---
title: SAP Data Loss Prevention, what to do?
description: How to avoid data leaks in SAP environment? What to keep into consideration when activating the SAP Data Loss Prevention mechanisms?
image: https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/Data%20Loss%20Prevention-Jun-14-2024-10-11-52-7434-AM.jpg
---

[linkedin](https://www.linkedin.com/company/292350?trk=vsrp_companies_res_name&trkInfo=VSRPsearchId%3A3373431891426179412478%2CVSRPtargetId%3A292350%2CVSRPcmpt%3Aprimary) [YouTube](https://www.youtube.com/c/AgleaSAPSecurity?sub_confirmation=1) [Twitter](https://twitter.com/AgleaItaly?lang=en)

[![Logo-Aglea-horsa-company](https://www.aglea.com/hubfs/Aglea/Aglea_November2018%20Theme/Images/Logo-Aglea-horsa-company.webp) ](https://www.aglea.com/en)

# SAP Data Loss Prevention, what to do?

# SAP Data Loss Prevention, what to do?

Posted by [Andrea Mazzolani (translation)](https://www.aglea.com/en/blog/author/andrea-mazzolani-translation) on Nov 11, 2022 12:00:00 AM

- [Tweet](https://twitter.com/share)

What does Data Loss Prevention mean?

![Data Loss Prevention](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/Data%20Loss%20Prevention-Jun-14-2024-10-11-52-7434-AM.jpg?width=492&name=Data%20Loss%20Prevention-Jun-14-2024-10-11-52-7434-AM.jpg)

 

It means to "put in place" all the possible actions to prevent non-authorized data leaks.

 

Data leak and data loss have multiple meanings. But what can you do in SAP?

Fuga di dati e perdita di dati hanno significati molteplici. Ma come è possibile fare in SAP?

## How to prevent and control data export in SAP?

Sadly, there isn't a unique tool or configuration to activate in SAP environments.

 

Instead, there are different solutions that can be used. Some paid and some readily available.

 

There are different areas to manage and control:

- The **data communication**, under different aspects. Server to Server or Client to Server
- The data **backup** or possible deposited files in the transit
- The **end point or client** protection
- The applicative **export** of data from SAP
- The data export at a **database level**

 

There are just a couple of examples to work on.

 

## SAP Security Audit Log

It's a functionality available in SAP ECC or SAP S/4HANA or on all ABAP based systems, that lets you trace a series of events, including the data export from SAP (in the latest releases)

 

Learn more on [how the SAP Security Audit Log works and how to configure it](https://www.aglea.com/en/blog/sap-security-audit-log-configuration)

 

## SAP Field Masking

In this case, thanks to this SAP paid add-on it's possible to activate two main functionalities:

 

- **Data Masking or Data Obfuscation** meaning, on an applicative level, therefore not at a data modification level in the database, the data are made non readable, for example with the use of asterisks ***
- **Data Logging** in this case it's possible to identify critical transactions to control in terms of accessed data and who accessed them

 

You can do the above for different channels (technologies) meaning:

- SAP GUI
- WebDynpro
- RFC/BAPI Web Service
- SAP UI5 FIORI

 

Learn more about [SAP Field Masking](https://www.aglea.com/en/blog/sap-field-masking) and how the UI Logging works

 

## SAP HANA Database

Data at the database level must also be audited too, by using the [SAP HANA](https://www.aglea.com/en/sap-security-hana), some aspects related to data security could be more explicit compared to other database, it's in fact possible to:

 

- All the connections should be configured in a secure way (therefore using encryption)
- You should **encrypt the data** inside the database and backup
- You should activate log specific audits to check what is happening in the system

 

Learn more on what you can immediately do to activate 4 [SAP HANA security](https://www.aglea.com/blog/sap-hana-security-4-suggerimenti-operativi) functionalities

## SAP RFC, communication protection and encryption

The connections towards SAP systems must be configured using encryption mechanisms to prevent possible data interceptions.

 

On different attack surfaces:

- Client -> Server ex. SAP GUI and SAP Application Server
- Server -> Server ex. between Application Server

 

The services exposed by SAP should be at least introduced, in this case the standard functionality called UCON (Unified Connectivity) could be helpful.

 

## Data export protection

There are different ways to export data from SAP. Here you can find the main ways to [export data from SAP](https://www.aglea.com/en/blog/come-esportare-dati-da-sap).

 

One of the aspects that may be further controlled is making sure that specific documents (ex. PLM but also others, financial and balance data) will be protected even after the export from SAP.

 

They should for instance answer the following questions:

- Is it possible to get notifications, for example in SIEM for every time data is exported from SAP
- Is it possible to make sure that the data exported in a non-authorized manner from SAP can't be used or encrypted?

 

What above said can be done by using a paid solution called SAP DAM ([Dynamic Authorization Management](https://www.aglea.com/blog/sap-dynamic-authorization-management)) and SAP EDRM by Nextlabs

 

## How to check if everything is configured correctly in SAP?

Once more it's not enough to just modify or do remediation projects or actions. You must activate a constant control procedure.

 

In this case two functionalities can be helpful inside SAP Solution Manager called:

- [SAP Solution Manager Configurator Validation](https://support.sap.com/en/alm/solution-manager/expert-portal/change-diagnostics/configuration-validation.html)
- SAP Solution Manager System Recommendations

Furthermore, it's possible to use other paid softwares like the [SAP Enterprise Threat Detection](https://www.aglea.com/blog/sap-cybersecurity-sap-enterprise-threat-detection-cosa-è).

 

 

 

 

 

 Topics: [SAP audit](https://www.aglea.com/en/blog/tag/sap-audit), [soar](https://www.aglea.com/en/blog/tag/soar), [sap etd](https://www.aglea.com/en/blog/tag/sap-etd), [sap siem](https://www.aglea.com/en/blog/tag/sap-siem), [sap hana](https://www.aglea.com/en/blog/tag/sap-hana), [data loss prevention](https://www.aglea.com/en/blog/tag/data-loss-prevention), [SAP DLP](https://www.aglea.com/en/blog/tag/sap-dlp), [rfc security](https://www.aglea.com/en/blog/tag/rfc-security)

### Subscribe Here!

### Blog Aglea, cosa puoi trovare?

Ogni mercoledì pubblichiamo articoli, interviste e documenti relativi alla security SAP.

Cosa puoi trovare:

- Suggerimenti su come mettere in sicurezza i sistemi SAP
- Come fare a … (How To)
- Checklist
- Gli errori comuni che spesso vengono fatti in ambito Security SAP
- Interviste con esperti del settore
- Chi è AGLEA quale è la nostra vision security SAP

### Recent Posts

### Post By Topic

- [SAP Security (12)](https://www.aglea.com/en/blog/tag/sap-security)
- [SAP GRC (11)](https://www.aglea.com/en/blog/tag/sap-grc)
- [pfcg (8)](https://www.aglea.com/en/blog/tag/pfcg)
- [gdpr (7)](https://www.aglea.com/en/blog/tag/gdpr)
- [SAP GDPR (5)](https://www.aglea.com/en/blog/tag/sap-gdpr)
- [Segregation of duties (5)](https://www.aglea.com/en/blog/tag/segregation-of-duties)
- [governance (5)](https://www.aglea.com/en/blog/tag/governance)
- [sod (5)](https://www.aglea.com/en/blog/tag/sod)
- [SAP ECC (4)](https://www.aglea.com/en/blog/tag/sap-ecc)
- [audit sap (4)](https://www.aglea.com/en/blog/tag/audit-sap)
- [auditing (4)](https://www.aglea.com/en/blog/tag/auditing)
- [sap consulenza security (4)](https://www.aglea.com/en/blog/tag/sap-consulenza-security)
- [sap password (4)](https://www.aglea.com/en/blog/tag/sap-password)
- [HANA (3)](https://www.aglea.com/en/blog/tag/hana)
- [SAP HR (3)](https://www.aglea.com/en/blog/tag/sap-hr)
- [UI logging (3)](https://www.aglea.com/en/blog/tag/ui-logging)
- [rfc security (3)](https://www.aglea.com/en/blog/tag/rfc-security)
- [sap cyber security (3)](https://www.aglea.com/en/blog/tag/sap-cyber-security)
- [sap hana (3)](https://www.aglea.com/en/blog/tag/sap-hana)
- [sap_all (3)](https://www.aglea.com/en/blog/tag/sap_all)
- [security audit log (3)](https://www.aglea.com/en/blog/tag/security-audit-log)
- [sicurezza sap (3)](https://www.aglea.com/en/blog/tag/sicurezza-sap)
- [su53 (3)](https://www.aglea.com/en/blog/tag/su53)
- [HANA Security (2)](https://www.aglea.com/en/blog/tag/hana-security)
- [ISO (2)](https://www.aglea.com/en/blog/tag/iso)
- [Profiles (2)](https://www.aglea.com/en/blog/tag/profiles)
- [SAP FIORI Security (2)](https://www.aglea.com/en/blog/tag/sap-fiori-security)
- [SAP audit (2)](https://www.aglea.com/en/blog/tag/sap-audit)
- [Secure programming (2)](https://www.aglea.com/en/blog/tag/secure-programming)
- [UCON (2)](https://www.aglea.com/en/blog/tag/ucon)
- [UI Masking (2)](https://www.aglea.com/en/blog/tag/ui-masking)
- [access management (2)](https://www.aglea.com/en/blog/tag/access-management)
- [authorization concept (2)](https://www.aglea.com/en/blog/tag/authorization-concept)
- [autorizzazioni sap (2)](https://www.aglea.com/en/blog/tag/autorizzazioni-sap)
- [consulenti (2)](https://www.aglea.com/en/blog/tag/consulenti)
- [corso (2)](https://www.aglea.com/en/blog/tag/corso)
- [e-learning (2)](https://www.aglea.com/en/blog/tag/e-learning)
- [password policy (2)](https://www.aglea.com/en/blog/tag/password-policy)
- [patch (2)](https://www.aglea.com/en/blog/tag/patch)
- [programmazione sicura (2)](https://www.aglea.com/en/blog/tag/programmazione-sicura)
- [quality (2)](https://www.aglea.com/en/blog/tag/quality)
- [rfc (2)](https://www.aglea.com/en/blog/tag/rfc)
- [ruoli (2)](https://www.aglea.com/en/blog/tag/ruoli)
- [sap access control (2)](https://www.aglea.com/en/blog/tag/sap-access-control)
- [sap custom (2)](https://www.aglea.com/en/blog/tag/sap-custom)
- [sap etd (2)](https://www.aglea.com/en/blog/tag/sap-etd)
- [sap gui (2)](https://www.aglea.com/en/blog/tag/sap-gui)
- [sap query (2)](https://www.aglea.com/en/blog/tag/sap-query)
- [sap security guidelines (2)](https://www.aglea.com/en/blog/tag/sap-security-guidelines)
- [sap siem (2)](https://www.aglea.com/en/blog/tag/sap-siem)
- [sap standard role (2)](https://www.aglea.com/en/blog/tag/sap-standard-role)
- [sap super user (2)](https://www.aglea.com/en/blog/tag/sap-super-user)
- [sap vulnerability (2)](https://www.aglea.com/en/blog/tag/sap-vulnerability)
- [se16 (2)](https://www.aglea.com/en/blog/tag/se16)
- [security ams (2)](https://www.aglea.com/en/blog/tag/security-ams)
- [siem (2)](https://www.aglea.com/en/blog/tag/siem)
- [soar (2)](https://www.aglea.com/en/blog/tag/soar)
- [supporto sap ams (2)](https://www.aglea.com/en/blog/tag/supporto-sap-ams)
- [test system (2)](https://www.aglea.com/en/blog/tag/test-system)
- [threat detection (2)](https://www.aglea.com/en/blog/tag/threat-detection)
- [upgrade (2)](https://www.aglea.com/en/blog/tag/upgrade)
- [312 (1)](https://www.aglea.com/en/blog/tag/312)
- [ABAP (1)](https://www.aglea.com/en/blog/tag/abap)
- [AI (1)](https://www.aglea.com/en/blog/tag/ai)
- [CVA (1)](https://www.aglea.com/en/blog/tag/cva)
- [DPO (1)](https://www.aglea.com/en/blog/tag/dpo)
- [FIORI Security (1)](https://www.aglea.com/en/blog/tag/fiori-security)
- [HANA Roles (1)](https://www.aglea.com/en/blog/tag/hana-roles)
- [PFCG SAP transaction (1)](https://www.aglea.com/en/blog/tag/pfcg-sap-transaction)
- [SAP Cloud Security (1)](https://www.aglea.com/en/blog/tag/sap-cloud-security)
- [SAP Consulting (1)](https://www.aglea.com/en/blog/tag/sap-consulting)
- [SAP DLP (1)](https://www.aglea.com/en/blog/tag/sap-dlp)
- [SAP Fraud Management (1)](https://www.aglea.com/en/blog/tag/sap-fraud-management)
- [SAP IDM (1)](https://www.aglea.com/en/blog/tag/sap-idm)
- [SAP LOG (1)](https://www.aglea.com/en/blog/tag/sap-log)
- [SAP Security Documentation (1)](https://www.aglea.com/en/blog/tag/sap-security-documentation)
- [SAP Table (1)](https://www.aglea.com/en/blog/tag/sap-table)
- [SAP Transactions (1)](https://www.aglea.com/en/blog/tag/sap-transactions)
- [SPOOL (1)](https://www.aglea.com/en/blog/tag/spool)
- [Security Analyzer (1)](https://www.aglea.com/en/blog/tag/security-analyzer)
- [Statistiche security SAP (1)](https://www.aglea.com/en/blog/tag/statistiche-security-sap)
- [Trace autorizzazioni SAP (1)](https://www.aglea.com/en/blog/tag/trace-autorizzazioni-sap)
- [User Access Management (1)](https://www.aglea.com/en/blog/tag/user-access-management)
- [aglea (1)](https://www.aglea.com/en/blog/tag/aglea)
- [audit (1)](https://www.aglea.com/en/blog/tag/audit)
- [authorization model (1)](https://www.aglea.com/en/blog/tag/authorization-model)
- [biometric (1)](https://www.aglea.com/en/blog/tag/biometric)
- [chatGPT (1)](https://www.aglea.com/en/blog/tag/chatgpt)
- [codice sicuro SAP (1)](https://www.aglea.com/en/blog/tag/codice-sicuro-sap)
- [consulenti sap security (1)](https://www.aglea.com/en/blog/tag/consulenti-sap-security)
- [consulenza sap security (1)](https://www.aglea.com/en/blog/tag/consulenza-sap-security)
- [crittografia SAP (1)](https://www.aglea.com/en/blog/tag/crittografia-sap)
- [custom transactions (1)](https://www.aglea.com/en/blog/tag/custom-transactions)
- [cyber security (1)](https://www.aglea.com/en/blog/tag/cyber-security)
- [data loss prevention (1)](https://www.aglea.com/en/blog/tag/data-loss-prevention)
- [data privacy (1)](https://www.aglea.com/en/blog/tag/data-privacy)
- [documentazione sap security (1)](https://www.aglea.com/en/blog/tag/documentazione-sap-security)
- [emergency users (1)](https://www.aglea.com/en/blog/tag/emergency-users)
- [gxp (1)](https://www.aglea.com/en/blog/tag/gxp)
- [identity management system (1)](https://www.aglea.com/en/blog/tag/identity-management-system)
- [idm (1)](https://www.aglea.com/en/blog/tag/idm)
- [log sap (1)](https://www.aglea.com/en/blog/tag/log-sap)
- [mail security sap (1)](https://www.aglea.com/en/blog/tag/mail-security-sap)
- [microsoft (1)](https://www.aglea.com/en/blog/tag/microsoft)
- [parameter sap (1)](https://www.aglea.com/en/blog/tag/parameter-sap)
- [processi security (1)](https://www.aglea.com/en/blog/tag/processi-security)
- [profili (1)](https://www.aglea.com/en/blog/tag/profili)
- [profili sap (1)](https://www.aglea.com/en/blog/tag/profili-sap)
- [progetti security sap (1)](https://www.aglea.com/en/blog/tag/progetti-security-sap)
- [quotazione borsa (1)](https://www.aglea.com/en/blog/tag/quotazione-borsa)
- [rfc destination (1)](https://www.aglea.com/en/blog/tag/rfc-destination)
- [role translation (1)](https://www.aglea.com/en/blog/tag/role-translation)
- [s_tabu_dis (1)](https://www.aglea.com/en/blog/tag/s_tabu_dis)
- [s_tabu_nam (1)](https://www.aglea.com/en/blog/tag/s_tabu_nam)
- [s_tabu_rfc (1)](https://www.aglea.com/en/blog/tag/s_tabu_rfc)
- [sap FIORI (1)](https://www.aglea.com/en/blog/tag/sap-fiori)
- [sap btp (1)](https://www.aglea.com/en/blog/tag/sap-btp)
- [sap data masking (1)](https://www.aglea.com/en/blog/tag/sap-data-masking)
- [sap dati personali (1)](https://www.aglea.com/en/blog/tag/sap-dati-personali)
- [sap developer (1)](https://www.aglea.com/en/blog/tag/sap-developer)
- [sap earlywatch (1)](https://www.aglea.com/en/blog/tag/sap-earlywatch)
- [sap grc 12 (1)](https://www.aglea.com/en/blog/tag/sap-grc-12)
- [sap grc tables (1)](https://www.aglea.com/en/blog/tag/sap-grc-tables)
- [sap gui history (1)](https://www.aglea.com/en/blog/tag/sap-gui-history)
- [sap gui security (1)](https://www.aglea.com/en/blog/tag/sap-gui-security)
- [sap gxp compliance (1)](https://www.aglea.com/en/blog/tag/sap-gxp-compliance)
- [sap ilm gdpr (1)](https://www.aglea.com/en/blog/tag/sap-ilm-gdpr)
- [sap license auditing (1)](https://www.aglea.com/en/blog/tag/sap-license-auditing)
- [sap logon (1)](https://www.aglea.com/en/blog/tag/sap-logon)
- [sap patch (1)](https://www.aglea.com/en/blog/tag/sap-patch)
- [sap security blog (1)](https://www.aglea.com/en/blog/tag/sap-security-blog)
- [sap security teal (1)](https://www.aglea.com/en/blog/tag/sap-security-teal)
- [sap sos (1)](https://www.aglea.com/en/blog/tag/sap-sos)
- [sap splunk (1)](https://www.aglea.com/en/blog/tag/sap-splunk)
- [sap sso (1)](https://www.aglea.com/en/blog/tag/sap-sso)
- [sap tabelle custom (1)](https://www.aglea.com/en/blog/tag/sap-tabelle-custom)
- [sap tdms (1)](https://www.aglea.com/en/blog/tag/sap-tdms)
- [sap_all_only_view (1)](https://www.aglea.com/en/blog/tag/sap_all_only_view)
- [se16n (1)](https://www.aglea.com/en/blog/tag/se16n)
- [secpol (1)](https://www.aglea.com/en/blog/tag/secpol)
- [secure coding sap (1)](https://www.aglea.com/en/blog/tag/secure-coding-sap)
- [secure operation map (1)](https://www.aglea.com/en/blog/tag/secure-operation-map)
- [security awareness (1)](https://www.aglea.com/en/blog/tag/security-awareness)
- [security bridge (1)](https://www.aglea.com/en/blog/tag/security-bridge)
- [sentinel (1)](https://www.aglea.com/en/blog/tag/sentinel)
- [sicurezza codice ABAP (1)](https://www.aglea.com/en/blog/tag/sicurezza-codice-abap)
- [sicurezza dei dati sap (1)](https://www.aglea.com/en/blog/tag/sicurezza-dei-dati-sap)
- [slaw (1)](https://www.aglea.com/en/blog/tag/slaw)
- [social engineering (1)](https://www.aglea.com/en/blog/tag/social-engineering)
- [sost (1)](https://www.aglea.com/en/blog/tag/sost)
- [sql (1)](https://www.aglea.com/en/blog/tag/sql)
- [su25 (1)](https://www.aglea.com/en/blog/tag/su25)
- [super utenti sap (1)](https://www.aglea.com/en/blog/tag/super-utenti-sap)
- [system users (1)](https://www.aglea.com/en/blog/tag/system-users)
- [tabelle (1)](https://www.aglea.com/en/blog/tag/tabelle)
- [tabelle SAP grc access control (1)](https://www.aglea.com/en/blog/tag/tabelle-sap-grc-access-control)
- [ticket management system (1)](https://www.aglea.com/en/blog/tag/ticket-management-system)
- [training (1)](https://www.aglea.com/en/blog/tag/training)
- [transazioni sap (1)](https://www.aglea.com/en/blog/tag/transazioni-sap)
- [userid (1)](https://www.aglea.com/en/blog/tag/userid)
- [usmm (1)](https://www.aglea.com/en/blog/tag/usmm)
- [ust04 (1)](https://www.aglea.com/en/blog/tag/ust04)
- [zero trust security (1)](https://www.aglea.com/en/blog/tag/zero-trust-security)

[See all](https://www.aglea.com/en/blog/data-loss-prevention-in-sap-cosa-fare#)

## [SAP Security Blog AGLEA RSS Feed](https://www.aglea.com/blog/rss.xml)

Aglea s.r.l. P. IVA: IT 03868780960 - 2026  | Copy | [Note legali](https://cdn2.hubspot.net/hubfs/4422290/Aglea_November2018%20Theme/Pdfs/Privacy-policy-AGLEA.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrea Mazzolani (translation)",
    "url" : "https://www.aglea.com/en/blog/author/andrea-mazzolani-translation"
  },
  "dateModified" : "2024-06-14T10:13:20.263Z",
  "datePublished" : "2022-11-10T23:00:00.000Z",
  "headline" : "SAP Data Loss Prevention, what to do?",
  "image" : [ "https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/Data%20Loss%20Prevention-Jun-14-2024-10-11-52-7434-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.aglea.com/en/blog/data-loss-prevention-in-sap-cosa-fare",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Horsa S.p.A."
  }
}
```