SAP R/3 Security Training Overview
SAP R/3 Security Training Overview
Information Security
Access Profiles
23.08.2005
INDEX
1. Objective
2. Training Content
market practices.
2. Training Content
The content of this training covers:
User Authentication.
Authorization Concepts.
Trilhas de Auditoria.
Profile Generator.
Useful Tools.
Reports.
The illustration below outlines the overall view of the security devices of the SAP R/3 system. The three (3) topics that will be
Addressed in this training, within the security topic, are indicated with red arrows.
3. Security Aspects of the SAP R/3 System
The demand for security increases in line with the increased use of distributed systems to manage data.
business. The use of this type of system requires that the processes and data supporting business needs are
protected against unauthorized access, especially when dealing with critical information.
Due to the aforementioned factors, it is necessary to adequately manage the following security aspects of
SAP R/3 environment:
Users can only perform authorized tasks and transactions that are
according to the functions performed.
Ensure that the company and the users of SAP R/3 are aware of their responsibilities.
and legal obligations.
Critical activities and events of the system must be recorded for consultation.
future and audits.
User Authentication
SAP has standard rules for password usage. These rules may be
altered according to convenience and in accordance with the Security Policy of
Organization. The standard rules for user passwords are detailed below:
It is mandatory to change the system access password the first time the user logs in.
make your connection.
The first character of the password cannot be a question mark "?" or an exclamation mark "!".
The first three (3) characters of the password cannot be in the same order of
parte da conta do usuário. Exemplo: usuário: JOSESILVA, senha: SES.
The first three (3) characters of the password cannot be repeated (e.g.: aaa) and cannot
can contain the character 'space'.
Authorization Concepts
Below are the main security parameters of the SAP R/3 system, the default values, and the recommended values
by Deloitte.
Login/no_automatic_user_sapstar or 0 (activated)
Automatic creation of the SAP user. 1 (disabled)
Login/no_automatic_user_sap
N
Turn off the authorization checks for transactions. Auth/no_check_in_some_cases Y It is not allowed
(allowed to turn off) turn off)
3. Security Aspects of the SAP R/3 System
Auditing and Usage Logs The transactions listed below allow the area
responsible for the ERP administration can monitor
The recording of events in business processes and activities
events and activities carried out in this:
made by the users of the integrated system must be
made for legal purposes and for monitoring the SM18: Security audit - delete old files.
security of the SAP R/3 environment.
SM19: Security audit - manage profile of
The ERP records various logs that are related to audit.
administration, monitoring, troubleshooting and
SM20: Audit log - local analysis.
system audit. Two (2) other tools that assist
the monitoring of the system's security is: SM21: System log - local evaluation.
Audit Info System (AIS) – transaction SECR. SLG1: Analyze application log.
The best practices for managing access privileges Administrator of Administrator of Administrator of
two users recommend that the maintenance tasks of the Authorization Data. Access Profiles Users
access profiles should be divided among three (3) people
Allowed Allowed Allowed
(segregation of duties), as detailed below:
Create and modify •Visualize the •Update the
Authorization data management: it only has the data of data of users.
authorizations. authorization.
permission to create, modify and save access profiles, Associate the profiles
Use the SUIM. Generate the profiles and to the users.
you do not have permission to generate.
authorizations.
Not Allowed •View profiles and
Access profile management: only has permission Not Allowed authorizations.
Modify users
to approve and generate the corrected access profile. and generate profiles. Modify users •Use the SUIM.
and the authorizations.
Standard SAP Profile Not Allowed
User administration: has permission to associate Generate profiles of
SAP_ADMIN_AU access with the objective of Modify and generate
the access profiles of users authorizations and
authorization that
profiles.
we start with
S_USER*. Standard SAP Profile
Standard SAP Profile SAP_ADM_US
SAP_ADMIN_PR
Profile Management
of Access
4. Management of Access Profiles
Among others.
4. Management of Access Profiles
The figure below shows the operating scheme of an access profile of the SAP R/3 system that has the following
components: transactions, authorization objects and authorization values.
Profile of
Access Transaction 1
Obj.
Authorization 1
Field 1
Restriction 1
Transaction 2 Obj.
Authorization 2
Field 2
Restriction 2
Transaction 3
4. Access Profile Management
The figure below shows the operating scheme of the access profile demonstrated on the previous slide with an example of
application.
Buyer
ME21N
M_BEST_EKO
ACTV
create
ME22N
EKORG
Organization
shopping
ME23N
4. Management of Access Profiles
Below we demonstrate the two (2) main screens of the tool "Profile Generator" (PFCG): (i) Transaction menu and
(ii). Authorizations.
4. Access Profile Management
Profile Generator
Useful Tools There are still tables that facilitate the Administrator's routine,
then, they provide information directly from the tables
The SAP R/3 system has tools that facilitate the
consulted by the SAP R/3 system, among them are:
management of access profiles and the maintenance of
user authorizations. Among these tools, Table AGR_AGRS: shows simple access profiles
stand out: that are associated with composite profiles.
Transaction SU53: displays authorization errors. Table AGR_TCODES: shows the transactions that are
associated with simple profiles.
Transaction SU24: shows the authorization checks
carried out in each transaction. Table AGR_USERS: shows the users that are
associated with simple profiles.
SUIM transaction: report tree of the System
User Information. TSTC table: list of system transactions.
Transaction SA38: execution of programs. TSTCA table: list of associated authorization objects
to the transactions.
Transaction SE16: table visualization.
Table TSTCV: shows the program that is called
when a transaction is executed.
Reports
Just like the useful tools of the system, the reports allow Managers, Consultants, and Auditors to analyze the
Information related to security, access profiles, and users. Below we demonstrate a list of the main reports.
of the system:
Reports (continued)
The figure on the side shows the report tree of the System of
User Information (transaction SUIM) and the path of
report that identifies potential critical combinations of
user transactions.
4. Segregation of Duties Matrix
The figure in the upper right corner of the slide shows the button
"Modify critical combinations" that must be clicked to
start the registration of access conflicts.
4. Segregation of Duties Matrix
1
As demonstrated in the previous slide, it is possible
register up to five (5) conflicting transaction codes per
line of the SUKRI table, that is, it can be identified that a
user can access up to five (5) transactions that do not
they can be within the same access profile and/or
user.