Fabio Mambretti

Fabio Mambretti

Recent Posts

Who are the owners of the Governance and Security area?

Posted by Fabio Mambretti on Apr 1, 2022 8:15:00 AM

Why is that all the decisions taken following authorization assignments requests fall under the IT department?

Read More

Topics: Segregation of duties, sap access control

SAP Field Masking

Posted by Fabio Mambretti on Mar 25, 2022 8:15:00 AM

For reasons of internal policies or regulations it may be necessary to make some data inside of SAP anonymous. There are many ways to do this. The first elements we need to consider are:

  • Which data needs to be anonymous
  • In which systems/environments
  • Which users to authorize
  • How to monitor the compliance of the created segregation
Read More

Topics: SAP GDPR, UI Masking, UI logging

SAP Upgrades. Authorizations are always neglected, why?

Posted by Fabio Mambretti on Mar 18, 2022 8:15:00 AM

 

SAP updates are frequent. SAP releases feature updates to its products but also new features or patch security.

 

Read More

Topics: patch, upgrade, su25, pfcg, HANA, S4/HANA

How does Segregation of Duties help protect your company data?

Posted by Fabio Mambretti on Mar 4, 2022 8:15:00 AM

How does segregation of duties help protect your company data?

 

Read More

Topics: SAP Security, governance, ISO, sod

How to export data from SAP?

Posted by Fabio Mambretti on Feb 25, 2022 8:30:00 AM

Here's why it's important to check how data is exported and by who it's spread

How do you monitor the data exported from SAP ECC?

 

Many users must be formally authorized in order to do that as part of their job. It’s however of great importance, especially in a GDPR framework, to monitor how and who exports data in a non-authorized way from the SAP system.

How do you do that? Let’s see some paid methods and others included in the SAP business suite

Read More

Topics: SAP Security, SAP ECC, SAP HR, gdpr, UI Masking, security audit log, UI logging

How do you surpass the 312 profiles limit in SAP?

Posted by Fabio Mambretti on Feb 11, 2022 8:15:00 AM

In SAP there is/was a limit on the number of profiles that can be assigned to a user. Historically this limit of 300 and then 312 has been kept to stop the assignment of too many authorizations to users.

 

 

Does this limit persist?

Read More

Topics: SAP Security, 312, profili, ust04, SAP ECC, pfcg, S4/HANA

5 Reasons (SAP Security) to have an updated test system

Posted by Fabio Mambretti on Feb 4, 2022 8:15:00 AM

A classic SAP landscape is made of three distinct machines:

 

  • Develop environment
  • Test or quality environment
  • Production environment

 

It's possible to define more environments, for example, pre-production or other clients in the aforementioned systems.

 

Why are test systems essential for SAP security, and why do they need to be managed in such a way?

Read More

Topics: gdpr, quality, test system, audit sap, sap security guidelines

Transactions for SAP Roles (and Security Manager)

Posted by Fabio Mambretti on Jan 14, 2022 8:15:00 AM

Which SAP Security transactions should you have in your favorites?

 

 

Transactions for managing SAP Roles, for Profile generator configuration, for SAP auditing. Some of them are useful in certain moments, some of them daily. Also keep in mind in some cases is suggested to be used though a firefighter or your emergency users.

Read More

Topics: sap cyber security, SAP Consulting, SAP Transactions

SAP GUI HISTORY

Posted by Fabio Mambretti on Dec 24, 2021 8:15:00 AM

We're talking about a program, available on many platforms (Windows or Unix like), that allows one to connect to SAP systems in an interactive way. The acronym SAP GUI stands for Graphical User Interface

 

If we want to be more precise it is the client that makes it possible to connect to SAP systems based on the ABAP technology. How do you make the most of the SAP GUI History function?

Read More

Topics: sap gui security, sap gui, sap gui history

Yes Subscribe!

Blog Aglea, what you could find out?

Every Friday a new post, interview or content related to SAP Security.

  • Tips on how to design SAP Security
  • How to
  • Checklist
  • Common error and pitfall on security SAP
  • Interview with experts
  • Who we are and Aglea vision on SAP Security

Recent Posts

Post By Topic

See all