| |
SAP Blogs
Security
Lessons learned from SAP GRC projects
SAP's Governance Risk and Compliance (GRC) solution has so much to offer that I can understand why some SAP customers might wonder if it is "overkill" or "too much for us." However, after several recent GRC projects, I am more convinced than ever that it has something for every SAP installation, large or small, public or privately held. I'll share some of my experiences, and you can see what you think.
Gretchen Y Lindquist
in Governance, Risk and Compliance, Business Process Expert, Identity Management, Security [Jan. 30, 2012 09:06 AM
| 5 Comments
| Permalink]
Assert4Soa: Advanced Security Service cERTificates for SOA
The Assert4Soa project aims at filling the gap between the need for lighter-weight, automatically processable security certificates and the current state of the practice. In order to do so, the Assert4Soa consortium is committed to producing novel techniques and tools for expressing, assessing and certifying security properties for service-oriented applications, composed of distributed software services that may dynamically be selected, assembled and replaced, and running within complex and continuously evolving software ecosystems.
Antonino SABETTA
in Service-Oriented Architecture, Security, SAP Research [Jan. 03, 2012 04:03 AM
| 2 Comments
| Permalink]
How to replace the SSL server Standard PSE?
Recently CAs around the world decided to sign certificate requests with key length equal to 2048 bits. If you have a PSE with key length equal to 1024 bits, then you cannot create such certificate request (with 2048 bits). The solution is replacing the SSL PSE and then adjusts the Key Length property.
Cristiano Hansen
in ABAP, Security [Dec. 25, 2011 11:03 PM
| 0 Comments
| Permalink]
SAP GRC: The 3 stages of Post-GRC Implementation Syndrome
So youre on a GRC (Governance, Risk and Compliance) project and your client turns to you and asks, Ok, so now were implemented, whats the best way to tackle these issues? Weve all been there. Staring at a client, wondering what is the best possible way to answer that question and replying with the most infamous line a consultant uses:
. Well, it depends
Peter Cortes
in Governance, Risk and Compliance, Professional Services, SAP Developer Network, Security [Sep. 27, 2011 05:54 PM
| 0 Comments
| Permalink]
WSNSCM'11 Workshop
We proudly organised the WSNSCM workshop related to the integration of Wireless Sensor Networks into Supply Chain Management systems. This workshop has been held jointly with the NetWare conference, held in Saint Laurent du Var, France, from the 21st to the 27th of August(http://www.iaria.org/conferences2011/WSNSCM.html).
Laurent GOMEZ
in Security, Travel and Logistics Services [Sep. 19, 2011 11:37 AM
| 0 Comments
| Permalink]
Thursday at SAP TechEd
Thursday is usually a peak day at SAP TechEd, and this year was no exception. My agenda included a hands on session, an Expert Networking session, leading an Influence Council Update session, and more. Read on for the highlights.
Gretchen Y Lindquist
in SAP TechEd, Security [Sep. 16, 2011 07:00 AM
| 0 Comments
| Permalink]
Wonderful SAP GRC Wednesday at SAP TechEd 2011
Every year it seems to get more difficult to pace myself during my week at SAP TechEd. Along about Wednesday afternoon, I take a deep breath and remember that, despite that exhilarating feeling from attempting to drink from the fire hose for several days, there is still a lot of learning and networking ahead. Nevertheless, I pushed myself full throttle through a full day of SAP security and GRC learning, and a lot more. Read on for my take on Wednesday at SAP TechEd.
Gretchen Y Lindquist
in Governance, Risk and Compliance, SAP TechEd, Security [Sep. 15, 2011 12:58 AM
| 4 Comments
| Permalink]
Around the SAP solution map: HANA and more on Tuesday at SAPTechEd 2011
Today, Tuesday, was the first official day of SAP TechEd, and my agenda was, as usual, jam packed with learning and networking opportunities, on a wide variety of SAP solutions. Fasten your seat belt and hang on, then read on for the wild ride!
Gretchen Y Lindquist
in SAP TechEd, Security, SAP Network TV [Sep. 14, 2011 08:41 AM
| 0 Comments
| Permalink]
Automatic User Review (Deactivation and Deletion)
Very generic question - How to automate user review, deactivation and deletion process in older versions (other than Netweaver)
Till the time I am very much confused and did a manual work on user Audits and reviews. Whenever I want to get the user list (Active) I used to go to the report and prepare an excel sheet and send the list to the concern person to lock, deactivate and delete the user ids in landscape. Continueous user review is one of the key point in every Audit, where there be some misses.
Finally I found a solution to automate the review and action part. For recent releases and 3rd party tools(which supported by SAP) User review, validation is not a big deal to handle automatically. But many of the customers still running their landscapes on older versions. SAP recommends to run each and every landscape as latest but might not be possible at a time.
At least till upgrade I/We can use the below process to automate the user review process. I have configured these process in 2 different methods (One is for temp users second is for all Non-Temp users).
Nick Loy
in Application Lifecycle Management, Governance, Risk and Compliance, Idea Place, Security [Sep. 12, 2011 12:18 AM
| 0 Comments
| Permalink]
Innovation in GRC: Friend or Foe when it comes to Risk Management and Efficiency?
The mere topic of innovation seems to have a watered down meaning in todays economy. When asked, everyone says its important but then most businesses funding priorities dont reflect that thought. Companies want innovation. They want a better way of doing business; they want operations streamlined, efficient, and compliant, along with any other buzz word that comes to mind. However, seldom do you hear about businesses taking a proactive approach when it comes to meeting these demands. Decision makers tell managers to be Lean and cut costs and oh, by the way, dont forget to stay innovative and keep our competitive edge.
Peter Cortes
in Governance, Risk and Compliance, SAP Developer Network, Security, Standards [Jul. 25, 2011 09:36 PM
| 0 Comments
| Permalink]
RESCUEIT at Seagital
SAP Research presented the RESCUEIT prototype at the Seagital Conference. Seagital is gathering international maritime professionals and innovative software companies.
RESCUEIT is the first French German research project, funded by ANR and BMBF, in the scope of the secure supply chain management system. 8 academic and industrial partners are involved in RESCUEIT, together with end-users such as REWE, Kuhne and Nagel, Dr Oectker, Groupe Casino, Baam, Eisbar.
Laurent GOMEZ
in ERP, Security, Travel and Logistics Services [Jul. 07, 2011 11:28 AM
| 8 Comments
| Permalink]
Relax - the 1980's all over again - with Mobile Devices
It's the 1980's all over again except end users are deploying mobile handheld solutions instead of PC's.
Workers are buying their own equipment and bringing it to work with them. Professionals in IT need to secure, control, and monitor the wild collection of BlackBerry, iPAD, iPOD, Android, Smartphones, PlayBooks and Tablets. Consumers are bringing them to work, and it's out of control. SAP Sybase Afaria to the rescue ! Whether it's in the office, the store, the warehouse, or on the road, user's want instant access to apps and information.
Colin Haig
in Mobile, Retail, Security, Software Support and Maintenance, Wholesale Distribution [Jun. 16, 2011 09:40 AM
| 2 Comments
| Permalink]
1 to 50 of 215
Next
|
Subscribe to Security Blogs
RSS:
Recent Security Discussions
Set parameter clockskew
Posted on Feb. 10, 2012 08:01 AM
by Dimitar Mihaylov
Hi,
The clock skew tolerance is fixed to 5 minutes and cannot be changed in the...
Awesome Blog!
Posted on Feb. 06, 2012 09:03 AM
by suvonkar
Hi Gretchen,
Lovely blog. It’s great to know about your experience with vario...
Access Control and SAP GRC
Posted on Feb. 06, 2012 02:19 AM
by Kunal Kant
Yes agree with Gretchen here that post the integration of GRC AC & PC in 10.0 th...
GRC makes it easy to communicate security
Posted on Feb. 05, 2012 08:39 PM
by Frank Koehntopp
Hi Gretchen,
great blog, thank you. GRC AC projects are a great way to get cu...
Access Control and SAP GRC
Posted on Jan. 31, 2012 07:58 AM
by Gretchen Y Lindquist
Norman,
So far I have just worked on Access Control, but I look forward to futu...
Access Control and SAP GRC
Posted on Jan. 31, 2012 07:36 AM
by Norman Marks
Gretchen, thanks for sharing your great experience with clients. Has that extend...
Not working
Posted on Jan. 12, 2012 01:39 AM
by K.Ranft
Hi,
i've changed the XML file and i've added a folder with the custom error mes...
great work
Posted on Jan. 09, 2012 09:27 AM
by Antonino SABETTA
Thanks Gabriel for your comment.
(I tried to reply earlier to your comment, b...
great work
Posted on Jan. 04, 2012 06:36 AM
by Gabriel SERME
Hi, thanks to let us know the status of the project. It seems to progress.
A...
No switch to HTTPS....
Posted on Dec. 29, 2011 12:19 AM
by Olivier CHRETIEN
Hello Cristiano,
Then there is a miracle on my ECC6 EHP4 system using Web Dis...
Keep the blogs coming
Posted on Dec. 28, 2011 07:23 AM
by Cristiano Hansen
Olá Tobias.
Obrigado for your words. I intend to show typical scenarios of us...
No switch to HTTPS....
Posted on Dec. 28, 2011 07:21 AM
by Cristiano Hansen
Salut Olivier,
I am sorry, but the assumption that both parameters can preven...
Keep the blogs coming
Posted on Dec. 28, 2011 05:59 AM
by Tobias Hofmann
SAP Web Dispatcher is one of the solutions that help you run your infrastructure...
No switch to HTTPS....
Posted on Dec. 28, 2011 02:33 AM
by Olivier CHRETIEN
Hello,
To avoid the warning message "No switch to HTTPS..." on the login page...
Real life
Posted on Dec. 26, 2011 07:41 AM
by Cristiano Hansen
Salut Olivier,
I intend to write another blog about this different scenario. ...
|
|