cancel
Showing results for 
Search instead for 
Did you mean: 

difference b/w mitigation and remediation

Former Member
0 Kudos

hello experts,

pls tell me the right procedure when should i go for mitigation and when should i go for remediation

regards,

sanjay

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

My approach would be keep your roles as clean as possible and then try use mitigation at user level where you think you can't remediate but give conflicting access to user as part of the business requirement.

Thank you,

Partha

Former Member
0 Kudos

Sanjay,

What Partha suggested is a best practice approach. SAP roles should be clean so that the SoD violations as user level do not multuply. Once the roles are clean, you can identify the users having SoD vioaltions and either remove the access (remediate) or apply a mitigating control (mitigation).

Regards,

Alpesh

Former Member

Hi Sanjay,

Good Question, Everybody has confusions.

Remediation : Reducing conflicts from the role/user( nothing but removing roles from user if they causes violations, remove tcodes or authorization objects/fields from role if they are having violations in role)

Mitigation : if you cant remediate roles or users then alternate procedure is Mitigation.

Mitigation is process identifying controls(alternatives) using this procedure we can assign conflciting access to users/ roles with the help of control monitors who will be responsible for the above risks if something fraud happened.

This is all about documenting every risk and alternative procuderes we took to reduce the impact of the risks.

Regards

Hari

ganesh2821
Discoverer
0 Kudos

it was a nice explanation thank you