SAP Technical Audit
SAP Technical Audit
SAP Technical Audit
A SAP Baseline Security Audit tells enterprises how their SAP security posture stacks
up against industry best practices. The Baseline Security Audit is the first step in a
comprehensive security audit program and is ideal for generating a quick win early.
This article outlines the areas covered under the SAP Baseline Security Audit we
perform. The audit covers two high-level areas:
1.
2.
Firewalls
Server controls
Network controls
Next, we drill down into a few specific checks to illustrate the type of checks that are
performed in practice:
Have the default passwords for default users (SAP, DDIC, etc) been
changed?
Network Controls
Has RFC communication in the SAP gateway been secured with the secinfo
file?
Has the network been segmented with adequate isolation for various SAP
elements?
Server Controls
Have OS commands that can be executed from SAP via SM49 been
prevented?
Next, we drill down into a few specific checks to illustrate the type of checks that are
performed in practice:
Are key administrative roles separated? Eg. User creation and approval
The above are sample checks performed as part of the baseline audit.
Transactions
- ABAP programs
- Tables
- Files
- Authorizations, authorization profiles and user master records
- Data carriers
- Other security measures (such as table types and separating different
clients)
, Naming conventions when altering transactions ABAPs, tables, files and
other SAP objects. determine whether they function properly and are
sufficiently documented.
Functional Scope
A)Project Preparation Phase
project organization
project schedule
Project charter
Standards and procedures
Scope
Training Plans
B)Business Blue Print Phase
As-Is Study
To-Be Process
Business Blue Print
Idetification of gaps
Work arounds for gaps
Organizational Structure
Business Process Master List
Baseline Scope Definition (80/20 rule)
Interfaces Required
Conversions required
Reports needed
Authorizations
Enhancements Needed
Level 1 Training and feed back reports
BBP Signoff
Issue log maintenance ,addressing and escalation
Risk analysis and mitigation
Backup and Recovery plans
C)Realization Phase
Level-2 traing and Feed back reports
Unit Testing plans
Unit test by consultants and core team members and test scripts acceptance.
Base line integration test scripts and results.
User acceptance tests and results.
D)Final Preparation
Final Configuration and documentation
Completion of Interface development and testing and user acceptance.
Cutover strategy preparation and documentation.
Level 3 traing of core team members.Traing feed back.
Training of End users and feed back
Retraining as per feed back.
Test scripts for Integration testing and user testing and acceptance.
Closure of open issues.
Volume testing and stress testing of SAP system and Interphases.
Preparation for Go-live
Setting up of Help desk and issue redressal mechanism and SLAs
E)Go live Review of support desk activities