Re: [sap-security] What to do with the SAP Security Audit Log?
Posted by
Admin at
|
Share this post:
|
on 06/15/2009 12:02:00 AM
Thanks,
I'm trying to understand how to best utilize the SAL.
I don't see how screening it weekly/monthly adds benefit because I don't
really what to look for or how to spot irregularities.
I would like to hear from others how they use the SAL. Do you screen it
regularly, and if so what exactly are you looking for? Do you use it for
auditing like picking up some transactions and double checking that correct
procedures were followed? Etc.
I would appreciate some feedback on that.
thanks
Osama Salah
On Sat, Jun 13, 2009 at 9:33 PM, ovanwyk via sap-security <
sap-security@groups.ittoolbox.com> wrote:
>
>
>
> Hi Osama,
>
> You could use transaction codes ST22, SM21, BD87 to monitor some of the
> errors, also SM37 job jobs failed/cancelled.
>
> Hope it helps
>
> From: Osama Salah via sap-security
> [mailto:sap-security@Groups.ITtoolbox.com]
> Sent: 13 June 2009 10:52 AM
> To: Orietta Van Wyk
> Subject: [sap-security] What to do with the SAP Security Audit Log?
>
>
>
>
> Hi,
> I'm an information security officer and now SAP falls under my
> responsabilities. I know very little about SAP and am planning to attend
> some SAP related security courses. At the moment I have one issue
> troubling me. Auditors were recommending to periodically review the
> security audit logs and keep evidence that the review was done. Looking
> at the log I couldn't really figure out what to do with it. I don't see
> how I am supposed to spot any irregularities in it. The way I see it I
> could pick up some random changes for example like users being added
> etc. and check that the proper procedures were followed.
> Any other idea how to deal with this? Are there any best practices?
> Anything good arguments, documentation that we can use to convince the
> auditors of a better approach. Or maybe I'm wrong, maybe its doable and
> makes sense.
> Please help me out with your thoughts.
> thanks
> Osama Salah __.____._
Toolbox.com
4343 N. Scottsdale Road
Suite 280
Scottsdale, AZ 85251
In the Spotlight
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion