Interfaces a major concern for SAP S4/HANA transformations

S4HANA Migration Project

Key Takeaways

  • Enable security by design. An S/4 project is often classified as a milestone to ensure lessons learned from the past are actually enforced, bottom-up. Interfaces that ran insecure for many years can now be identified and remediated.
  • Housekeeping. The number of communication channels across your landscape may have become polluted over many years. RFC destinations no longer responding or not in use should be decommissioned
  • Review your interface authorizations. Often we identify that communication channels use dialog users, or systems users have privileged access rights. As part of a transformation project, it is key to reduce the attack surface to an absolute minimum.

Interfaces a major concern for S4/HANA transformations

A wave of progressive technology developments such as cloud, social media, mobility and in-memory computing have positively impacted business processes, organizational workflows, business models and have provided innovations that have enriched capabilities to the overall business strategy. This technological revolution is increasing the demand on IT organizations, but its effects are not limited to IT. Leading German software technology company, SAP, has responded to its customer demands by majorly enhancing the SAP Business Suite, now powered by S4/HANA. Existing SAP customers running e.g. R/3 benefit considerably from upgrading to SAP S/4HANA.

What is SAP S/4HANA?

SAP S4/HANA is the latest generation of SAP NetWeaver ABAP/JAVA systems based on the SAP HANA database, and the term database should really be considered an understatement. It’s characterized by in-memory computing, streamlined transactions, a better user experience, combined with light-speed data processing and new functionality. Customers combine these new technologies, with strategic insights to unlock new opportunities, evolve business processes, or solve previously intractable challenges.

S4/HANA: Well prepared, winning the game

Before unleashing the power of SAP S4/HANA, customers already running SAP need to perform an upgrade of their SAP NetWeaver installation, unless deciding on a green- or brownfield implementation. Two-thirds of an SAP S4/HANA upgrade, a so-called migration project consists of “Preparation“.

S4HANA Project flow
S4HANA Project

The prerequisite for an effective S4/HANA migration phase is a clean and well-prepared environment. For “brown-field“ migration approaches in particular, this is a challenge, as they have been formed over many years. Getting insight is key. Customers therefore need to create a detailed understanding of what is used today, and what is ideal for the future system architecture and operations, before shedding unnecessary weight.

S/4HANA: SAP Interfaces

In addition to analyzing the business processes, and customers’ codebase, understanding the SAP interfaces is crucial. Most critical business transactions are performed by machine-to-machine connections. In preparing for S4/HANA upgrades, the IT-Team needs to answer the following questions:

  • Which interfaces exist, and which systems are connected? (SAP, non-SAP)
  • Which interfaces are still in use? What is their business purpose, and which data is being transferred?
  • Is the communication State of the Art secured according to internal or external regulations?

For organizations maintaining a complex integration landscape, running multiple system lines for distinct SAP modules such as  ERP, SRM, CRM and HCM, answering these questions isn’t easy.

IT-experts have to work through a list of existing RFC connections, analyzing their target and the distinct business purpose. Digging deeper to the next level will require technical analysis of data in transfer. Key questions would be: Is the connection still in use, and how frequently is it used? Helpful to know is: which business data is exchanged and which remote functions and user credentials are used? Gathering and analyzing this information is a time consuming and extensive task, involving mainly manual effort.

S/4HANA: Find the answers that you are looking for

Based on our customers’ feedback we realized that the SecurityBridge Interface Traffic Monitor provides the needed answers and allows our customers to maintain interface governance before and also after the SAP S4/HANA transformation project.
The SecurityBridge Interface Traffic Monitor combines all key requirements in one view without additional configuration.

  • Transparent graphical overview of all systems (SAP and non-SAP) and all connections
  • RFC traffic statistics for all connections and communications
  • Detailed technical description of all calls

You may also like this post

June 18, 2020
#rfc, #sapsecurity
Latest addition to the SecurityBridge suite is a fully integrated interface monitor, which visualizes RFC interface connectivity across your SAP landscape. Through a bird’s eye view security critical traffic and vulnerable interfaces can easily be spotted.

Posted by

Rudolf Kubica
Share on linkedin
Share on twitter
Share on email
Find recent Security Advisories for SAP©

Looking into securing your SAP landscape? This white-paper tells you the “Top Mistakes to Avoid in SAP Security“. Download it now.

S/4HANA migration
SAP Cybersecurity- SAP Security Automation- Security News
“There are a few constants in life” – a statement that also applies to the SAP user community. It has always been a challenge for SAP customers to bring their large SAP environments to a current release level. Although the vendor has done a lot in the past to simplify this, it is still not a complex undertaking. However, the S/4HANA migration comes with more stumbling blocks that facilitate a chance to rethink the current SAP Cybersecurity approach.
SecurityBridge
Here at SecurityBridge, we are extremely lucky to have a team full of amazing professionals. Thanks to our team, we have achieved extraordinary things in the past couple of years. With that in mind, we thought it was time for us to start introducing you to the team that drives everything behind the scenes. And we couldn't have chosen a better example to start with than our very own, Harish Dahima! Read on and learn all about Harish's life as a Senior Product Developer, his role, and life at SecurityBridge.
SAP Cloud Connector
SAP Cloud Security- SAP Cybersecurity- Security News
Every organization constantly faces the challenge of minimizing the attack surface that an adversary could use to perform malicious operations. To do this, administrators must install the deployed components and understand them in detail to identify risks and proactively mitigate or prevent those. Today we are looking at what is necessary to protect the SAP Cloud Connector.
SAP Cycling event
Life at SecurityBridge- Partner News- Security News
It was John F. Kennedy who once said: “nothing compares to the simple pleasure of a bike ride”. And what a pleasure it has been! We had our annual bike ride with friends from Accenture, Deloitte, CGI, McCoy, Thales, KPN, Hunt &Hacket, and security leaders from major customers. We had a lot of opportunities for exchange in the cozy atmosphere among like-minded people who all love road cycling and have SAP Security improvement in mind.