From Policing to Prevention
摘要
For many years, SAP security governance has operated much like a police force. Controls were evaluated only after suspicious activity had already taken place. Audit findings served as “tickets” issued months after violations occurred. Investigations unfolded once damage had been done long after access decisions, system changes, or workflow bypasses introduced the underlying risk. In this model, governance is reactive. It waits. It monitors. It catches failures but rarely prevents them.