Day One
Reviewing the basics
- System Parameters
- Key Security Settings
- Most Critical Basis and Security Risks
SAP System Settings
- Multiple Logons
- Single Sign-on
- Database & Operating System Parameters
Advanced SAP Basis Security
- Securing direct access to tables
- Securing access to ABAP programs
- Controlling administrator access
- Central User Administration (CUA) considerations
- Protecting security-critical objects and tables
Controlling Non-Dialog User Types
- System users
- Communication users
- Service Users
- Reference Users
Special Considerations
- Defining the Superuser to replace SAP*
- Global deactivation of authorization objects
- Remote Function Calls (RFC)
- TMS Trusted Services
- Virus Protection
- SAP GUI Integrity Checks
Day Two
SAP Authentication Issues
- Secure Network Communications (SNC)
- X.509 Client Certificates
- SAP Logon Tickets
- Pluggable Authentication Services
Netweaver Security
- Network security for the SAP Web AS ABAP
- Secure Store & Forward (SSF)
- Digital Signatures & Protecting Keys
Advanced auditing of SAP customizations
- Reviewing ABAP code
- Including custom tables in change document reports
Advanced SAP Change & Transport System (CTS)
- TMS QA Approval Procedure
- Defining Approval Steps
- Tips for reconciling to change request systems
- Using SE03 Transport Organizer Tools
Batch Input
- Protecting Batch Input Sessions
- Protecting the SAPconnect RFC User
- Controlling List Downloads
- Internet Graphics List Security
Analyzing SAP tables
- Key configuration tables
- Using the SQ01 Query Builder
- Data access with ACL / IDEA
|