- What is a Firefighter ID, and why is it useful?
- What are the different types of users available in SPM (Superuser Privilege Management)?
- What is the difference between a Firefighter Owner and a Firefighter Controller?
- What roles can be assigned to users in SPM?
- What are the key tables related to Firefighter IDs?
- How do you configure a Firefighter ID?
- How can you assign a Firefighter ID (FFID) to a Firefighter?
- What is the background job used to generate Firefighter reports?
- How can you retrieve a report of Firefighter ID assignments?
- What are the different types of Firefighter IDs available?
- What are the critical parameters to configure during Firefighter setup?
- How can reports be generated for Firefighter activity, and what types of reports can you obtain?
- What is the maximum duration for which an FFID can be assigned to a Firefighter?
- In which situations should a Firefighter ID be used?
- What settings must be configured to obtain Firefighter ID trace details?
1. What is a Firefighter ID, and why is it useful?
A Firefighter ID (FFID) is a special user ID in SAP GRC (Governance, Risk, and Compliance) used for emergency access. It allows users to temporarily perform critical tasks that their regular roles do not permit. Firefighter IDs help track and control privileged access, ensuring compliance and reducing security risks.
2. What are the different types of users available in SPM (Superuser Privilege Management)?
SPM (now part of SAP GRC Access Control) has four main user types:
- Firefighter ID (FFID) – Special user with elevated access.
- Firefighter (User assigned to FFID) – Uses the Firefighter ID for critical tasks.
- Firefighter Controller – Monitors and reviews Firefighter activities.
- Firefighter Owner – Manages and assigns Firefighter IDs.
3. What is the difference between a Firefighter Owner and a Firefighter Controller?
- Firefighter Owner: Responsible for assigning and maintaining Firefighter IDs.
- Firefighter Controller: Reviews logs and ensures proper use of Firefighter IDs.
4. What roles can be assigned to users in SPM?
- /GRC/SAP_GRIA_FFID_OWNER – Firefighter Owner
- /GRC/SAP_GRIA_FFID_CONTROLLER – Firefighter Controller
- /GRC/SAP_GRIA_FFID_USER – Firefighter User
- /GRC/SAP_GRIA_FFID_ADMIN – Firefighter Administrator
5. What are the key tables related to Firefighter IDs?
- GRACFFUSER – Stores Firefighter user assignments.
- GRACFFLOG – Logs Firefighter activities.
- GRACFFCTRL – Firefighter Controller details.
- GRACFFOWNER – Firefighter Owner details.
6. How do you configure a Firefighter ID?
- Create a Firefighter ID in SAP.
- Assign roles with necessary authorizations.
- Assign a Firefighter Owner and Firefighter Controller.
- Set up the required background jobs for log generation.
- Assign the Firefighter ID to a user.
- Test Firefighter ID access and log reporting.
7. How can you assign a Firefighter ID (FFID) to a Firefighter?
- Open SAP GRC Access Control.
- Go to NWBC → Access Management → Firefighter ID Owner.
- Select Assign Firefighter ID.
- Choose the FFID and assign the user.
- Save and activate the assignment.
8. What is the background job used to generate Firefighter reports?
- GRAC_SPM_LOG_SYNC – Syncs logs from plug-in systems.
- GRAC_SPM_GRAC_SPM_LOG_SYNC – Generates Firefighter reports.
9. How can you retrieve a report of Firefighter ID assignments?
- Go to NWBC → Reports & Analytics → Access Control Reports.
- Choose Firefighter Log Report.
- Enter the Firefighter ID or date range.
- Execute the report to view assignments and activities.
10. What are the different types of Firefighter IDs available?
- Shared FFID – Used by multiple users.
- Individual FFID – Assigned to a single user.
- System FFID – Used for system-level emergency access.
11. What are the critical parameters to configure during Firefighter setup?
- Log retention period – Define how long logs should be stored.
- Notification settings – Set up alerts for FFID use.
- Session timeouts – Set limits for Firefighter sessions.
- Controller approvals – Ensure controllers review logs.
12. How can reports be generated for Firefighter activity, and what types of reports can you obtain?
- Use NWBC → Reports & Analytics → Firefighter Reports.
- Types of reports:
- Usage Report – Who used the FFID and when.
- Transaction Log Report – Actions performed.
- Audit Report – Controller reviews and approvals.
13. What is the maximum duration for which an FFID can be assigned to a Firefighter?
The default session duration is 8 hours, but it can be configured based on security policies.
14. In which situations should a Firefighter ID be used?
- Critical production support (e.g., fixing urgent issues).
- Temporary access for high-risk tasks (e.g., configuration changes).
- Disaster recovery operations.
- When regular user roles do not provide the necessary access.
15. What settings must be configured to obtain Firefighter ID trace details?
- Enable logging in GRAC_SPM_LOG_SYNC.
- Ensure audit logs are stored in GRACFFLOG.
- Configure email notifications for controller reviews.
- Enable real-time monitoring using SAP GRC dashboards.
No comments:
Post a Comment