Control Objectives: SAP Application Security

No control objectives match the current filters.
Database Auditing
SNow
Classification: DetectiveState: Published
A dedicated third party application (Imperva) monitoring the database layer for non-legitimate activities performed by high privilege accounts (i.e. DB admins). Outsourcing high privilege access authorization to externals requires a detective control at least. (ICFR, GDPR).
Identify Security and Data Privacy Job Roles
SNow
Classification: PreventiveState: Published
Security relevant roles are identified and got a security specific training. The system documentation must cover the security-related functions of the system (e. g. access control, authorization management, logging, encryption). Documented Security Functions (e.g. SAP Security Admin) to ensure that
SAP Authorization Concept Verification
SNow
Classification: PreventiveState: Published
An external and Roche-independent security assessment for the authorization concept is required to prove that access restrictions work as intended and privilege escalation is not possible. Mitigate all potential findings.
SAP-specific Access Controls for Externals (Contractors & Business Partners)
SNow
Classification: PreventiveState: Published
Access to confidential, sensitive and business critical data is excluded (without additional mitigating controls) via dedicated restricted roles for external business partners. The access concept has been assessed independently and profen to be reliable. External, i.e. non-Roche-employees have separ
SAP-specific Application Firewall
SNow
Classification: PreventiveState: Published
Connections to system via RFC will be restricted using UCON functionality. Application Firewall UCON and/or Dedicated Server Firewall to reduce the attack surface for potential attackers.
SAP-specific High Privileged Access Management
SNow
Classification: PreventiveState: Published
High privilege access to the system and its data is governed by the Roche Standard solutions SAP Fire Fighter / SAP Emergency Users. Dedicated solutions to protect access to high privilege accounts like admins. To prevent full system compromise through breached high privilege accounts.
SAP-specific Malware Protection
SNow
Classification: PreventiveState: Published
Dedicated Anti-Virus may be required. If many different file formats are uploaded from a multitude of non-managed devices.
SAP-specific Roles for Externals (Contractors and External Business Partners)
SNow
Classification: PreventiveState: Published
To protect Roche's assets and to comply with legal requirements like data privacy laws, an authorization concept with data-access restrictions reflecting the contractual & location-based attributes of a user is to be established.  In cases where an access restriction is not possible (e.g. due to th
SAP-specific Secure Code Development
SNow
Classification: PreventiveState: Published
Three different controls are available based on the need, SAP Code Inspector for SL2, Self-developped enhanced solution eSCR for SL3 or third party solution (Onapsis) for SL4. Self-developped SAP code or code developped by a third party vendor poses a multitude of potential risks like backdoors, har
SAP-specific Security Compliance Checks
SNow
Classification: PreventiveState: Published
According to Roche’s internal regulation, GxP relevant systems are periodically reviewed by an independent auditor. Perform the Roche SAP security standard compliance check and mitigate all portential non compliance of medium and high criticality before go live and regular compliance checks need to
SAP-specific Security Monitoring
SNow
Classification: DetectiveState: Published
A dedicated third party application (Onapsis) monitoring the SAP application layer for ongoing attacks. Data breach notifications within the specified time range cannot rely on a monthly manual review of the audit logs. (GDPR)
SAP-specific Standardized Permission Management
SNow
Classification: PreventiveState: Published
Usage of Globally developed BASIS roles restricting Access to the Application Layer (no access to business transactions). Standardized and harmonized high privilege authorization roles. Balanced approach between access restriction and globalized standard roles for administrator accounts, for instanc
Graph Explorer