The axl & trax predefined SoD ruleset is the result of over 14 years of experience in auditing SAP systems and helping customers establishing rulesets and SoD matrices. It features a list of approximately 350 functionalities mapped to technical queries that cross-linked into more than 3,000 Segregation of Duties rules.
Approximately 400 of these are generally considered critical conflicts. The predefined queries and SoD rules are defined in both business language and technical parameters (transaction codes with authorization objects) and are ranked based on risk relevant to Sarbanes-Oxley. Each query and SoD rule can be tailored, expanded or adapted to the needs of a specific organization.
Generally speaking, the SoD ruleset can be considered as an encyclopedia of SoD rules that may well be used as a reference when defining risk mitigation strategies within any organization and establish a specific SoD ruleset.
The SAP SoD ruleset can be used immediately in CSI Authorization Auditor, but can also be used as an MS-Excel reference or mapped to work as an SAP GRC Access Control SoD matrix.