We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

Re: [sap-security] Is S_A.System good for system IDs?

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Reply from SAPAUSSEC on Mar 21 at 9:41 AM
It is not a good idea to use standard SAP roles and profiles, and
depending upon business requirements and risks is likely to be an audit
finding at some future time.

The ideal approach is to have a user ID for each type of background job
- e.g. one for finance jobs, one for logistics etc with appropriate
access for the jobs that will be run. Yes I know this is a bit of work
but if security is needed it is the best approach that I am aware of -
happy to hear if there are better solutions.

As for system ID's provided by SAP with default profiles they need to be
examined individually. Basis should help here. The following
precautions are suggested:

Those with powerful access should never be a dialogue user
Those that are not needed on a daily basis should be locked and only
activated when needed included SAP*
All others should never be available to normal dialogue users - only
background processes and their default passwords should be changed e.g.
DDIC EARLYBIRD etc
IF necessary log the activities of these users
Dialogue users should _never_ be assigned standard SAP profiles or roles

---------------Original Message---------------
From: evijaykummar2
Sent: Friday, March 20, 2015 11:51 PM
Subject: Is S_A.System good for system IDs?

Best procedure to implement Batch user accounts\requirement. In my
case we decided to create one composite role per system, is this fine?
Please provide me suggestions on non domain\batch I'd accounts Thanks

 
Reply to this email to post your response.
 
__.____._
Manage Settings | Unsubscribe | Create FAQ | Send Feedback
  
Copyright © 2015 Ziff Davis, LLC. and message author.
Ziff Davis, LLC. 28 E 28th Street New York, NY 10016
SAPAUSSEC  

achievements
 
Mark as helpful
View this online
Ask a new question
 
In the Spotlight
Become a blogger at Toolbox.com and share your expertise with the community. Start today.

_.____.__

0 comments:

Post a Comment

T r a n s l a t e to your language