracle is a registered trademark of O racle Corporation.

    UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group.

    Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or r egistered trademarks of C itrix Systems, Inc.

    HTML, XML, XHTML and W3C are trademarks or registered trademarks of W 3C, World Wide Web Consortium, Massachusetts Institute of Technology.

    Java is a registered trademark of Sun Microsystems, Inc.

    JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape.

    SAP, R/3, SAP NetWeaver, Duet, PartnerEdge, ByDesign, SAP BusinessObjects Explorer and other SAP products and services mentioned herein as well as their respective logos are trademarks or r egistered trademarks of SAP AG in Germany and other countries..

    2012 SAP AG. All rights reserved

    Business Objects and the Business Objects logo, BusinessObjects, Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and other Business Objects products and services mentioned herein as well as their respective logos are trademarks or r egistered trademarks of Business Objects Software Ltd. in the United States and in other countries.

    All other product and service names mentioned are the t rademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may var y.

    The information in this document is proprietary to SAP. No part of this document may be reproduced, copied, or transmitted in any form or for any purpose without the express prior written permission of SAP AG.

    This document is a preliminary version and not subject to your license agreement or any other agreement with SAP. This document contains only intended strategies, developments, and functionalities of the SAP product and is not intended to be binding upon SAP to any particular course of business, product strategy, and/or development. Please note that this document is subject to change and may be changed by SAP at any time without notice.

    SAP assumes no responsibility for errors or omissions in this document. SAP does not warrant the ac curacy or c ompleteness of the information, text, graphics, links, or ot her items contained within this material. This document is provided without a warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, or non-infringement.

    SAP shall have no liability for damages of any kind including without limitation direct, special, indirect, or consequential damages that may result from the use of t hese materials. This limitation shall not apply in cases of intent or gross negligence.

    The statutory liability for personal injury and defective products is not affected. SAP has no control over the information that you may access through the use of h ot links contained in these materials and does not endorse your use of third-party Web pages nor provide any warranty whatsoever relating to third-party Web pages.