TIB SYSTEMS LLC SAP Security · GRC · Controls
← All four programmes
Stage 02 · Capture

TRK · 02

SAP Controls Consultant — Hands-On Course

No-Access Track taught you to judge evidence someone else handed you. This is where you learn to go get it yourself — the same fifteen domains and sixty-four items, but now you're the one inside SAP and SAP GRC producing them, screen by screen.

Evidence Capture Training · direct one-to-one companion to No-Access Track · SAP GRC sandbox access required

64Items matched to No-Access Track
15SAP & GRC domains
2Evidence types taught
FreeIncluded in the self-paced bundle

Background

Why this programme exists

No-Access Track is deliberately built so you never have to touch a live SAP system — you're handed the evidence and asked to judge it. That's the right way to build judgment fast. But it leaves a real gap: it never teaches you where a SUIM extract, a GRC risk analysis, or an audit log actually comes from, or how someone produces it in the first place. This course closes that gap directly. Same fifteen domains. Same sixty-four items. This time, you're the one navigating to the screen, running the report, and deciding how the evidence gets saved.

The core skill

Two kinds of evidence, and knowing which is which

Most training glosses over this. A real controls analyst has to know, screen by screen, whether what's in front of them is something you export as a working file, or something where the screenshot itself is the entire piece of evidence. Getting this wrong either wastes time hunting for an export button that doesn't exist, or hands in a screenshot when a real file was expected.

Export as file

The screen shows a list or report — a SUIM extract, a GRC risk analysis, an audit log query. You run it, export it (Excel/PDF), and the exported file is the evidence a reviewer actually works from.

Screenshot only

A configuration or display screen with nothing to export — a PFCG authorization tab, an RZ11 parameter, an SM59 destination. The screenshot itself is the complete, final evidence.

Who it's for

Built for the step right after judgment

You'll feel at home here if

You've completed (or are partway through) No-Access Track and can already recognize a control exception — you just haven't produced the evidence yourself yet. Also a strong fit if you're comfortable with SAP navigation basics and want to build real screen-level fluency before Mastery Console's live labs.

What you need to start

Access to an SAP GRC sandbox — the same access No-Access Track deliberately doesn't require. If you don't have one yet, this is the point in the sequence where getting one becomes worth it.

Scope covered

The same fifteen domains — now you produce them

Every domain below matches a chapter in No-Access Track exactly. Where that track had you read a SUIM extract, this course has you navigate to SUIM, run it, and export it yourself.

01 · SUIM

User Information System

Navigating and exporting user, role, and authorization reports.

02 · PFCG

Profile Generator

Building and displaying roles, capturing authorization tabs correctly.

03 · SOD

Segregation of Duties

Running GRC risk analysis and SU24/SU25 checks, and exporting the results.

04 · FIORI

Fiori App & Catalog Security

Navigating catalog configuration and target mapping screens.

05 · EAM

Emergency Access Management

Producing firefighter activation and session logs from GRC EAM.

06 · ARQ

Access Request Management

Navigating request status, approval history, and aging reports.

07 · UAR

User Access Review

Producing campaign decision history and population evidence.

08 · RAR

Risk Analysis & Remediation

Running remediation tracking and What-If simulation reports.

09 · PCCM

Process & Continuous Control Monitoring

Locating and screenshotting control-testing and monitoring evidence.

10 · TLOG

Table Logging

Producing table-change history and technical-settings evidence.

11 · STMS

Transport Management System

Navigating import queues and transport ownership evidence.

12 · ITGC

IT General Controls

Producing batch-job schedule, execution, and change evidence.

13 · SM59

RFC Connections

Navigating destination configuration and trust relationship screens.

14 · SECPARAM

Security Parameters

Producing profile-parameter evidence from RZ11.

15 · SM20

Security Audit Log

Running and exporting filtered audit-log evidence.

Course layout

A guided walkthrough, not just a task list

01

Sixty-four items, one screen sequence each

Every item names the SAP or GRC tool, tells you exactly what the evidence is supposed to show, and gives numbered navigation steps to get there — not a vague pointer to "check SUIM."

02

Explicit evidence-type labeling

Each item is marked "export as file" or "screenshot only" before you start, so you're never guessing which one applies or hunting for a button that isn't there.

03

A companion navigation guide

A full step-by-step capture guide ships alongside the course — the same document used to build this course's own content — for offline reference while you're in the sandbox.

04

File naming and progress tracking

A consistent naming convention across all 64 items, with progress tracked automatically so you always know what's left.

What you'll walk away with

By the end of the course

Ready to start Stage 02?

Included free with the self-paced bundle — sign in and start matching evidence to No-Access Track item 1.

Sign in to Evidence Capture Training →