GRC Analytics powered by SAP HANA – exciting news in the world of SAP GRC
If you attended the SAPPHIRE and ASUG conferences in Orlando last week, or if you read my blog posts about my experiences at the conferences, you may already be aware of some exciting news in the world of SAP GRC 10.0 . For those who missed the conferences and my previous posts, get ready as there is some very exciting new functionality coming, called GRC Analytics. I was fortunate to be able to spend some time in an exclusive interview with Chris Radkowksi of SAP Labs and Jochen Thierer of SAP AG, and they walked me through a demo of the prototype of this coming solution.
The gist of GRC Analytics is that it will offer analytics on GRC content, powered by SAP HANA, including reporting using data from the Access Control, Process Control, and Risk Management components. Keep in mind, this is not just the same old, same old but faster; we are talking here about new reporting capable of providing levels of business intelligence about security and compliance not previously possible.
So what kind of use cases are anticipated? For example, Identity Analytics could help you get started on a role rationalization initiative via reports such as Unused Roles, Orphan Roles, and Frequently Used Roles.
Applying the power and speed of SAP HANA to risk management will mean that simulations can be done with many times more repetitions than are possible today since today, it would just time out. Monitoring within Process Controls, such as monitoring of suspicious accounts or unusual postings on holidays or weekends, would be possible with millions of records analyzed. One of the best parts of this news is that customers do not have to change anything about their GRC 10.0 system to deploy this new functionality.As Chris and Jochen explained to me, the GRC data is replicated onto the HANA box via real time Sybase replication.
As exciting as this news is, readers are reminded that this solution is still under development. The planned shipment date is targeted for Q4 2012; however, keep in mind that dates are subject to change, and as always, SAP reminds customers to not make a purchase decision based on that target.
As the targeted shipment date draws closer, customers who are interested in this solution should watch for an announcement of a Customer Advisory Call. Stay tuned in the coming months for more news about this exciting solution. Thanks for Chris and Jochen for taking time during the busy week in Orlando to share this news with us.
They shared the same with me when I was in GRC 2012 conferences in Las Vegas in March and I also shared some ideas about this topic and others but it's now becoming difficult to get any news from the GRC side about new functionalities that will be delivered based on the SAP Ideas place as well as related to their development progress.
Even being part of the CAC doesn't help more.
Hope they will improve the communication.
But, that's right, the GRC analytics capabilities they will deliver should bring a lot of value based on the exchanges we had.
Thanks for your feedback on this.
I have not heard any further on this coming functionality either. Additionally, much to my great disappointment, I do not find anything on GRC Analytics in the TechEd education session abstracts, a member of SAP security solution management having informed me at SAPPHIRE that GRC is "not a technology,"(!) so I am not particularly hopeful of learning anything there either. However, since the targeted delivery was Q4, perhaps we will hear something yet this year. Certainly, if I luck out and do get an update at TechEd, I will be blogging about it.