Automated Emergency Access Management process
Improved Access Requests in S/4HANA
Access risk remediated in legacy solutions
Transparency in access management
Based in Norway, Orkla ASA is a leading industrial investment company. Their scope of activity is brands and consumer-oriented companies. At present, Orkla has 12 portfolio companies.
Orkla has a long-term, industrial approach to its portfolio companies. They invest in companies where they can contribute to further value creation through their industry expertise, consumer insight and experience in building leading brands. Orkla ASA is listed on the Oslo Stock Exchange.
Orkla manages roughly 120 SAP ERP systems across their landscape. The reason they run a large number of systems is primarily because of historical mergers and acquisitions; they also have data located both on-premise, and in the cloud.
They encountered three main GRC (Governance, Risk and Compliance) challenges:
Orkla was able to address their GRC challenges by implementing Soterion solutions, as follows:
The insights we got from Soterion enabled us to really see what access people used, and not just what they felt they required
Orkla was able to address their challenges with Soterion by having detailed information available on emergency access management. This reduced the risk to the organisation. Moving forward, they are looking at improving the process even further. The different local businesses are now able to take ownership of the user access requests thanks to the business roles included on Orkla’s S/4HANA systems, visibility of well-defined roles and the access request data Soterion could provide.
Legacy systems can achieve unnecessary access permissions over time. To improve security and clarity, it’s recommended to organise user access around business functions. Orkla achieved this by streamlining existing roles and leveraging Soterion’s capabilities to consolidate roles based on user activities, minimizing potential security vulnerabilities.
With Soterion’s Access Manager, the approval process is much more transparent, and there is no resistance from the business users anymore
Approvers gained visibility of user access. |
User access now owned by the business. |
Need for email-based approvals eliminated. |
Simplified business processes (284, 880 role assignment changes roll up into 604 workflows). |
Valuable insights into legacy system’s roles. |
Support for a future-proof business role concept. |
© 2024 EPI-USE Labs
Trafford House, 11th Floor, Chester Road, Stretford, Manchester, United Kingdom, M32 0RS •Other Office Locations