 |
"Application-level security focuses on Authentication, Authorization, Administration, Audit and Data Protection. Infrastructure security provides baseline protection for major computing infrastructure resources like servers and networks."
– Forrester Research
We have designed and refined SAP roles and authorization security as well as other forms of ERP application security in many different customer scenarios and have performed ERP security reviews in all variety of SAP modules and sub applications, you don’t have to look beyond security experts at EnCrisp® for your SAP security design, review needs.
Data availability and security are two sides of the same coin in ERP systems, the subtle balance between data availability and a well-secured ERP is not easy to achieve. To manage risk and reduce the TCO of Enterprise Applications such as SAP, organizations need to plan, implement and manage appropriate access strategy and a suitable level of control. Pinching pennies and being lax in this area could lead to embarrassing and potentially devastating outcomes that could jeopardize the goodwill and image of a company.
To find out that security and controls in your ERP system are inadequate and constitute exposure for your company is an OPTION you do NOT want to take.
Leveraging the core foundation blocks of our EnCuRe methodology, the Application Security solutions cover the entire life-cycle of a process in a complex ERP environment. Interfaces and bolt-on applications as applicable are also considered in securing your ERP application. EnCrisp® services in this area ensure that the final end goal of Application Security services is to reduce the TCO (Total Cost of Ownership) by implementing security and controls correctly the first time, reducing rework and decreasing administration costs – all with minimum disruption to the production environment. Security experts at EnCrisp® have the expertise and methodologies to help your company develop a tailored, cost-effective approach to ERP security and controls. We apply our lessons learned from global best practices to address key issues, during:
Pre and Post-Implementation Security and Control Assessments;
SOD (Segregation of Duties) Control Remediation and Redesign;
Security and Control Design Implementation;
Portal-Security Integration;
System Upgrades and Security;
Internal Security Audit Support.
Using specialized tools and customized business rules based approach EnCrisp® security and controls professionals;
- Evaluate and develop access control policies and procedures for on-going sustainability
- Utilizing field-tested methodologies and tools, facilitate the process of designing/re-designing appropriate data security
- Analyze access to sensitive application objects and transactions
- Perform segregation of duties analysis
- Assist with the construction, deployment and testing of proper security profiles
- Assist with the deployment of appropriate security configuration settings and procedures
- Evaluate Infrastructure security and control for SAP NetWeaver layer & the legacy SAP technical architecture of the BASIS module
- Vulnerability assessment for SAP exposures and hot patches
- Implementation & integration of SAP MIC (Management of Internal Controls), controls documentation module with external continuous controls testing and monitoring systems.
- Implementation of SAP centric continuous segregation of duties monitoring tools such as Virsa & BizRights.