CSI tools Facebook CSI tools Twitter CSI tools LinkedIn CSI tools Instagram
  • Home
  • Newsroom
    • Awards
    • Events
    • Press Releases
    • Publications
  • Software
    • By Solution
      1. Access Risk Management
      2. Access Request Management
      3. Privileged Access Management
      4. Access Role Management
      5. SAP License Audit
      6. Mass User Maintenance
    • Tools
      1. CSI Authorization Auditor
      2. CSI Automated Request Engine
      3. CSI Emergency Request
      4. CSI Role Build & Manage
      5. CSI Mass User Maintenance
      6. CSI Integrate & Collaborate
    • Pathlock
    • Legacy Tools
    • Pathlock Cloud: The Successor of CSI tools
  • Customer Center
  • Community
    • CSI tools Forum
    • Meta's Blog
    • Tech Updates
    • Training
  • About
    • Contact
    • Jobs
    • Partners
      • Become a Partner
    • References
    • Testimonials
    • Sustainability
  • Login

CSItools MetaBlogHeader2018 20180518 v03

  • You are here:  
  • Home
  • Meta's Blog Home
  • The Secure Habits for Securing SAP systems

The Secure Habits for Securing SAP systems

Details
Published: Friday, 13 July 2018 11:02

SAP systems contain business critical, sensitive and personal information that needs to be safeguarded from (cyber) security threats. We listed 7 secure habits that can help you with securing your SAP environment(s).

Habit 1 - Take actions before incidents can occur

SAP systems contain business critical, sensitive and personal information that needs to be safeguarded from (cyber) security threats. Securing SAP systems against these threats requires preventive countermeasures and monitoring over different areas. These areas can be divided into the network layer, operating system layer, application server layer, application layer and database level.

To make sure your system is hardened, (preventive) monitoring is needed in all these areas. Working in a preventive manner is alwaysbetter than detecting problems when they already occrued, so we recommend implementing as much preventive controls as possible. You should only look for other solutions if no preventive check can be used.

Habit 2 - Develop an SAP security statement

The SAP security statement should be described in the Governance model. This focuses on what you want to accomplish, and is your plan for a secure SAP system. With a clear goal, the security strategy can be spread through the organization. This SAP security statement (governance model) contains the goals, priorities, risk values and standards as agreed by the board and covers all areas that are related to the SAP system.

The conceptual layer is where the high-level management defines the security requirements on high level. This conceptual layer must be translated into the technical layer, by technical people. The main advantage is that the security model becomes transparent, high level management can focus on the governance aspects and the technical people can focus on the technical layer and get instructions through the governance layer.

Habit 3 - Simplify

Now that the Governance model is created, and the conceptual layer is clear, it can be translated into technical security measures. Keep in mind that, when implementing security checks, almost everything is possible, and you have to say "No" to prevent that the SAP security will become too complex.

Habit 4 - Win-Win

Win-win means that agreements or solutions are mutually beneficial and satisfying. SAP systems are used by many users within the organization and thus should support the business processes. Implementing security aspects can mean that the system can become less user-friendly.

Thinking win-win can be hard while implementing security aspects for SAP systems. Securing the system for vulnerabilities can lead to less user-friendliness. We advise to communicate to the organization what the risks are and why the security is needed. People will become more aware of the risks and understand why in some cases access can be taken away from them. Seek into possible win-win scenarios to get a secure SAP system in which people can still work efficiently.

Habit 5 - Communication

Communication. That is what it is all about.

Make people risk-minded, inform them about the changes that will take place and why these changes are necessary. Do not just inform people, make sure they understand.

Habit 6 - Organization wide

"The whole is greater than the sum of its parts."

When hardening the systems, keep all areas in scope. Focusing only on securing the operating system but leaving all people with full access on the application level, will not safeguard your SAP system.

Habit 7 - Keep knowledge up-to-date

Technology is changing. Now with HANA databases being adapted by organizations, we see that new security threats arise. Keep your knowledge about the security aspects up to date. When migrating to new systems or databases, make sure that the security aspect is part of the scope and is being implemented as part of the process.

Let's get personal

Let's get personal, request a demo!

Blog Archive

  • The Power of Workflow
  • The NIST framework for SAP Access Security
  • Who has access to your business critical and sensitive SAP data?
  • What are the pros and cons of converting authorization fields to organizational levels?
  • Security risks of Robotic Processing Automation (RPA) in SAP
  • Privileged Access Management
  • The Secure Habits for Securing SAP systems
  • SAP User Licenses
  • Access Certification
  • Implementing compliancy for SAP environments
  • Protection of personal data for GDPR within SAP
  • (SOx) Governance, Risk and Compliance with CSI tooling
  • SAP support packages keeping me busy
  • Role building with (non) organizational values in SAP
  • CSI Authorization Auditor instead of manual control
  • Reverse Engineering for the SAP security concept
  • How to perform critical authorizations and SoD checks in SAP systems
  • Who is doing what in your SAP system?
  • Fine tuning your GRC filter set with Custom transactions
  • Display roles - are they really display only?
  • User type reference not always taken into account
  • SAP Special Users

Get in touch

Pathlock Benelux
Support Direct
Link to the support portal https://support.pathlock.com

To gain access to the new support portal, please contact us at customersupport@pathlock.com

Tel. +32 16 308 008

Address
Kempische Steenweg 303/200
B-3500 Hasselt, Belgium

Via phone
Tel: +32 16 308 000

Last Updates

  • Pathlock Cloud: The Successor of CSI tools
  • Pathlock named Market Leader for Zero Trust by Cyber Defense Magazine

Solutions

  • SoD and Risk analysis - CSI Authorization Auditor
  • Compliant Provisioning - CSI Automated Request Engine
  • Emergency Access Management - CSI Emergency Request
  • Compliant Role and Mass User Management - CSI Role Build & Manage
  • Extract SAP data - CSI Data Xtractor
  • CSI Integrate & Collaborate

©1997-2025 Pathlock Benelux. All rights reserved. - Privacy Policy  - Cookie Policy - Code of Ethical Conduct - Sitemap