We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

SAP Notes for Security

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Keyword: BASIS
Title : SAP Notes for Security

SAP Security Audit log Vs SAP System Log

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

There are different types of logs in the SAP system. Logs helps us to trace events as they occur and they are invaluable in problem troubleshooting and consequent resolution. Logs represents the first point of call when the system malfunctions. It is important to point out that logs too can be used to investigate users activity. A very good attribute of logs is that they are targeted towards a particular subject area. This is why logs are categorized into different topic areas such as applications, security and system among others.

Purpose and usage: The intent of the security audit log is to capture security and control events in the SAP system, for example, unsuccessful logon attempts. On the other hand, the intent of the system log is to record system-related problems such as ABAP dumps.

Beneficiary: The main beneficiary of the security audit log are the external and internal auditors. The system log is of immense importance to system administrators as it helps them in troubleshooting system problems.

Activation: You can choose to activate or deactivate security audit log at any point in time based on a need analysis, however, the system log is crucial and it is needed continuously, hence it is always activated.

Retention Period: The retention approach of security audit logs differs from that of the system log. While security audit log is maintained by the system on a daily basis and has to be archived or manually deleted, system logs are managed in a circular manner. This implies that when it gets filled, the logs are overwritten from the beginning.

Personalization: To a large extent, security audit log deals with personal or user data. This personal data in most cases are guided by data protection regulation. However, same cannot be said of system log has personal details are not displayed in the system log.
Source Kehinde Eseyin



Keyword: BASIS
Title : SAP Security Audit log Vs SAP System Log

SAP System Security

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

A good number of parameters in the RSPARAM table define how security is enforced in the SAP system. These parameters have default values defined for them. If many of these default values are not changed, the integrity of the system can be compromised.

Find following a concise description of some important security-oriented parameters.

Login/no_automatic_user_sapstar
By default, the SAP system is installed with a super user master record called SAP*. If this master record is deleted, SAP allows a user to logon with a password of “PASS” for the SAP* user. To disallow this “illegal” entry, set the value to 1. Recommended value is 1.

Login/failed_to_user_lock
This parameter defines the maximum number of unsuccessful logon attempts before the user is locked by the system. An entry will therefore be recorded in the system log. Recommended value is 6

Login/failed_user_auto_unlock
This parameter activates or deactivates the automatic unlocking of locked users at midnight. It is advisable that the system/user administrator performs the unlocking of locked users. Recommended value is 0

Login/fails_to_session_end
This parameter defines the number of times a user may enter a wrong password before the login session is terminated. Recommended value is 3

Login/gui_auto_logout
This parameter defines the number of inactive seconds after which a user is automatically logged out of the system. Recommended value is 1800 sec

Login/password_expiration_time
This parameter defines the number of days after which a password must be changed. Recommended value is 35 days

Login/min_password_lng
This parameter defines the minimum password length. Recommended value is 8

*Login/min_password digit
This parameter defines the minimum number of digits (0-9) in a password.

*Login/min_password_letters
This parameter defines the minimum number of letters or alphabets (A-Z) in a password.

*Login/min_password_special
This parameter defines the number of special characters in a password. These special characters include (), !, \, $ , %,:,’, “, ;, =, &, #, },],{,[, >, <

*Login/min_password_diff
This parameter defines the number of differing characters from previous password.

Rec/client
This parameter activates or deactivates automatic table logging. It is recommended to switch it on, however, resource utilization, table(s) to be logged and log volume should be critically analyzed.

Auth/rfc_authority_check
This parameter defined how S_RFC object is checked during RFC calls. When set to a recommended value of 2, check is active and it performed against SRFC-FUGR.



Keyword: BASIS
Title : SAP System Security

Main HR Authorization Object for Security

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Keyword: SAP HR
Title : Main HR Authorization Object for Security

Main HR Authorization Object for Security

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Keyword: SAP HR
Title : Main HR Authorization Object for Security

T r a n s l a t e to your language