At first glance, the structure of the individual level doesn’t suggest any fixed dependencies. Apart from the fact that on each level e.g. "Environment" the associated ranges, subject, activities are listed. The basis is the environment with the areas:
- Network Security
- Operating System & Database Security
- Client Security
- Security Hardening
- Secure SAP Code
- Security Monitoring & Forensic
This level is largely focused on the standard SAP product and the installed Add-ons. The SecurityBridge platform for SAP, covers the three thematic blocks and includes even more areas from the following levels.
This level also deals with the SAP standard product, but from a different perspective. Here, the areas are:
- User & Identity Management
- Authentication & Single Sign-on
- Roles & Authorization
- Custom Code Security
All these areas are determined by the customer, the environment and the intended use.
This is about the process and actions that are performed within the SAP system. These must comply with certain standards to prevent access to personal data (GDPR) or fraud. Also, legal frameworks must be complied with. The following areas are included:
- Regulatory Process & Compliance
- Data Privacy & Protection
- Audit & Fraud Management
As the name suggests, this is about organizational measures such as risk assessment in Enterprise Risk Management (ERM), as well as awareness training for users, etc. The areas mentioned can certainly only be understood as incomplete examples:
- Awareness
- Security Governance
- Risk Management