SlideShare une entreprise Scribd logo
1  sur  11
Télécharger pour lire hors ligne
Processes do not have to kill you
GUIDED END-TO-END PROCESSES IN THE LIGHT OF THE USE OF CLOUD
SERVICES
Ute Riemann SAP Deutschland AG & Co. KG
© 2013 SAP AG. All rights reserved. 2Customer
Why security is so difficult - and why value is lost
• The value of Cloud Services is
generated „between“ the business and
technology
• But: outtasking services also means:
loosing control over the data (= missing
security)
• Today‘s approach: identify technology
risks and – as a consequence – do not
use Cloud services if too risky
 Too inflexible, too much value is lost
 Our approach:
look at the value chain first!
Security
People
BusinessTechnology Value of Cloud
Services
© 2013 SAP AG. All rights reserved. 3Customer
The 5 steps from identification of cloud value add and the
business process inherent compliance risks of a company
Identify the
company-
specific
value chain
Identify the
key processes
within the
value chain
Select the
appropriate
fraud indicators
Perform IT
identification
Link the
processes with
the cloud
specifics within
the E2E
process model
1 2 3 4 5
© 2013 SAP AG. All rights reserved. 4Customer
A comprehensive analysis of the compliance
requirements within the process environment
To answer this question it is required to
understand the various dimensions that
needs to be considered
Dimension 1: Business perspective
Dimension 2: Service perspective
Dimension 3: Compliance perspective
Service
perspective
Business
perspective
Compliance
perspective
© 2013 SAP AG. All rights reserved. 5Customer
The following indicator categories need to be considered
within the cloud environment
What is the importance of the
process within the value chain
What is the value towards the
corporate result
Estimate what frauds can
occur due to the use of the
process (independent of the
environment)
Result
relevance
Cost
relevance
Security
relevance
Check how cost intensive the
current process is and what
implications are possible due
to the cloudification
© 2013 SAP AG. All rights reserved. 6Customer
Example: Order-to-Cash Process
End-to-End
Processes
Sub
Processes
Main
Processes
Order to Cash
Customer Order Delivery Debt
Order
Mgmnt
Execution
Delivery
Planning &
Mgmnt
Transpor-
Tation
Planning &
execution
Outbound
Logistics
Returns &
Refusals
Mgmnt
Credit
Mgmnt
Stock
Mgmnt
Accounts
Receivable
Factoring
© 2013 SAP AG. All rights reserved. 7Customer
Processed information within the O2C process
Analyzed process modules, interfaces and process status
Process Modules, Transactions and Information
Critical Module Relevant Transactions (SAP) Critical Information
OTC01
Sales Order Creation
Create Sales Order VA01
Change Sales Order VA02
Display Sales Order VA03
List of Sales Orders VA05
sales order data, sales conditions
OTC02 Availability Check Create Sales Order VA01
Change Sales Order VA02
materials master data, sales order
data
OTC03
Order Confirmation
Change Sales Order VA02
Display Sales Order VA03
sales order data
OTC04
Delivery Creation Inbound/
Outbund
Create Outb. Dlv. w/ Order Ref. VL01n
Change Outbound Delivery VL02n
Display Outbound Delivery VL03n
Edit User-specific Delivery List VL10
Change Sales Order VA02
customer master data
sales order data
OTC14
Invoice Creation
Create Billing Document VF01
Change Billing Document VF02
Display Billing Document VF03
Maintain Billing Due List VF04
Cancel Billing Document VF11
Change Sales Order VA02
customer master data, sales order
data, invoice data
© 2013 SAP AG. All rights reserved. 8Customer
Cloud Threats towards information
Process Module Potential Threat
OTC01
Sales Order Creation
Wrong prices to the customer lead to a wrong legal binding
order; Order handling due to incomplete/wrong order data (by
interfaces)
OTC02
Availability Check
OTC03
Order Confirmation
Process customer order via cloud services (transparency of
customer data to 3rd party)
OTC04
Delivery Creation Inbound/
Outbound
Delivery data transparent in the cloud
OTC14
Invoice Creation
Invoicing with the use of cloud services with bank data by the
customer in the cloud; Dunning accounts handled via cloud
services with customer internal data; Payment / Financial
information by customer transparent in the cloud
© 2013 SAP AG. All rights reserved. 9Customer
Future work
• To monitor which kind of information is requested for processing with an
interface, a GRC monitoring receipt is suggested to further analyze the GRC
status achieved.
• Having process modules, interfaces and the used technology (cloud / non-cloud)
and GRC monitoring attributes addressed, the problem remains, how those
criteria can be effectively monitored throughout a EtE as the OtC, while providing
dedicated attention to risks and compliance issues involved by processing
information by both people and technology.
• This is subject to future work.
© 2013 SAP AG. All rights reserved. 10Customer
© 2013 SAP AG. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG.
The information contained herein may be changed without prior notice.
Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors.
National product specifications may vary.
These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or
warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group
products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing
herein should be construed as constituting an additional warranty.
SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in
Germany and other countries.
Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices.
© 2013 SAP AG. All rights reserved. 11Customer
© 2013 SAP AG. Alle Rechte vorbehalten.
Weitergabe und Vervielfältigung dieser Publikation oder von Teilen daraus sind, zu welchem Zweck und in welcher Form auch immer, ohne die
ausdrückliche schriftliche Genehmigung durch SAP AG nicht gestattet. In dieser Publikation enthaltene Informationen können ohne vorherige
Ankündigung geändert werden.
Einige der von der SAP AG und ihren Distributoren vermarkteten Softwareprodukte enthalten proprietäre Softwarekomponenten anderer
Softwareanbieter.
Produkte können länderspezifische Unterschiede aufweisen.
Die vorliegenden Unterlagen werden von der SAP AG und ihren Konzernunternehmen („SAP-Konzern“) bereitgestellt und dienen ausschließlich zu
Informationszwecken. Der SAP-Konzern übernimmt keinerlei Haftung oder Gewährleistung für Fehler oder Unvollständigkeiten in dieser Publikation.
Der SAP-Konzern steht lediglich für Produkte und Dienstleistungen nach der Maßgabe ein, die in der Vereinbarung über die jeweiligen Produkte und
Dienstleistungen ausdrücklich geregelt ist. Keine der hierin enthaltenen Informationen ist als zusätzliche Garantie zu interpretieren.
SAP und andere in diesem Dokument erwähnte Produkte und Dienstleistungen von SAP sowie die dazugehörigen Logos sind Marken oder
eingetragene Marken der SAP AG in Deutschland und verschiedenen anderen Ländern weltweit. Weitere Hinweise und Informationen zum
Markenrecht finden Sie unter http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark.

Contenu connexe

En vedette

Startups: Streit, Scaleup - introduction and product demo
Startups: Streit, Scaleup - introduction and product demoStartups: Streit, Scaleup - introduction and product demo
Startups: Streit, Scaleup - introduction and product demoCloudOps Summit
 
Lightning Talk: Ploegert, Sharewise - Crowd mit Cloud
Lightning Talk: Ploegert, Sharewise - Crowd mit CloudLightning Talk: Ploegert, Sharewise - Crowd mit Cloud
Lightning Talk: Ploegert, Sharewise - Crowd mit CloudCloudOps Summit
 
Q magazine covers
Q magazine coversQ magazine covers
Q magazine coverssarahlambe
 
Marcommagazine Maart 2011
Marcommagazine Maart 2011Marcommagazine Maart 2011
Marcommagazine Maart 2011gijs28
 
Role of the Police
Role of the PoliceRole of the Police
Role of the Policesarahmbeck
 
Bos pengalihan ke transfer (2)
Bos   pengalihan ke transfer (2)Bos   pengalihan ke transfer (2)
Bos pengalihan ke transfer (2)Pramudjo211052
 
Lexis Nexis Company Dossier
Lexis Nexis Company DossierLexis Nexis Company Dossier
Lexis Nexis Company Dossierstaffordlibrary
 
images for cover and dps
images for cover and dpsimages for cover and dps
images for cover and dpssarahlambe
 
Азбука схемы принятия решения - как продавать большим компаниям
Азбука схемы принятия решения - как продавать большим компаниямАзбука схемы принятия решения - как продавать большим компаниям
Азбука схемы принятия решения - как продавать большим компаниямGreenbusiness Consulting
 
My memorable meal
My memorable mealMy memorable meal
My memorable mealluis_90
 
What its ‘real’ about my video
What its ‘real’ about my videoWhat its ‘real’ about my video
What its ‘real’ about my videosarahlambe
 
WS: Kohler, Logica - Running operations devops style
WS: Kohler, Logica - Running operations devops styleWS: Kohler, Logica - Running operations devops style
WS: Kohler, Logica - Running operations devops styleCloudOps Summit
 
Semnarea digitala a unui e mail
Semnarea digitala a unui e mailSemnarea digitala a unui e mail
Semnarea digitala a unui e mailcraciunmalina
 
P&G Team Project
P&G Team ProjectP&G Team Project
P&G Team Projecttamimae72
 

En vedette (18)

Startups: Streit, Scaleup - introduction and product demo
Startups: Streit, Scaleup - introduction and product demoStartups: Streit, Scaleup - introduction and product demo
Startups: Streit, Scaleup - introduction and product demo
 
Lightning Talk: Ploegert, Sharewise - Crowd mit Cloud
Lightning Talk: Ploegert, Sharewise - Crowd mit CloudLightning Talk: Ploegert, Sharewise - Crowd mit Cloud
Lightning Talk: Ploegert, Sharewise - Crowd mit Cloud
 
Q magazine covers
Q magazine coversQ magazine covers
Q magazine covers
 
Marcommagazine Maart 2011
Marcommagazine Maart 2011Marcommagazine Maart 2011
Marcommagazine Maart 2011
 
Role of the Police
Role of the PoliceRole of the Police
Role of the Police
 
Bos pengalihan ke transfer (2)
Bos   pengalihan ke transfer (2)Bos   pengalihan ke transfer (2)
Bos pengalihan ke transfer (2)
 
Lexis Nexis Company Dossier
Lexis Nexis Company DossierLexis Nexis Company Dossier
Lexis Nexis Company Dossier
 
images for cover and dps
images for cover and dpsimages for cover and dps
images for cover and dps
 
The Nerd Off
The Nerd OffThe Nerd Off
The Nerd Off
 
Азбука схемы принятия решения - как продавать большим компаниям
Азбука схемы принятия решения - как продавать большим компаниямАзбука схемы принятия решения - как продавать большим компаниям
Азбука схемы принятия решения - как продавать большим компаниям
 
My memorable meal
My memorable mealMy memorable meal
My memorable meal
 
What its ‘real’ about my video
What its ‘real’ about my videoWhat its ‘real’ about my video
What its ‘real’ about my video
 
Gamification101
Gamification101Gamification101
Gamification101
 
WS: Kohler, Logica - Running operations devops style
WS: Kohler, Logica - Running operations devops styleWS: Kohler, Logica - Running operations devops style
WS: Kohler, Logica - Running operations devops style
 
Full e board
Full e boardFull e board
Full e board
 
Semnarea digitala a unui e mail
Semnarea digitala a unui e mailSemnarea digitala a unui e mail
Semnarea digitala a unui e mail
 
Mi portafolio electronico
Mi portafolio electronicoMi portafolio electronico
Mi portafolio electronico
 
P&G Team Project
P&G Team ProjectP&G Team Project
P&G Team Project
 

Plus de CloudOps Summit

Enable2Cloud: Risk Management by Cloud Escrow
Enable2Cloud: Risk Management by Cloud EscrowEnable2Cloud: Risk Management by Cloud Escrow
Enable2Cloud: Risk Management by Cloud EscrowCloudOps Summit
 
Augmenting People – Steuern wir noch oder werden wir gesteuert?
Augmenting People –  Steuern wir noch oder werden wir gesteuert?Augmenting People –  Steuern wir noch oder werden wir gesteuert?
Augmenting People – Steuern wir noch oder werden wir gesteuert?CloudOps Summit
 
Enterprise IT - between ugly and sexy
Enterprise IT - between ugly and sexyEnterprise IT - between ugly and sexy
Enterprise IT - between ugly and sexyCloudOps Summit
 
Time is the currency of IT
Time is the currency of ITTime is the currency of IT
Time is the currency of ITCloudOps Summit
 
Agile Stabilität - Wenn Operations agil wird
Agile Stabilität - Wenn Operations agil wirdAgile Stabilität - Wenn Operations agil wird
Agile Stabilität - Wenn Operations agil wirdCloudOps Summit
 
Devops in the real world
Devops in the real worldDevops in the real world
Devops in the real worldCloudOps Summit
 
Convergence – Social Enterprise
Convergence – Social EnterpriseConvergence – Social Enterprise
Convergence – Social EnterpriseCloudOps Summit
 
Lokale Clouds für mehr Kontrolle der Unternehmensdaten
Lokale Clouds für mehr Kontrolle der UnternehmensdatenLokale Clouds für mehr Kontrolle der Unternehmensdaten
Lokale Clouds für mehr Kontrolle der UnternehmensdatenCloudOps Summit
 
True Storage Virtualization with Software-Defined Storage
True Storage Virtualization with Software-Defined StorageTrue Storage Virtualization with Software-Defined Storage
True Storage Virtualization with Software-Defined StorageCloudOps Summit
 
Cloud Computing is not simple
Cloud Computing is not simpleCloud Computing is not simple
Cloud Computing is not simpleCloudOps Summit
 
How to Create Value Through Mergers & Acquisitions
How to Create Value Through Mergers & AcquisitionsHow to Create Value Through Mergers & Acquisitions
How to Create Value Through Mergers & AcquisitionsCloudOps Summit
 
You should not own a data center
You should not own a data centerYou should not own a data center
You should not own a data centerCloudOps Summit
 
Cloud-Dienste aus DE & EU als AWS Konkurrenz
Cloud-Dienste aus DE & EU als AWS KonkurrenzCloud-Dienste aus DE & EU als AWS Konkurrenz
Cloud-Dienste aus DE & EU als AWS KonkurrenzCloudOps Summit
 
EMC's IT's Cloud Transformation, Thomas Becker, EMC
EMC's IT's Cloud Transformation, Thomas Becker, EMCEMC's IT's Cloud Transformation, Thomas Becker, EMC
EMC's IT's Cloud Transformation, Thomas Becker, EMCCloudOps Summit
 
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...CloudOps Summit
 
Liquid Work, Luca Hammer, work.io
Liquid Work, Luca Hammer, work.ioLiquid Work, Luca Hammer, work.io
Liquid Work, Luca Hammer, work.ioCloudOps Summit
 

Plus de CloudOps Summit (20)

Enable2Cloud: Risk Management by Cloud Escrow
Enable2Cloud: Risk Management by Cloud EscrowEnable2Cloud: Risk Management by Cloud Escrow
Enable2Cloud: Risk Management by Cloud Escrow
 
Augmenting People – Steuern wir noch oder werden wir gesteuert?
Augmenting People –  Steuern wir noch oder werden wir gesteuert?Augmenting People –  Steuern wir noch oder werden wir gesteuert?
Augmenting People – Steuern wir noch oder werden wir gesteuert?
 
Programming humans
Programming humansProgramming humans
Programming humans
 
Enterprise IT - between ugly and sexy
Enterprise IT - between ugly and sexyEnterprise IT - between ugly and sexy
Enterprise IT - between ugly and sexy
 
Time is the currency of IT
Time is the currency of ITTime is the currency of IT
Time is the currency of IT
 
Komplex – Perplex?
Komplex – Perplex?Komplex – Perplex?
Komplex – Perplex?
 
Agile Stabilität - Wenn Operations agil wird
Agile Stabilität - Wenn Operations agil wirdAgile Stabilität - Wenn Operations agil wird
Agile Stabilität - Wenn Operations agil wird
 
Agile Virtualisierung
Agile VirtualisierungAgile Virtualisierung
Agile Virtualisierung
 
Devops in the real world
Devops in the real worldDevops in the real world
Devops in the real world
 
Convergence – Social Enterprise
Convergence – Social EnterpriseConvergence – Social Enterprise
Convergence – Social Enterprise
 
Banking Reloaded
Banking ReloadedBanking Reloaded
Banking Reloaded
 
Lokale Clouds für mehr Kontrolle der Unternehmensdaten
Lokale Clouds für mehr Kontrolle der UnternehmensdatenLokale Clouds für mehr Kontrolle der Unternehmensdaten
Lokale Clouds für mehr Kontrolle der Unternehmensdaten
 
True Storage Virtualization with Software-Defined Storage
True Storage Virtualization with Software-Defined StorageTrue Storage Virtualization with Software-Defined Storage
True Storage Virtualization with Software-Defined Storage
 
Cloud Computing is not simple
Cloud Computing is not simpleCloud Computing is not simple
Cloud Computing is not simple
 
How to Create Value Through Mergers & Acquisitions
How to Create Value Through Mergers & AcquisitionsHow to Create Value Through Mergers & Acquisitions
How to Create Value Through Mergers & Acquisitions
 
You should not own a data center
You should not own a data centerYou should not own a data center
You should not own a data center
 
Cloud-Dienste aus DE & EU als AWS Konkurrenz
Cloud-Dienste aus DE & EU als AWS KonkurrenzCloud-Dienste aus DE & EU als AWS Konkurrenz
Cloud-Dienste aus DE & EU als AWS Konkurrenz
 
EMC's IT's Cloud Transformation, Thomas Becker, EMC
EMC's IT's Cloud Transformation, Thomas Becker, EMCEMC's IT's Cloud Transformation, Thomas Becker, EMC
EMC's IT's Cloud Transformation, Thomas Becker, EMC
 
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...
Strategic Importance of Semantic Technologies as a Key Differentiator for IT ...
 
Liquid Work, Luca Hammer, work.io
Liquid Work, Luca Hammer, work.ioLiquid Work, Luca Hammer, work.io
Liquid Work, Luca Hammer, work.io
 

Dernier

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Principled Technologies
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 

Dernier (20)

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 

Processes do not have to kill you

  • 1. Processes do not have to kill you GUIDED END-TO-END PROCESSES IN THE LIGHT OF THE USE OF CLOUD SERVICES Ute Riemann SAP Deutschland AG & Co. KG
  • 2. © 2013 SAP AG. All rights reserved. 2Customer Why security is so difficult - and why value is lost • The value of Cloud Services is generated „between“ the business and technology • But: outtasking services also means: loosing control over the data (= missing security) • Today‘s approach: identify technology risks and – as a consequence – do not use Cloud services if too risky  Too inflexible, too much value is lost  Our approach: look at the value chain first! Security People BusinessTechnology Value of Cloud Services
  • 3. © 2013 SAP AG. All rights reserved. 3Customer The 5 steps from identification of cloud value add and the business process inherent compliance risks of a company Identify the company- specific value chain Identify the key processes within the value chain Select the appropriate fraud indicators Perform IT identification Link the processes with the cloud specifics within the E2E process model 1 2 3 4 5
  • 4. © 2013 SAP AG. All rights reserved. 4Customer A comprehensive analysis of the compliance requirements within the process environment To answer this question it is required to understand the various dimensions that needs to be considered Dimension 1: Business perspective Dimension 2: Service perspective Dimension 3: Compliance perspective Service perspective Business perspective Compliance perspective
  • 5. © 2013 SAP AG. All rights reserved. 5Customer The following indicator categories need to be considered within the cloud environment What is the importance of the process within the value chain What is the value towards the corporate result Estimate what frauds can occur due to the use of the process (independent of the environment) Result relevance Cost relevance Security relevance Check how cost intensive the current process is and what implications are possible due to the cloudification
  • 6. © 2013 SAP AG. All rights reserved. 6Customer Example: Order-to-Cash Process End-to-End Processes Sub Processes Main Processes Order to Cash Customer Order Delivery Debt Order Mgmnt Execution Delivery Planning & Mgmnt Transpor- Tation Planning & execution Outbound Logistics Returns & Refusals Mgmnt Credit Mgmnt Stock Mgmnt Accounts Receivable Factoring
  • 7. © 2013 SAP AG. All rights reserved. 7Customer Processed information within the O2C process Analyzed process modules, interfaces and process status Process Modules, Transactions and Information Critical Module Relevant Transactions (SAP) Critical Information OTC01 Sales Order Creation Create Sales Order VA01 Change Sales Order VA02 Display Sales Order VA03 List of Sales Orders VA05 sales order data, sales conditions OTC02 Availability Check Create Sales Order VA01 Change Sales Order VA02 materials master data, sales order data OTC03 Order Confirmation Change Sales Order VA02 Display Sales Order VA03 sales order data OTC04 Delivery Creation Inbound/ Outbund Create Outb. Dlv. w/ Order Ref. VL01n Change Outbound Delivery VL02n Display Outbound Delivery VL03n Edit User-specific Delivery List VL10 Change Sales Order VA02 customer master data sales order data OTC14 Invoice Creation Create Billing Document VF01 Change Billing Document VF02 Display Billing Document VF03 Maintain Billing Due List VF04 Cancel Billing Document VF11 Change Sales Order VA02 customer master data, sales order data, invoice data
  • 8. © 2013 SAP AG. All rights reserved. 8Customer Cloud Threats towards information Process Module Potential Threat OTC01 Sales Order Creation Wrong prices to the customer lead to a wrong legal binding order; Order handling due to incomplete/wrong order data (by interfaces) OTC02 Availability Check OTC03 Order Confirmation Process customer order via cloud services (transparency of customer data to 3rd party) OTC04 Delivery Creation Inbound/ Outbound Delivery data transparent in the cloud OTC14 Invoice Creation Invoicing with the use of cloud services with bank data by the customer in the cloud; Dunning accounts handled via cloud services with customer internal data; Payment / Financial information by customer transparent in the cloud
  • 9. © 2013 SAP AG. All rights reserved. 9Customer Future work • To monitor which kind of information is requested for processing with an interface, a GRC monitoring receipt is suggested to further analyze the GRC status achieved. • Having process modules, interfaces and the used technology (cloud / non-cloud) and GRC monitoring attributes addressed, the problem remains, how those criteria can be effectively monitored throughout a EtE as the OtC, while providing dedicated attention to risks and compliance issues involved by processing information by both people and technology. • This is subject to future work.
  • 10. © 2013 SAP AG. All rights reserved. 10Customer © 2013 SAP AG. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices.
  • 11. © 2013 SAP AG. All rights reserved. 11Customer © 2013 SAP AG. Alle Rechte vorbehalten. Weitergabe und Vervielfältigung dieser Publikation oder von Teilen daraus sind, zu welchem Zweck und in welcher Form auch immer, ohne die ausdrückliche schriftliche Genehmigung durch SAP AG nicht gestattet. In dieser Publikation enthaltene Informationen können ohne vorherige Ankündigung geändert werden. Einige der von der SAP AG und ihren Distributoren vermarkteten Softwareprodukte enthalten proprietäre Softwarekomponenten anderer Softwareanbieter. Produkte können länderspezifische Unterschiede aufweisen. Die vorliegenden Unterlagen werden von der SAP AG und ihren Konzernunternehmen („SAP-Konzern“) bereitgestellt und dienen ausschließlich zu Informationszwecken. Der SAP-Konzern übernimmt keinerlei Haftung oder Gewährleistung für Fehler oder Unvollständigkeiten in dieser Publikation. Der SAP-Konzern steht lediglich für Produkte und Dienstleistungen nach der Maßgabe ein, die in der Vereinbarung über die jeweiligen Produkte und Dienstleistungen ausdrücklich geregelt ist. Keine der hierin enthaltenen Informationen ist als zusätzliche Garantie zu interpretieren. SAP und andere in diesem Dokument erwähnte Produkte und Dienstleistungen von SAP sowie die dazugehörigen Logos sind Marken oder eingetragene Marken der SAP AG in Deutschland und verschiedenen anderen Ländern weltweit. Weitere Hinweise und Informationen zum Markenrecht finden Sie unter http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark.