Installation Guide Sap Businessobjects Access Control™ 10.0, Process Control™ 10.0, and Risk Management™ 10.0
Installation Guide Sap Businessobjects Access Control™ 10.0, Process Control™ 10.0, and Risk Management™ 10.0
Target Audience
ÇA14óF System Administrators
ÇA14óF Technical Consultants
PUBLIC
ÇA1ÐÖ›ÖB−Páfi#ÌY‚ÌE§÷vÀËÑSl^˝ú9mó¡ô`�tˆ˙”ÛtJ˝ò!ÞMóœ¢Ê‹È¢…q¢uDú] :h-&}ö
SAP AG
Dietmar-Hopp-Allee 16
69190 Walldorf
Germany
T +49/18 05/34 34 34
F +49/18 05/34 34 20
www.sap.com
Disclaimer
Example Description
<Example> Angle brackets indicate that you replace these words or characters with appropriate
entries to make entries in the system, for example, “Enter your <User Name>”.
Example Arrows separating the parts of a navigation path, for example, menu options
Example
Example Emphasized words or expressions
Example Words or characters that you enter in the system exactly as they appear in the
documentation
http://www.sap.com Textual cross-references to an internet address
/example Quicklinks added to the internet address of a homepage to enable quick access to specific
content on the Web
123456 Hyperlink to an SAP Note, for example, SAP Note 123456
Example A¨A¿°ÿ Words or characters quoted from the screen. These include field labels, screen titles,
pushbutton labels, menu names, and menu options.
A¨A¿°ÿ Cross-references to other documentation or published works
Example A¨A¿°ÿ Output on the screen following a user action, for example, messages
A¨A¿°ÿ Source code or syntax quoted directly from a program
A¨A¿°ÿ File and directory names and their paths, names of variables and parameters, and
names of installation, upgrade, and database tools
EXAMPLE Technical names of system objects. These include report names, program names,
transaction codes, database table names, and key concepts of a programming language
when they are surrounded by body text, for example, SELECT and INCLUDE
EXAMPLE Keys on the keyboard
CAUTION
Before you start the implementation, make sure you have the latest version of this document.
You can find the latest version at the following location: https://service.sap.com/
instguides.
The following table provides an overview of the most important document changes.
Version Date Description
1.00 2010-12-13 New content SAP BusinessObjects AC 10.0, PC 10.0, RM 10.0 (initial release).
1.10 2011-01-31 Adds SAP BusinessObjects Access Control 10.0 only scenario.
1.20 2011-03-28 Updates to general prerequisites and AC 10.0 and PC 10.0 plug-in prerequisites.
1.30 2011-04-18 Adds a statement to clarify that Content Lifecycle Management (CLM) is currently
only available for SAP BusinessObjects Process Control 10.0 and SAP BusinessObjects
Risk Management 10.0.
Chapter 1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
1.1 About this Document . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
1.2 SAP Notes for the Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
1.3 Information Available on SAP Service Marketplace . . . . . . . . . . . . . . . . . . . . . 10
1.4 Important Upgrade Information for Risk Management . . . . . . . . . . . . . . . . . . 11
Chapter 2 Planning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Chapter 7 Post–Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
7.1 Client Copy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
7.2 Activating the Applications in Clients . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
7.3 Checking SAP ICF Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
7.4 Maintaining System Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
7.5 Maintaining Plug-in Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
1 Introduction
SAP BusinessObjects Access Control 10.0, Process Control 10.0, and Risk Management 10.0 are part of
the SAP Governance, Risk, and Compliance (GRC) solution.
For more information about GRC, go to http://www.sap.com/grc.
SAP BusinessObjects Access Control is an enterprise software application which enables organizations
to control access and prevent fraud across the enterprise, while minimizing the time and cost of
compliance. The application streamlines compliance processes, including access risk analysis and
remediation, business role management, access request management, superuser maintenance, and
periodic compliance certifications. Access Control delivers immediate visibility of the current risk
situation with real-time data.
SAP BusinessObjects Process Control is an enterprise software solution for internal controls
management. It enables organizations to document their control environment, test and assess controls,
track issues to remediation, and certify and report on the state and quality of internal controls. Using
a combination of data forms, automated workflows, certification, and interactive reports, this solution
enables members of internal control, audit, and business process teams to effectively manage
compliance activities.
SAP BusinessObjects Risk Management is an enterprise software solution that enables organizations to
balance business opportunities with financial, legal, and operational risks to minimize the market
penalties from high-impact events. The application allows customers to collaboratively identify these
risks and monitor them on a continuous basis. Stakeholders and owners are provided with such tools
as analytic dashboards for greater visibility in mitigating risks in their areas of responsibility.
SAP Note
Number Title Description
1500691 Upgrade to SAP ECC 600 Supplemental information relevant for the upgrade to SAP ECC 600
with GRCPIERP
V1000_700
1500692 Upgrade to SAP ECC 600 Supplemental information relevant for the upgrade to SAP ECC 600
with GRCPIERP
V1000_700
1501879 Upgrade to SAP ECC 500 Supplemental information relevant for the upgrade to SAP ECC 500
with GRCPIERP
V1000_640
1501880 Installing GRCPIERP Supplemental information for installing SAP BusinessObjects Process
V1000_640 on NW04/ Control 10.0 and Access Control 10.0 plug-ins on SAP ERP 2004 (ECC 5.0)
SAP ECC 500
1501881 Upgrade to SAP ECC 500 Supplemental information relevant for the upgrade to SAP ECC 500
with GRCPIERP
V1000_640
1501882 Installing GRCPINW Supplemental information for installing SAP BusinessObjects Access
V1000_640 on NW04/ Control 10.0 Non-HR plug-ins on SAP ERP 2004 (ECC 5.0)
SAP ECC 500
1503749 Installing GRCPINW Supplemental information for installing SAP BusinessObjects Access
V1000_710 on NW 7.10 Control 10.0 Non-HR plug-ins on NW710
1503750 Upgrade to SAP ECC 600 Supplemental information relevant for the upgrade to SAP ECC 600
with GRCPIERP
V1000_700
1504132 Release Strategy for
ABAP add-on
GRCPCINW
1504243 Release Strategy for
ABAP add-on
GRCPIERP
1509636 Additional information
for GRC2010 installation
1510002 Installing SAP GRC Information about installing the GRC_POR 1000 software component.
Portal 10.0
1514346 BRF+ Various Bug Fixes
in EHP2 (SP04–SP06)
The following table outlines the additional SAP Notes that you need to read before installing the
software in an AC/PC/RM 10.0 environment:
SAP Note Number Title Description
1470670 User-defined Fields for RM
1505255 Transfer client-specific
Customizing for PC/RM
Security https://service.sap.com/security
Procedure
Upgrading from SAP Risk Management 3.0 to SAP BusinessObjects Risk Management 10.0 is a same-
box upgrade process. The following steps are typical for this kind of upgrade:
1. Close all open workflow instances and all open survey instances.
2. Perform a system backup.
3. If it is used, delete all Datamart data.
4. Upgrade from SAP NetWeaver 7.01 to NW 7.02.
5. Upgrade from SAP Portal 7.01 to SAP Portal 7.02 (if you use portal, alternatively you can use NWBC
3.0).
6. Install RM10.0 (GRCFND_A V1000).
7. Perform system backup.
8. Survey instances and Heat map color ranges are automatically converted by XPRA; verify the data
conversion.
9. Upload the new BC sets for new features and new roles (optional for Risk Management 10.0 new
features).
10. Perform configuration for optional RM 10.0 new features.
11. If it is used, refill Datamart.
2 Planning
Before you start the installation, you should plan the following preliminary steps:
Procedure
1. Determine the software components and supporting systems needed to run Access Control 10.0
or AC/PC/RM 10.0 by consulting the corresponding master guides on SAP Service Marketplace at:
https://service.sap.com/instguides.
For Access Control 10.0, consult the SAP BusinessObjects Access Control 10.0 Master Guide. For AC/PC/
RM 10.0, consult the SAP BusinessObjects Access Control 10.0 Master Guide, SAP BusinessObjects Process Control
10.0 Master Guide, and SAP BusinessObjects Risk Management Master Guide 10.0
2. Decide what you want to install.
When installing AC/PC/RM 10.0, the following components are available:
Mandatory
ù‰ý¬�ý NetWeaver ABAP
Optional (recommended)
ù‰ý¬�ý NetWeaver Java, if you need to use Adobe Document Services
ù‰ý¬�ý Portal
ù‰ý¬�ý TREX, if you want to use document search (Process Control and Risk Management only).
ù‰ý¬�ý Plug-ins on your ERP system (Access Control and Process Control only).
3. Download and check the relevant SAP Notes. For more information, see section 1.3 above.
CAUTION
Make sure that you review the information in SAP Note 1509636 before you start any
installation procedures.
4. Take all applicable security measures. For more information, see the SAP BusinessObjects AC/PC/RM
10.0 Security Guide on SAP Service Marketplace at https://service.sap.com/securityguide.
AC/PC/RM 10.0 should not be installed with SAP Business Suite or with any SAP Business Suite
components such as ERP, SCM, CRM, and SRM.
Prerequisites
You use SAP Solution Manager to download the AC/PC/RM 10.0 applications and patches. SAP Solution
Manager must be available in the system landscape; however, it does not need to be on the same system
as the AC/PC/RM 10.0 applications.
For more information about SAP Solution Manager, see https://service.sap.com/
solutionmanager.
In an Access Control 10.0 only environment, the following components of SAP NetWeaver 7.0 EHP2
SP06 are required:
Component Details
SPAM (Support Not applicable
Package Manager)
40 or higher
SAP NetWeaver ¡ˆqœ…˝ SAP_ABA 7.02 (SP06)
Application ¡ˆqœ…˝ SAP_BASIS 7.02 (SP06)
Server ABAP ¡ˆqœ…˝ PI_BASIS 7.02 (SP06)
Components ¡ˆqœ…˝ SAP_BW 7.02 (SP06)
(Optional) SAP Portal 7.02
NetWeaver
Application
Server Java
Components
SAP Solution Not applicable
Manager 7.00 SP19
or higher
(Optional) SAP SAP NetWeaver Java is required to use Adobe Document Services. It must be available in the
NetWeaver system landscape, but does not need to be installed on the same system as the AC/PC/RM
Application 10.0 applications.
Server Java for You need to create and respectively activate the following JCo destinations:
Adobe Document ¡ˆqœ…˝ WD_ALV_METADATA_DEST
Services ¡ˆqœ…˝ WD_ALV_MODELDATA_DEST
It is essential to create Adobe Credentials; see SAP Note 736902, Adobe Credentials.
Component Details
For more details about troubleshooting, see SAP Note 944221, Troubleshooting if problems occur in
forms processing.
For more information, see https://www.sdn.sap.com/irj/sdn/adobe under Installation &
Configuration.
We recommend BI Java usage type must be installed on the same system as the Adobe Document Services.
that you install BI For more information, see SAP Note 918236, WD ABAP ALV - create print version.
Java usage type
(part of the SAP
NetWeaver Java
stack) to enable
printing of PDFs
from Process
Control reports
and Risk
Management
reports.
In an AC/PC/RM 10.0 environment, the following components of SAP NetWeaver 7.0 EHP2 SP06 are
required:
Component Details
SPAM (Support Not applicable
Package
Manager) 40 or
higher
SAP NetWeaver ¨wø<% SAP_ABA 7.02 (SP06)
Application ¨wø<% SAP_BASIS 7.02 (SP06)
Server ABAP ¨wø<% PI_BASIS 7.02 (SP06)
Components ¨wø<% SAP_BW 7.02 (SP06)
SAP NetWeaver ¨wø<% Adobe Document Services 7.01
Application ¨wø<% Portal 7.02
Server Java ¨wø<% SAP_IGS Version 7000.0.15.1 or higher
Components
Standalone TREX 7.10 (revision 27 or higher)
Engine
SAP Solution Not applicable
Manager 7.00
SP19 or higher
SAP NetWeaver SAP NetWeaver Java is required to use Adobe Document Services. It must be available in the
Application system landscape, but does not need to be installed on the same system as the AC/PC/RM
Server Java for 10.0 applications.
Adobe You need to create and respectively activate the following JCo destinations:
Document ¨wø<% WD_ALV_METADATA_DEST
Services ¨wø<% WD_ALV_MODELDATA_DEST
It is essential to create Adobe Credentials; see SAP Note 736902, Adobe Credentials.
For more details about troubleshooting, see SAP Note 944221, Troubleshooting if problems occur in
forms processing.
Component Details
For more information, see https://www.sdn.sap.com/irj/sdn/adobe under Installation &
Configuration.
We recommend BI Java usage type must be installed on the same system as the Adobe Document Services.
that you install BI For more information, see SAP Note 918236, WD ABAP ALV - create print version.
Java usage type
(part of the SAP
NetWeaver Java
stack) to enable
printing of PDFs
from Process
Control reports
and Risk
Management
reports.
NOTE
If you make use of Process Control 10.0 Policy Survey PDFs, be sure to upgrade to version 9.3.4 of
Adobe Reader.
Follow the steps in SAP Note 1490996 to download the files for Access Control, which use the
component GRCFND_A V1000.
Procedure
1. Go to the SAP Software Distribution Center on SAP Service Marketplace at http://
service.sap.com/swdc.
2. Choose Software Downloads Installation and Upgrades A - Z Index G SAP GRC Access Control SAP
GRC ACCESS CONTROL SAP Access Control 10.0 Installation .
3. Select the SAP Access Control/SAP Process Control/SAP Risk Mgmt 10.0 download object, and choose Add
to Download Basket.
NOTE
JSPM must be run as ‹sid›adm user. In versions prior to 5.3, SAP GRC Access Control used the Software
Deployment Manager (SDM) to install and uninstall the software components. As of version 5.3, SAP
GRC Access Control uses JSPM to install (“deploy” in JSPM terms), but still uses SDM to uninstall.
Prerequisites
You have downloaded the most recent SAP Access Control 10.0 Support Package and placed it in the
JSPM Inbox in the directory /usr/sap/trans/EPS/in/.
To download the SAP Access Control 10.0 Support Package, go to SAP Software Distribution Center
on SAP Service Marketplace at http://service.sap.com/swdc Software Downloads Installation and
Upgrades A - Z Index G SAP GRC Access Control SAP GRC ACCESS CONTROL SAP Access Control
10.0 Installation .
Procedure
Launch the JSPM, which is found in the directory /usr/sap/‹SID›/‹CD›/j2ee/JSPM/go.bat.
JSPM scans the directory that contains the installation files (/usr/sap/trans/EPS/in/).
Using the JSPM Installer, follow these steps:
1. Select Package Type and then New Software components. Use the radio button to specify the system
role and whether or not the system is under NWDI. Click Next.
2. Specify Queue. Select the software components that you want to install (for SAP Access Control,
select GRCACMIGxx_0.sca, where xx represents the Support Package number). Click Next
3. Check Queue to monitor the installation.
Result
The SAP GRC Access Control 10.0 Migration is installed on top of your SAP AC 5.3 system.
NOTE
The software component BP ERP05 COMMON PARTS version 1.51 is required to be deployed in
Enterprise Portal if you use the portal as front-end.
Procedure
For download information, see SAP Note 1490996.
NOTE
ç‘
k8â Plug-ins are not used in Risk Management. This section applies only to Access Control and
Process Control.
ç‘
k8â If you already have the Process Control 3.0 RTAs, follow the instructions in the SAP
BusinessObjects Process Control 10.0 Upgrade Guide, located on the SAP Service Marketplace at:
http://service.sap.com.
Prerequisites
Use the tables in this section to identify the appropriate SAP Note describing how to install the SAP
GRC 10.0 plug-in on the corresponding platform.
For GRCPINW (AC 10.0 and PC 10.0)
SAP Note Number Platform
1500168 SAP Basis 46C NW
1497971 SAP Basis 620 NW
1501882 SAP Basis 640 NW
1500689 SAP Basis 700 NW
1503749 SAP Basis 710 NW
Procedure
Prerequisites
NOTE
Access Control, Process Control, and Risk Management have specific system requirements, and
cannot run successfully unless these requirements are met. See the earlier sections for the system
prerequisites.
Procedure
The SAP BusinessObjects AC/PC/RM applications require the add-on component GRCFND_A. SAP Note
1490996 explains the procedure for installing this add-on component.
Prerequisites
AC/PC/RM 10.0 requires the add-on portal business package GRC_POR and the software component BP
ERP05 COMMON PARTS version 1.51.
You must upload the content objects to the portal so that you can use the business package after you
have downloaded it.
NOTE
For Access Control 10.0 only environments, installing the components in Enterprise Portal is
optional. You do, however, need to install the NetWeaver Portal Plug-in GRCPIEP in Access
Control 10.0 only environments to enable risk analysis and provisioning using the portal.
Procedure
1. To download the AC/PC/RM 10.0 portal business packages from the SAP Software Distribution
Center (SWDC), go to http://service.sap.com/swdc Software Downloads Support Packages and
Patches Browse our Download Catalog SAP Solutions for Governance, Risk, and Compliance .
2. Choose your application (SAP GRC Access Control, SAP Process Control, or SAP Risk
Management). For example, for Access Control choose SAP GRC Access Control SAP GRC
ACCESS CONTROL SAP ACCESS CONTROL 10.0 Entry by Component GRC Java Components SAP
GRC PORTAL 10.0 OS independent .
3. Choose the SAP GRC PORTAL 10.0 download object and choose Add to Download Basket.
1. To download NetWeaver Portal Plug-in GRCPIEP from the SAP Software Distribution Center
(SWDC), go to http://service.sap.com/swdc Software Downloads Support Packages and Patches
Browse our Download Catalog SAP Solutions for Governance, Risk, and Compliance .
2. Choose SAP GRC Access Control SAP GRC ACCESS CONTROL SAP ACCESS CONTROL 10.0
Entry by Component Portal Plug-in SAP GRC AC PORTAL PLUG–IN 10.0 OS independent .
3. Choose the SAP GRC AC PORTAL PLUG–IN 10.0 download object and choose Add to Download
Basket.
The Java Support Package Manager (JSPM) ensures that you download the latest version of the relevant
SAP software.
For information about using the JAVA Support Package Manager (JSPM) to deploy software packages
in NetWeaver 7.02, go to the SAP NetWeaver Library in SAP Help Portal at http://help.sap.com, click
on the Search Documentation link in the upper right-hand corner of the screen, and enter the search term
“JSPM”.
On the right-hand side of the hit list, you will see a list called Narrow by Info-Class. Click on the
Component info-class, and then in the resulting hit list, click on the entry for “Java Support Package
Manager” to go to the top-level entry for JSPM documentation.
Using SDM
If you must reinstall a prior version of SAP software because of a system crash, you will need to use the
Software Deployment Manager (SDM).
For information about the Software Deployment Manager (SDM) to deploy software packages in
NetWeaver 7.02, go to the SAP NetWeaver Library in SAP Help Portal at http://help.sap.com, click
on the Search Documentation link in the upper right-hand corner of the screen, and enter the search term
Core Development Tasks.
On the right-hand side of the hit list, you will see a list called Narrow by Info-Class. Click on the Component
info-class. In the resulting hit list, click on the first entry “Core Development Tasks,” and then follow
Deployment: Putting It All Together Software Deployment Manager SDM Remote GUI Client SDM Repository
Management .
You can install the standalone version of TREX if you want to use Enterprise Search for document
search in Process Control 10.0 and Risk Management 10.0.
NOTE
Procedure
You install TREX 7.10, revision 27 or higher. See the NetWeaver Enterprise Search Installation Guide
on the SAP Service Marketplace at https://service.sap.com/instguides SAP NetWeaver SAP
NetWeaver Enterprise Search Installation Guide for SP3
For more information, see the following SAP Notes:
SAP Note Number Title
1249465 How to install TREX for Embedded Search
1164532 Limitations
1266024 Sizing TREX for Embedded Search
1269011 Additional TREX instance for Embedded Search
7 Post–Installation
After downloading and installing the files described in the previous sections, to configure the product,
follow the post-installation sections in the order they are presented.
Procedure
Complete the following steps to activate:
1. Open the SAP Reference IMG in Tools Customizing IMG Project Administration (transaction
SPRO) .
2. Display the SAP Reference IMG.
3. Open SAP BusinessObjects Access Control, Process Control, or Risk Management.
4. Execute Activate Applications in Client.
To activate an application component:
1. Choose the New Entries pushbutton.
2. Select an application component from the dropdown list. Choose GRC-AC, GRC-PC or GRC-
RM (choose GRC-AC for Access Control 10.0 only environments).
3. In the Active column, you must specify if the application component is to be activated or not. If
you are using more than one component, you must set the indicator for each one.
NOTE
This Customizing activity is the same in all the Risk Management, Process Control, and Access
Control nodes. If you are using all three components, they can be activated from the
corresponding Customizing activity of any of the three applications.
NOTE
For more information about activating these services, see SAP Note 1088717, Active services for Web Dynpro
ABAP in transaction SICF.
Procedure
1. Activate each of the following ICF service nodes:
ÙÊ<±ƒ /sap/public/bc
ÙÊ<±ƒ /sap/public/bc/icons
ÙÊ<±ƒ /sap/public/bc/icons_rtl
ÙÊ<±ƒ /sap/public/bc/its
ÙÊ<±ƒ /sap/public/bc/pictograms
ÙÊ<±ƒ /sap/public/bc/ur
ÙÊ<±ƒ /sap/public/bc/webdynpro
ÙÊ<±ƒ /sap/public/bc/webdynpro/mimes
ÙÊ<±ƒ /sap/public/bc/webdynpro/adobeChallenge
ÙÊ<±ƒ /sap/public/bc/webdynpro/ssr
ÙÊ<±ƒ /sap/public/bc/webicons
ÙÊ<±ƒ /sap/public/myssocntl
NOTE
Procedure
1. Locate the System Data application in the Support Portal in SAP Service Marketplace under Data.
2. Use one of the search functions provided to select an installed SAP system.
3. On the System tab, scroll down to the Add-On Product Version section.
4. Insert a line.
5. Select the SAP BusinessObjects Access Control 10.0 support package, SAP BusinessObjects Process
Control 10.0 application support package, and/or the SAP BusinessObjects Risk Management
10.0 application support package from the list.
6. Save your changes.
7. Repeat this procedure for all SAP systems.
To use the Crystal Reports function in GRC10, activate the flag Allow Crystal Reports in Customizing
under SAP NetWeaver Application Server SAP List Viewer (ALV) Maintain Web Dynpro ABAP-Specific
Settings .
Procedure
1. Open the SAP Reference IMG in Tools Customizing IMG Project Administration (transaction
SPRO) .
2. Display the SAP Reference IMG.
3. Open Governance, Risk and Compliance (Plug-In) Access Control .
4. Execute Maintain Plug-in Exits Settings.
5. Execute Maintain Plug-in Configuration Settings.
NOTE
For Access Control 10.0 only environments, you only need to activate the Access Control BC Sets.
You can activate a particular BC set only if that client is not a production client in the system. When
you activate the BC set, all data in the BC set is transferred into the corresponding original tables. Any
entries already in the original tables are overwritten in this process.
See SAP Solution Manager for information about customizing activities at https://service.sap.com/
solutionmanager. For SAP BusinessObjects Access Control, Process Control and Risk Management
10.0, the appropriate SAP Solution Manager release for enhanced Solution Manager content is ST-ICO
150 SP27.
For more information about the SAP NetWeaver Application Server, see http://help.sap.com/nw70
SAP NetWeaver Library SAP NetWeaver by Key Capability Solution Life Cycle Management by Key Capability
Customizing Business Configuration Sets (BC-SETS)
Procedure
1. Choose Existing BC Sets from the toolbar in the Implementation Guide. This identifies all of the IMG
activities for which the BC set exists.
2. Select one of these IMG activities and choose the pushbutton BC Sets for Activity.
The contents of the BC set are displayed in a new window.
3. To activate this BC set, choose the pulldown menu Go to Activation Transaction .
4. Select the icon for Activate BC Set (or use F7).
The Activation Options screen opens.
5. Choose Continue.
A completion message appears: Activation successfully completed.
NOTE
The information that follows applies only when activating AC/PC/RM 10.0 Business
Configuration sets. The following does not apply when activating BC sets in Access Control
10.0 only environments.
Alternatively, if a yellow informational message appears, choose Enter and then the completion
message appears.
CAUTION
You can safely ignore Basis functionality error messages that state:
System table GRPCATTR* cannot be put in a BC Set.
A message colored with a yellow background is only a warning. A message colored red is an
error message.
When activating the BC set tables that begin with GRPC-ATTR-*, errors may be listed in the
progress column. There are five BC sets that need to be activated twice:
ð}Ƀ£_ GRPC-ATTR-CTRL_OBJ_CATEGORY
ð}Ƀ£_ GRPC-ATTR-CTRL_GROUP
ð}Ƀ£_ BC_SET_RISK_LEVEL_MATRIX
ð}Ƀ£_ GRFN-PNS-FDA
ð}Ƀ£_ GRFN-PNS-SOX
1. You can ignore the following error messages during first-time activation:
ð}Ƀ£_ GRPC-ATTR-CTRL_GROUP VC_GRPCATTR Table/View V_GRPCATTRVALUE2: higher-
level entry for & missing
NOTE
You can activate all of the BC sets by using transaction SCPR20, including those that can be activated
via Customizing (marked with an asterisk [*] in the table below).
BC Set Name
GRPC-ROLE-CROSS-REG Role Assignment for PC Cross Regulation Roles
GRPC-SCOPE-MAT-ANA-FREQ Scoping Materiality Analysis Frequency
GRPC-SCOPE-IMPACT-LEVEL Impact Levels
BC_SET_PROBABILITY_LEVEL_ID Maintain Probability Level ID
BC_SET_RISK_LEVEL_MATRIX Maintain Risk Level Matrix
NOTE
Before activating this BC set, first activate
BC_SET_PROBABILITY_LEVEL_ID.
NOTE
Before activating this BC set, first activate GRPC-MCF-FDA.
GRPC-AGENTSLOTC-FDA FDA Roles to Receive Tasks in Workflow
GRPC-MCF-FDA Regulation/Policy – FDA
GRPC-ROLE-FDA Roles for Regulation/Policy FDA
NOTE
Before activating this BC set, first activate GRPC-MCF-FDA.
BC Set Name
BC sets for SOX regulations:
GRFN-PNS-SOX Plan Usage – SOX
NOTE
Before activating this BC set, first activate GRPC-MCF-SOX.
GRPC-AGENTSLOTC-SOX SOX Roles to Receive Tasks in Workflow
GRPC-MCF-SOX Regulation/Policy – SOX
GRPC-ROLE-SOX Roles for Regulation/Policy SOX
NOTE
Before activating this BC set, first activate GRPC-MCF-SOX.
NOTE
NOTE
This BC set must be activated twice.
GRFN-WORKFLOW-NOTIFICATION Maintain Workflow Notifications
GRPC-FREQUENCY Timeframe Frequencies
GRPC-TIMEFRAME Timeframes
BC_SET_BENEFIT_CATEGORY Maintain Benefit Category
GRPC-RISK-DRIVER-CATEGORY Driver Category of Risk Attributes
GRPC-RISK-IMPACT-CATEGORY Impact Category of Risk Attributes
Procedure
To create systems in the portal to access the Web Dynpro applications in the Process Control ABAP
system:
1. Navigate the SAP Help Portal as follows: help.sap.com/nw70 scroll past SAP NetWeaver 7.0 including
Enhancement Package 1 Knowledge Center Support Package Stack 05, September 2009 scroll past Docupedia
Functional View SAP NetWeaver by Key Capability People Integration by Key Capability Portal Portal
Administration Guide System Administration .
Specifically, the topic Workset: System Administration provides tools to configure, maintain, and support
the portal, its services, and system landscape.
2. Use the above path until you reach Portal, then follow this path: Portal Administration Guide Super
Administration Administration Roles Workset: System Administration .
For optimum display of the portal, you need to choose the relevant portal configuration required
depending on the license purchased. Select portal configuration for AC10-only license users or for GRC
Suite multiple application license users (AC10+PC10+RM10 or any combination of two applications).
NOTE
SAP provides a set of sample roles, which include recommended authorizations. You can create
your own PFCG roles or copy the sample roles to your customer namespace, and then modify
them as needed. For more information about the delivered roles for, see Security Guide for SAP
BusinessObjects Access Control 10.0 / Process Control 10.0 / Risk Management 10.0.
Œ€ð,W8 Assign the role ERP COMMON to everyone in the user group.
NOTE
This section uses the delivered roles only as an example. As you complete the procedure, it is
essential that you replace the sample roles with equivalent roles in your customer namespace.
Procedure
To create an initial user in the ABAP system for SAP BusinessObjects Access Control 10.0:
1. Initially, all Access Control users need to be assigned to SAP_GRAC_FN_BASE to access AC 10.0
applications.
2. Next, assign the SAP_GRAC_FN_ALL role to the user doing the customizing of the product.
This is the power user role. It gives the designated user the ability to see and do everything without
being assigned to a specific Access Control role.
This role is typically assigned to the user setting up the organization structures and assigning
business roles to all the other users.
The role does not contain the authorizations for Workflow Customizing, Case Management, or Web
services activation. For these authorizations, use the role SAP_GRAC_SETUP.
CAUTION
Assign the SAP_GRAC_FN_ALL role with caution, since a user assigned to this role can make
pervasive changes.
For more information on the SAP_GRAC_FN_ALL role and its authorizations, see the SAP
BusinessObjects AC/PC/RM 10.0 Security Guide on the SAP Service Marketplace at: https://
service.sap.com/securityguide SAP Business User SAP BusinessObjects AC/PC/RM 10.0
Security Guide .
3. Using transaction SU01, create a user.
4. On the Address data tab, assign the communications type of e-mail and provide an e-mail address
if this user needs to receive workflow notifications via e-mail.
5. On the Roles tab, assign the SAP_GRAC_FN_BASE, SAP_GRAC_FN_ALL, and SAP_GRAC_ALL roles to this
user.
6. This user can now go to the IMG using transaction code SPRO and complete the configuration,
including such steps as activating the Business Configuration (BC) sets and assigning roles to other
users.
To create an initial user in the ABAP system for SAP BusinessObjects Process Control 10.0 and Risk
Management 10.0:
1. Initially, all Process Control users and Risk Management users need to be assigned to
SAP_GRC_FN_BASE to access PC/RM 10.0 applications.
2. Next, assign the SAP_GRC_FN_ALL role to the user doing the customizing of the product.
This is the power user role. It gives the designated user the ability to see and do everything without
being assigned to a specific Process Control or Risk Management role.
This role is typically assigned to the user setting up the organization structures and assigning
business roles to all the other users. It contains all of the authorizations from the role
SAP_GRC_FN_BUSINESS_USER, in addition to the following authorizations:
Ýñ†\MH Administrative functions in the Process Control Implementation Guide (IMG), and Risk
Management IMG.
Ýñ†\MH Structure setup in expert mode.
Ýñ†\MH Data upload for structure setup.
Ýñ†\MH Customizing table maintenance for PC/RM 10.0.
Ýñ†\MH Initiation of role assignment procedures.
The role does not contain the authorizations for Workflow Customizing, Case Management, or Web
services activation. For these authorizations, use the role SAP_GRC_SPC_SETUP.
CAUTION
Assign the SAP_GRC_FN_ALL role with caution, since a user assigned to this role can make
pervasive changes.
For more information on the SAP_GRC_FN_ALL role and its authorizations, see the SAP
BusinessObjects AC/PC/RM 10.0 Security Guide on the SAP Service Marketplace at: https://
service.sap.com/securityguide SAP Business User SAP BusinessObjects AC/PC/RM 10.0
Security Guide .
3. Using transaction SU01, create a user.
4. On the Address data tab, assign the communications type of e-mail and provide an e-mail address
if this user needs to receive workflow notifications via e-mail.
5. On the Roles tab, assign the SAP_GRC_FN_BASE and SAP_GRC_FN_ALL roles to this user.
6. This user can now go to the IMG using transaction code SPRO and complete the configuration,
including such steps as activating the Business Configuration (BC) sets and assigning roles to other
users.
NOTE
This section uses the delivered roles only as an example. As you complete the procedure, it is
essential that you replace the sample roles with equivalent roles in your customer namespace.
Procedure
1. Log on as portal user administrator and access the User Administration function.
2. If the user has been created by the User Management Engine (UME) that is connected to the GRC
ABAP system, you do not need to create the user in the portal system.
If not, create a new portal user and assign the system to the user in the User Mapping for System
Access tab, along with a mapped user ID and password.
3. After creating the user, go to the Assigned Roles tab and assign the role GRC Suite (name:
pcd:portal_content/com.sap.pct/com.sap.grc.grac/com.sap.grc.ac.roles/
com.sap.grc.ac.Role_All) to the user who has the power user role SAP_GRAC_FN_ALL in the ABAP
system, to enable viewing of all the Work Centers.
1. Log on as portal user administrator and access the User Administration function.
2. If the user has been created by the User Management Engine (UME) that is connected to the GRC
ABAP system, you do not need to create the user in the portal system.
If not, create a new portal user and assign the system to the user in the User Mapping for System
Access tab, along with a mapped user ID and password.
3. After creating the user, go to the Assigned Roles tab and assign the role GRC Suite (name:
pcd:portal_content/($installedpath$)/com.sap.grc.GRC_Suite/
com.sap.grc.GRC_Suite_Role/com.sap.grc.GRC_Suite) to the user who has the power user role
SAP_GRC_FN_ALL in the ABAP system, to enable viewing of all the Work Centers.
More Information
For more information about visibility of Work Centers, see the SAP BusinessObjects AC/PC/RM 10.0 Security
Guide at https://service.sap.com/securityguide.
Communication is based on the technologies delivered by SAP NetWeaver Portal. For more
information, see the SAP NetWeaver Portal Security Guide at https://service.sap.com/securityguide.
This chapter applies only to SAP BusinessObjects Process Control 10.0 and SAP BusinessObjects
Risk Management 10.0.
Content Lifecycle Management (CLM) aims to support the management of application content. This
is achieved by providing users with a consistent way to package, version-control, inspect, and import
vendor content into their systems. It focuses on the capability to deliver content from vendors’
landscapes to customers’ landscapes.
It is not intended to provide a means to transport content within a single landscape; this is already
facilitated by the ABAP transport system.
1511322 Installing POASBC You want to install an add-on or perform a delta upgrade to SAP NetWeaver
100_702 on NW 7.0 7.0 with Enhancement Package 2.
EHP2
1536594 Support packages for This note contains information about Add-on Support Packages for
POASBC 100_702 POASBC.
CAUTION
Do not import Support Package SP01 (SAPK-10001INPOASBC) and
Support Package SP02 (SAPK-10002INPOASBC) together in a queue
because a termination may occur during the import.
RECOMMENDATION
CAUTION
To enable communication between connected SAP systems it might be necessary to set up trust
relationships between systems. When planning the installation of Content Lifecycle Management
on an already existing application system instance alongside an existing application, security and
performance considerations must be taken into account.
Content Lifecycle Management only delivers sample technical roles containing authorizations for
various managed applications and with supported features for each managed application. The delivered
roles are only for reference for a particular managed application; for more restrictions, you need to
plan what roles can exist with regard to CLM and what CLM activities can users with these roles perform.
Documentation of the CLM-based authorization objects and delivered technical roles is included in
the Security Guide.
RECOMMENDATION
We recommend to have the same users for both CLM and the application. The CLM authorization
object can be assigned to users specific to the application via Netweaver ABAP user and role
management.
Authorization checks for application-specific objects and roles are part of the application itself.
Since CLM interacts with these applications for content extraction and deployment; unauthorized
access to content can only be prevented if the same user is used in both CLM and the application.
Software Component
Software Component Prerequisites
POASBC version POA_SBC_100_702 SAP_ABA 7.02 SAP_BASIS 7.02
NOTE
This step mainly applies to standalone CLM landscape model. In the landscape model where
communication between the application and CLM happens locally, there is no need for
communication destinations.
For each system that has to be managed via CLM there should be at least one RFC destination set up.
NOTE
If it cannot be guaranteed that the same users are used throughout the landscape, it is also the
point when users in the managed system and in the system hosting CLM can be mapped to each
other. This can be done by configuring authentication of the created RFC Destinations (Logon &
Security).
For more information about setting up RFC destinations, see SAP Help Portal at http://
help.sap.com SAP NetWeaver .
CAUTION
When configuring the RFC destination, make sure that you set up authentication (logon and
security). Ensure that the user is not asked for RFC connection logon details, as CLM lacks the
capability to prompt users for RFC connection logon details during runtime.
Make a note of the destinations created as these are needed later on during the configuration process.
Determining Naming Policy and Global Configurations
To ensure that a globally unique identification is available for content managed by CLM, namespaces
have to be configured within CLM. When application content is managed in CLM system; it receives
specific identification based on values configured in this step.
Use
There are three levels of unique names within CLM:
¦û—¡5d Vendor namespace
NOTE
Vendor namespace is only necessary for the business process Providing Content. It is not necessary
for the business process Consuming Content.
¦û—¡5d Authoring domains
¦û—¡5d Repository identification
You define these values in Customizing for Content Lifecycle Management under Define Global Settings and
Define Authoring Domains.
For more information about the namespace concept within CLM, see SAP Library documentation
under Content Lifecycle Management Content Group .
Procedure
1. Specify CLM repository ID and vendor namespace that is globally unique for this instance of CLM.
NOTE
To ensure the uniqueness of the chosen namespace, SAP operates a service that issues unique
namespaces for use in SAP Service Marketplace. Vendors are free to use their own namespace
identifier that can distinguish their content from others in CLM.
RECOMMENDATION
2. Test client 200 has values: Vendor Namespace = XXX, Repository ID = QUA100, Authoring
Domain = O&G_USA
You can define the applications that communicate with CLM in Customizing for Content Lifecycle
Management under Define Applications.
Configuring System Registry
The CLM system registry is used for maintaining a list of the managed systems along with their
connectivity information. CLM must have an entry in the system registry for all the systems that are
to be managed by CLM.
You can configure new managed systems in Customizing for Content Lifecycle Management under Maintain
System Registry (transaction SPRO).
For more information, see Maintain System Registry documentation.
During maintenance of system registry, you are asked to specify an existing authoring domain and an
existing RFC destination whose values were set in above steps.
CLM predelivers application-specific API groups containing APIs that are RFC functions modules
residing in application system. When you configure system registry, you associate RFC destination to
API groups and finally you use the system registry at runtime in your business scenarios for content
extraction and deployment.
NOTE
After settings have been made in Customizing, the transaction /POA/CLM_API_TESTER should
be run to test the configured systems, APIs, and function modules before running CLM for actual
extraction and deployment. This tool is only intended for developers and it accepts the system
registry ID. The returned results display the format, signature, and RFC checks against a particular
application system.
You can also maintain the system registry in transaction SE54. Choose Edit View Cluster and enter /POA/
VC_CLM_SYS_REG.
Configuring Technical Settings for Content Lifecycle Management
CLM has the following technical settings that can be maintained:
|1˘}²) Deployment polling count — how many times to check the deployment
|1˘}²) Deployment polling interval (minutes) — how often to check the deployment
|1˘}²) Maximum extract chunk size (KB)
|1˘}²) Refresh (seconds) — how often to refresh the content in the main view
|1˘}²) Comparison threshold (hours) — if a content group you are comparing is older than the defined
threshold, you receive a warning message
To change these settings, see Customizing for Content Lifecycle Management under Maintain Technical
Settings (transaction SPRO).
For more information, see the Maintain Technical Settings documentation.
Content Lifecycle Management (CLM) is delivered with the following SAP ABAP-based roles:
ve�⁄x /POA/CLM_GRC_USER
ve�⁄x /POA/CLM_GRC_<application name>_USER
There are three possible information architectures:
SAP GUI Installation
If SAP GUI is used as the information architecture, the following configuration steps must be followed
to allow access to CLM:
The CLM roles include the menu for the CLM Web Dynpro ABAP application and also an authorization
profile for CLM-based authorization objects. For more information about authorizations, see the
application security guide.
As an administrator, you can assign users in the CLM roles or create your own roles as a copy of these
and assign users to these roles.
For example, after assignment of CLM roles to 'CLM_TEST' user in SAP backend, the CLM role is
available in the user menu.
NetWeaver Business Client Installation
If NetWeaver Business Client is used as the information architecture, the following configuration steps
must be followed to allow access to CLM:
SAP BusinessObjects governance, risk, and compliance (GRC) solutions predeliver roles for NetWeaver
Business Client for various applications and various functions such as:
ve�⁄x SAP_GRC_NWBC for overall GRC solutions work centers.
RECOMMENDATION
We recommend that you include CLM in your existing GRC solutions role and provide the
configuration in PFCG as needed. You can either include the menu from the delivered CLM role
or create your own menu path in NetWeaver Business Client pointing to the CLM Web Dynpro
ABAP application /POA/WD_CLM.
The CLM ABAP Web Dynpro application has the following configuration ID to run CLM for GRC
solutions:
/POA/WD_CLM_GRC - Configuration parameter for CLM in GRC solutions
EXAMPLE
The CLM Web Dynpro ABAP application is included as a new folder in a customer role, which is
based on SAP_GRC_NWBC role in PFCG. As a result, the UI that is displayed to a user with this
role includes work centers from an existing GRC solutions role plus a new work center for Content
Lifecycle Management.
Portal-Based Installation
If portal-based access is used as the information architecture, the following configuration steps must
be followed to allow access to CLM:
Portal roles are used in GRC solutions to provide NetWeaver portal-based user access for various
functions.
For CLM, no existing portal role is supplied, but the following steps can be used to enable portal users
to access CLM:
1. In NetWeaver Portal, choose Content Administration Portal Content Management Portal Content .
2. Copy an existing model workset, create a new workset, or enhance the old workset with the CLM
link.
3. To add CLM as an application link:
1. Create a new iView based on Web Dynpro ABAP application.
2. Provide WAS server details or an existing SAP system alias.
3. Enter Web Dynpro ABAP application name as wd_clm and enter WDCONFIGURATIONID=%2fPOA
%2fWD_CLM_GRC in Application Parameters field.
4. Assign the workset to existing or new portal roles as needed.
EXAMPLE
You can create a new portal role specifically for CLM, which is only visible to content
administrators or you can assign the CLM work center to an existing role depending on your
requirements.
5. Assign the portal role to relevant users and groups.
6. Enable portal users to use back-end users, with the correct authorization to run CLM. Map the
portal users to back-end users with CLM roles assigned.