SAP AMS Support, How to Choose?

Posted by Andrea Mazzolani (translation) on Mar 31, 2023 12:00:00 AM

What is it? How should you structure it in our opinion?

 

 

How should you prepare to activate and evaluate it?

Read More

Topics: security ams, supporto sap ams

Standard SAP Roles, are they used or it's better not to use them?

Posted by Andrea Mazzolani (translation) on Mar 24, 2023 12:00:00 AM

 

SAP provides pre-defined roles instead of having to create them from scratch.

 

 

Is it worth using them or not? Why are they often, or almost always, not used?

Read More

Topics: pfcg, sap standard role

Does SAP trace everything?

Posted by Andrea Mazzolani (translation) on Mar 17, 2023 12:00:00 AM

This is a statement that I often hear: "SAP traces everything". 

 

 

But is it actually like that? Can I really ensure an activity tracing and find out who did what in the system? Or are there any methods to bypass these logs?

Read More

Topics: audit sap, log sap

SAP Security Patch Day

Posted by Andrea Mazzolani (translation) on Mar 10, 2023 12:00:00 AM

What is a SAP Security Patch Day? When should you do it?

 

Who are the main researchers reporting security problems to SAP?

Read More

Topics: patch, sap vulnerability, sap patch

10 things NOT to do if you have SAP GRC

Posted by Andrea Mazzolani (translation) on Mar 3, 2023 12:00:00 AM

 

What are the main oversights when using SAP GRC or deciding whether to use it or not?

 

 

Read More

Topics: SAP GRC, SAP Fraud Management

5 suggestions on SAP S/4HANA Security: S/4HANA Upgrade

Posted by Andrea Mazzolani (translation) on Feb 24, 2023 12:00:00 AM

What are the focus points in SAP S/4HANA projects?

 

What is worth doing to prepare? How to approach new things?

Read More

Topics: crittografia SAP, UCON, upgrade

6 checks the Data Protection Officer must do in SAP

Posted by Andrea Mazzolani (translation) on Feb 17, 2023 12:00:00 AM

 

What should the Data Protection Officer do in SAP systems? 

 
What are the controls to be carried out in the management system?
Read More

Topics: SAP audit, DPO, sap dati personali

TIP OF THE DAY: LIMIT VISIBILITY TO CERTAIN FINANCIAL YEARS

Posted by Klea Duro on Feb 10, 2023 12:00:00 AM

For many companies using SAP (if not all of them) it is absolutely normal to 'undergo' inspections by external entities. Especially for the auditing of balance sheet data.

 

 

A common practice is to enable everything to the auditors. And from the perspective of maximum transparency it could certainly make sense. But is it possible to evaluate or reason differently? Continue reading...

Read More

TIP OF THE DAY: SAP AUTHORIZATION PFUD USER COMPARISON

Posted by Klea Duro on Feb 3, 2023 12:00:00 AM

Did you know that there is a feature called "User Comparison" in SAP? Even in S/4HANA?

 

 

But what is it for and why in some cases might there be errors?

Read More

SAP DEFAULT PASSWORD

Posted by Fabio Mambretti on Jan 27, 2023 12:00:00 AM

Did you know that there are "special" SAP users whose credentials are known, public?

This is not an SAP oversight; it is something known and familiar. Especially in the initial setup processes of the system, utilities are activated that should be secured immediately thereafter. But what are they and what should you do?

Read More

Topics: password policy, sap super user, sap password, cyber security, userid

Yes Subscribe!

Blog Aglea, what you could find out?

Every Friday a new post, interview or content related to SAP Security.

  • Tips on how to design SAP Security
  • How to
  • Checklist
  • Common error and pitfall on security SAP
  • Interview with experts
  • Who we are and Aglea vision on SAP Security

Recent Posts

Post By Topic

See all