Authorizations For SWO1 - Delegation Execution

Martinek, Jerry Jerry.Martinek at icbc.com
Thu Sep 15 12:51:51 EDT 2005


Hi,

 

I'm interested in finding out how other SAP clients are dealing with
this scenario/issue. 

 

Our security group removed the authorization object S_TABU_CLI from all
of our roles in all of our SAP systems (development and production) due
to a perceived security risk. The external auditor who reviewed the SAP
authorizations mentioned that this authorization object poses a risk so
our security group removed it from all SAP environments.

 

This decision basically removes our ability to execute SAP functionality
that updates cross client tables.

 

The immediate impact to me is that I can't execute the 'DELEGATION'
function in SWO1 because you need to have the S_TABI_CLI authorization
object in your role. Now I need to request a temporary authorization
change in order to complete the delegation function. 

 

Is this the norm or was it just a bad auditor?

 

Thanks,

Jerry Martinek  

 

   

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.mit.edu/pipermail/sap-wug/attachments/20050915/84901e7e/attachment.htm


More information about the SAP-WUG mailing list