0% found this document useful (0 votes)
4 views30 pages

SAP R/3 Security Training Overview

The document discusses security aspects and access profiles in the SAP R/3 system, including user authentication, authorization concepts, security parameters, and access profile administration.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views30 pages

SAP R/3 Security Training Overview

The document discusses security aspects and access profiles in the SAP R/3 system, including user authentication, authorization concepts, security parameters, and access profile administration.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SAP R/3 System Training

Information Security
Access Profiles

23.08.2005
INDEX

1. Objective

2. Training Content

3. Security Aspects of the SAP R/3 System

4. Management of Access Profiles

5. Segregation of Duties Matrix


1. Objective

The objective of this material is to present the main


features and functionalities of the SAP R/3 system
that are related to information security and,
consequently, to the access profiles, so that
the administration of this environment can follow the good practices

market practices.
2. Training Content
The content of this training covers:

Security Aspects of the SAP R/3 System:

User Authentication.

Authorization Concepts.

Security Parameters (RSPARAM).

Trilhas de Auditoria.

Segregation of Duties in Administration


Access Profiles.

Access Profile Management:

Profile Generator.

Useful Tools.

Reports.

Function Segregation Matrix.


Security Aspects
of the SAP R/3 System
3. Security Aspects of the SAP R/3 System

The illustration below outlines the overall view of the security devices of the SAP R/3 system. The three (3) topics that will be
Addressed in this training, within the security topic, are indicated with red arrows.
3. Security Aspects of the SAP R/3 System

The demand for security increases in line with the increased use of distributed systems to manage data.
business. The use of this type of system requires that the processes and data supporting business needs are
protected against unauthorized access, especially when dealing with critical information.

Due to the aforementioned factors, it is necessary to adequately manage the following security aspects of
SAP R/3 environment:

Only authorized users can access the SAP R/3 system.

Users can only perform authorized tasks and transactions that are
according to the functions performed.

The system data cannot be modified without recording the operation.

Data and communication must be protected against unauthorized access.

Ensure that the company and the users of SAP R/3 are aware of their responsibilities.
and legal obligations.
Critical activities and events of the system must be recorded for consultation.
future and audits.

Topics that are covered in this training.


3. Security Aspects of the SAP R/3 System

User Authentication

User authentication is carried out through user accounts.


(IDs) and access passwords, ensuring:

Only authorized users can access the SAP R/3 system.

Maintenance of the integrity of the recorded information.

The system has several mechanisms (rules and parameters) for


authenticate users and ensure that access accounts (IDs) do not
may be improperly used, among these mechanisms are:
(i).número mínimo de caracteres por senha, (ii).troca periódica da senha,
blocking of users' accounts who enter incorrect passwords, among others
mechanisms that we will discuss in more detail in the item 'Parameters
of SAP R/3 System Security.
3. Security Aspects of the SAP R/3 System

User Authentication (continued)

SAP has standard rules for password usage. These rules may be
altered according to convenience and in accordance with the Security Policy of
Organization. The standard rules for user passwords are detailed below:

It is mandatory to change the system access password the first time the user logs in.
make your connection.

The password must contain at least three (3) characters.

The maximum password length is eight (8) characters.

The first character of the password cannot be a question mark "?" or an exclamation mark "!".

The first three (3) characters of the password cannot be in the same order of
parte da conta do usuário. Exemplo: usuário: JOSESILVA, senha: SES.

The first three (3) characters of the password cannot be repeated (e.g.: aaa) and cannot
can contain the character 'space'.

The password cannot be 'SAP*' or 'PASS'.

The user cannot reuse the last five (5) passwords.

Users can only change their passwords if they are logged in to


system.
3. Security Aspects of the SAP R/3 System

Authorization Concepts

Organizations have various positions and roles associated with


its organizational structure (organizational chart), and the people
those responsible for performing such activities need to have
access to certain modules (features) of the system
integrated. In this sense, the processes and information do not
they must be and do not need to be available to users who
do not perform this function.

Users should only have access to transactions and


programs associated with your tasks, therefore, it is important
that the person in charge of maintaining access profiles
regularly review the use of available transactions
to the users. If these are not being used, it must-
to withdraw this access.
3. Security Aspects of the SAP R/3 System

Authorization Concepts In order to assist System Administrators in creating and


to maintain user access profiles, SAP created the
The concept of authorization in the SAP R/3 system was
Profile Generator tool (PFCG) that automates the
developed to allow users to only access
process of creating access profiles, facilitating management
the transactions and programs for which they were authorized.
of these.
Therefore, when a user performs a transaction or a
The system performs an authorization check
(authority check) to verify if the user has the
necessary access privileges to perform such access.

The authorization checks of the SAP R/3 system are


based on four (4) types of authorization checks:

1. Authorization for transaction execution (subject to


authorization S_TCODE.

2. Specific authorizations to execute transactions (objects


of authorization).

3. Authorization check in programs (clause of


authority check).

4. Report classes (class) and authorization groups in


tables (authorization group).
3. Security Aspects of the SAP R/3 System

Security Parameters (RSPARAM)

The main parameters of the SAP R/3 system are


registered in the RSPARAM program that is structured in
three (3) columns with the following information:

Parameter name: this column records the code


of the parameter (login/fails_to_user_lock, for example).

User-defined value: if this column is


filled, the value of this prevails over the standard value, or
these are the values defined by the Organization.

Default value of the system: in this column are


the values defined by SAP are recorded.

The parameters of RSPARAM can affect performance of the


system, therefore, any changes to these must be assessed
by the System Administrators together with the area of
TI.

The following slide demonstrates the main parameters of


security of the SAP R/3 system.
3. Security Aspects of the SAP R/3 System

Security Parameters (RSPARAM) - continuation

Below are the main security parameters of the SAP R/3 system, the default values, and the recommended values
by Deloitte.

Parameter Description Parameter Code Standard Value Valor Recomendado


Password expiration time. Login/password expiration time 90 days 60 days
Minimum password size. Login/min_password_lng 3 characters 8 characters
Number of invalid access attempts for the 12 attempts
Login fails to user lock 3 attempts
user to be blocked.
Number of invalid access attempts, after the 3 attempts
Login/fails_to_session_end 3 attempts
which system session is closed.
Maximum execution time of a program in 1200 seconds
Rdisp/max_wprun_time 900 seconds
real time (online).
Idle time for work session to be 0 (never)
Rdisp/gui_auto_logout 1200 seconds
automatically disconnected.

Automatic unlocking of users after midnight. Login/failed_user_auto_unlock 1 (activated) 0 (disabled)

Login/no_automatic_user_sapstar or 0 (activated)
Automatic creation of the SAP user. 1 (disabled)
Login/no_automatic_user_sap
N
Turn off the authorization checks for transactions. Auth/no_check_in_some_cases Y It is not allowed
(allowed to turn off) turn off)
3. Security Aspects of the SAP R/3 System

Security Parameters (RSPARAM) - continuation

Parameter Description Parameter Code Standard Value Recommended Value


Multiple connections to SAP Login/disable_multi_gui_login 0 (activated) 1 (disabled)
Disable the authorization checks of the objects of Y (can be N (Cannot be
Auth/object_disabling_active
authorization. disabled) disabled)
Perform the authorization checks of the objects 1 (deactivates the 2 (activates the
Auth/rfc_authority_check
S_RFC and FUGR checking checking
Time to check unused connections. Rdisp/keepalive 1200 seconds 300 seconds
Turn off the automatic checking of authorizations for 0 (deactivates the
Auth/system_access_check_off 0 (activates the check)
ABAP. checking
Enabling the audit trail. Rsau/enable 0 (disabled) 1 (activated)
Log of modifications to the tables. Rec/client OFF ALL
Disables the authorization check for the 0
auth/tcodes_not_checked SU53
SU53 and/or SU56 transactions.
3. Security Aspects of the SAP R/3 System

Auditing and Usage Logs The transactions listed below allow the area
responsible for the ERP administration can monitor
The recording of events in business processes and activities
events and activities carried out in this:
made by the users of the integrated system must be
made for legal purposes and for monitoring the SM18: Security audit - delete old files.
security of the SAP R/3 environment.
SM19: Security audit - manage profile of
The ERP records various logs that are related to audit.
administration, monitoring, troubleshooting and
SM20: Audit log - local analysis.
system audit. Two (2) other tools that assist
the monitoring of the system's security is: SM21: System log - local evaluation.

Audit Info System (AIS) – transaction SECR. SLG1: Analyze application log.

Security Audit Log (transaction SM20). STAT: System statistics.

ST01: System trace.

ST03: Workload in the system.

SECR: Audit information system.


3. Security Aspects of the SAP R/3 System
Super User

Segregation of Functions in the Administration of Profiles


Access

The best practices for managing access privileges Administrator of Administrator of Administrator of
two users recommend that the maintenance tasks of the Authorization Data. Access Profiles Users
access profiles should be divided among three (3) people
Allowed Allowed Allowed
(segregation of duties), as detailed below:
Create and modify •Visualize the •Update the
Authorization data management: it only has the data of data of users.
authorizations. authorization.
permission to create, modify and save access profiles, Associate the profiles
Use the SUIM. Generate the profiles and to the users.
you do not have permission to generate.
authorizations.
Not Allowed •View profiles and
Access profile management: only has permission Not Allowed authorizations.
Modify users
to approve and generate the corrected access profile. and generate profiles. Modify users •Use the SUIM.
and the authorizations.
Standard SAP Profile Not Allowed
User administration: has permission to associate Generate profiles of
SAP_ADMIN_AU access with the objective of Modify and generate
the access profiles of users authorizations and
authorization that
profiles.
we start with
S_USER*. Standard SAP Profile
Standard SAP Profile SAP_ADM_US
SAP_ADMIN_PR
Profile Management
of Access
4. Management of Access Profiles

Profile Generator Company (company code).

The proper management of user access profiles of Centro (plant).


the SAP R/3 system allows for security, integrity and
Cost Center
the confidentiality of the stored data can be
maintained. Purchasing group.

Access profiles are essential for the Organization Purchasing Organization


segregate the functions performed by the users, in order to Tipo de Depósito (storage type).
that they can only execute transactions associated with
Distribution Channel
functions performed by them.
Sales Organization
To enable organizations to configure access
of its employees according to their needs, SAP Profit Center
developed the tool Profile Generator which is used
Sales Office
to create user access privileges for R/3. This
the tool allows access to be restricted according Type of Movement

with the organizational levels related to the side: Document Type.

Among others.
4. Management of Access Profiles

The figure below shows the operating scheme of an access profile of the SAP R/3 system that has the following
components: transactions, authorization objects and authorization values.

SAP R/3 User

Profile of
Access Transaction 1
Obj.
Authorization 1
Field 1
Restriction 1
Transaction 2 Obj.
Authorization 2
Field 2
Restriction 2
Transaction 3
4. Access Profile Management

The figure below shows the operating scheme of the access profile demonstrated on the previous slide with an example of
application.

SAP R/3 User

Buyer
ME21N
M_BEST_EKO
ACTV
create
ME22N

EKORG
Organization
shopping
ME23N
4. Management of Access Profiles

Below we demonstrate the two (2) main screens of the tool "Profile Generator" (PFCG): (i) Transaction menu and
(ii). Authorizations.
4. Access Profile Management

Profile Generator

The SAP R/3 system tool that allows creating profiles


access has several features to facilitate the
day-to-day of the Administrator, among them are:

Creation of Composite Profiles.

Copy of Simple and Composite Profiles.

Download and Upload Access Profiles between Clients.

Generation, Adjustment, Transport, Download Tool of


Comparison of Access Profiles.

Creation of Derived Profiles (Hierarchy).

Assignment of Access Profiles to Users.


4. Management of Access Profiles

Useful Tools There are still tables that facilitate the Administrator's routine,
then, they provide information directly from the tables
The SAP R/3 system has tools that facilitate the
consulted by the SAP R/3 system, among them are:
management of access profiles and the maintenance of
user authorizations. Among these tools, Table AGR_AGRS: shows simple access profiles
stand out: that are associated with composite profiles.

Transaction SU53: displays authorization errors. Table AGR_TCODES: shows the transactions that are
associated with simple profiles.
Transaction SU24: shows the authorization checks
carried out in each transaction. Table AGR_USERS: shows the users that are
associated with simple profiles.
SUIM transaction: report tree of the System
User Information. TSTC table: list of system transactions.

Transaction SA38: execution of programs. TSTCA table: list of associated authorization objects
to the transactions.
Transaction SE16: table visualization.
Table TSTCV: shows the program that is called
when a transaction is executed.

Table USR01: user information.


4. Management of Access Profiles

Useful Tools – Transaction SUIM

The SUIM transaction (User Information System)


allows the Managers responsible for maintenance of
Access profiles and users view reports with data
two users (incorrect logins, critical authorizations, etc)
functions, profiles, authorizations in the system, objects of
authorization, transactions, comparisons, list of uses and
modification documents. It is within this set of
relatórios que está o relatório para identificação de conflitos
Access (According to Critical Combinations of Authorizations
for Transaction Execution).

These data are of great relevance in the process of


management of access profiles, as they allow the
Administrator, research and analyze the access profiles.
users based on various search engines.
4. Access Profile Management

Reports

Just like the useful tools of the system, the reports allow Managers, Consultants, and Auditors to analyze the
Information related to security, access profiles, and users. Below we demonstrate a list of the main reports.
of the system:

Report Name Description


RSUSR002 User by complex selection criteria
RSUSR002_ADDRESS User [Link]
RSUSR003 Check the passwords of SAP* and DDIC users in all clients
RSUSR004 Restrict user values to individual profile segments and authorized objects.
RSUSR005 With critical authorizations
RSUSR006 List of users with incorrect logins
RSUSR008 According to critical combinations of authorizations for transaction execution

RSUSR009 With critical authorizations


RSUSR011 Transaction list by selection with user, profile, or object
RSUSR012 Search for authorizations, profiles, and user with determined object values
RSUSR020 Profiles according to complex selection criteria

RSUSR030 Authorizations according to complex selection criteria

RSUSR040 Authorization objects according to complex selection criteria


4. Management of Access Profiles

Reports (continued)

Report Name Description


RSUSR050 Comparisons
RSUSR060 Usage lists
RSUSR060OBJ List of uses for authorization objects in programs and transactions
RSUSR070 Functions according to complex selection criteria

RSUSR080 Users by license data


RSUSR100 Modification documents for user
RSUSR101 Modification documents for profiles
RSUSR102 Modification documents for authorizations
RSUSR200 List of users by login date and password modification
Segregation Matrix of
Functions
4. Segregation of Duties Matrix

The matrix of segregation of functions is a list composed of


transactions (pairs) that, according to best practices, do not
may be present in the same access profile and/or
user.

The SAP R/3 system has the (standard) report 'Second


Critical Combinations of Authorizations for Execution
Transaction" that identifies access conflicts, based on
in the access conflict list registered in the SUKRI table.
The result of this report can be displayed in two (2)
different formats

Users x access conflicts.

2. Access conflicts vs user.

The figure on the side shows the report tree of the System of
User Information (transaction SUIM) and the path of
report that identifies potential critical combinations of
user transactions.
4. Segregation of Duties Matrix

In order for the segregation of duties matrix to be executed,


it's necessary for access conflicts to be registered
in the SUKRI table. Access to the table can be done through two
(2) paths:

Transaction SE16 > SUKRI > Execute > Modify


critical combinations.

2. Transaction SUIM > User > Second


critical combinations of authorizations for
transaction execution > Modify combinations
criticisms.

The figure in the upper right corner of the slide shows the button
"Modify critical combinations" that must be clicked to
start the registration of access conflicts.
4. Segregation of Duties Matrix

1
As demonstrated in the previous slide, it is possible
register up to five (5) conflicting transaction codes per
line of the SUKRI table, that is, it can be identified that a
user can access up to five (5) transactions that do not
they can be within the same access profile and/or
user.

Deloitte developed two (2) programs in ABAP for


assist in the performance of our review work of
access profiles. These programs have the following functions:

1. Access Profiles with Conflicts: shows which 2ones


access profiles have problems with
segregation of duties. This report may be
shown in two (2) ways: (i). Access Profiles
versus Conflicts and (ii). Conflicts versus Profiles of
Access.

2. Possible Access Conflicts: shows the


possible and current conflicts in the profiles of
access case a certain transaction is inserted.

You might also like