CISOs must know about SAP Cyber security
As the IT landscape gets more complex, the difficult job of a Chief Information Security Officer (CISO) is getting even more difficult. One of the challenges facing any CISO is to keep track of various technologies used by their organisation. CISOs for organisations using SAP face another big challenge – managing SAP security.
Traditionally, most CISOs relied on the SAP BASIS team to manage?SAP Security using?SAP GRC Access Control (or similar tools) to manage SAP?segregation of duties?(‘SoD’) and access issues within the SAP system. Occasional audits of SAP system covered the IT General Controls sufficient to satisfy the financial auditors.
However, rapidly changing threat perception and SAP technology landscape is challenging this traditional model of managing SAP security. With my own experience of working with multiple large and medium size organisations across industries, I have identified these ten things that will help a CISO navigate the increasingly complex SAP security challenges:
领英推荐
A CISO of an organisation using SAP has the responsibility to protect its most important system – SAP ERP. An SAP security threat mapping is a good starting point to understand the specific challenges in the organisations.
Once the security risks and vulnerabilities are identified, come up with a roadmap to address these. Identify the ones with high impact but easy solutions – and go after them first. Have a time-bound and phased approach for the remaining. It is best to take some of the more complex areas as mini projects!