Best sap security Online Training |Sap Security With Real time Expert. PowerPoint PPT Presentation

presentation player overlay
About This Presentation
Transcript and Presenter's Notes

Title: Best sap security Online Training |Sap Security With Real time Expert.


1
(No Transcript)
2
SAP SECURITY
  • This site strives to be a comprehensive guide
    to SAP Security and Authorizations. Though  a
    search in Google returns any number of references
    on security, the number of sites dealing
    exclusively with SAP security are few and far
    between. This is a personal site maintained
    solely by me.

3
SAP SECURITY
  • A companys IT security policy should specify
    mandatory software requirements for things such
    as minimum password length, password strength,
    number of password fails allowed before account
    lockout, etc.  These requirements should be
    followed by all applications, and SAP is no
    exception. 

4
SAP SECURITY
  • Since SAP is an integrated system, there is a
    risk of internal fraud if incompatible
    responsibilities are allocated to the same
    individual. For example, if a user were to have
    privileges to maintain bank account details and
    execute the payment run, it might be possible for
    him or her to bypass controls and divert vendor
    payments to his or her own account.

5
SAP SECURITY
  • These are not isolated cases. And while I
    cannot confirm which kind of system OPM is using
    for the CPDF database, taking into account public
    information, most likely OPM is using an
    ERP-based system to hold and report federal
    employment statistics.

6
SAP SECURITY
7
SAP SECURITY
  • Its quite common in the SAP world that one
    transaction calls another via different menu
    options. At the code level this is often
    implemented via the ABAP construct CALL
    TRANSACTION. We know that to start a transaction
    from menu or typing via the command window, a
    S_TCODE check is performed at the SAP kernel
    level. However whether a S_TCODE check is
    performed for the CALL TRANSACTION statement can
    be controlled by us through the SE97 code. 

8
SAP SECURITY
9
Thank You
  • By
  • HYDERABADSYS Online Training
  • Contact Us
  • HYDERABADSYS.COM
  • INDIA 91 9030400777   
  • USA 1-347-606-2716
  •  Email contact_at_Hyderabadsys.com
Write a Comment
User Comments (0)
About PowerShow.com