CIO, Large Lubricants and Chemicals Corporation ...
“Using Xpandion’s ProfileTailor Dynamics, we were able to very quickly narrow user authorizations – a task that would have taken us weeks if we had done it manually. With ProfileTailor, it took only minutes to check the actual usage of every user. In addition, we received automated reports that supplied us with all the information required for our auditing projects. This saved us a tremendous amount of time and money, and our employees were freed to accomplish more high-level tasks during the time saved. We are very satisfied with the process and the results, and would highly recommend Xpandion to any company needing to narrow their SAP authorizations and automate their auditing processes.”
| ProfileTailor Dynamics for Security Officers and Risk Managers |
|
The security departments of organizations using SAP face a number of challenges. One set of problems stems from the fact that, since their expertise lies in the area of information security - and not in the complex workings of SAP --- including the problematic issue of authorizations --- they must rely on internal SAP specialists in order to retrieve security-related information from the SAP system.
Another group of problems is SAP-related. Since the focus of SAP is not security, many critical security features and capabilities are simply not part of the system. For example, a lack of definitions for privileged access to information - with the consequent granting of inappropriate privileged authorizations such as SAP-ALL and SAP-NEW - can needlessly endanger organizational security. Security can be further compromised by the accumulation of unnecessary authorizations - collected and never discarded as people change roles in an organization. Typically, more than 93% of authorizations are unused and easily exploited! Other SAP-related issues include cumbersome audit trail access, lack of control over multiple ghost, dormant or dead accounts, and incomplete logging of activities.
The currently available SAP security solutions were developed specifically to answer compliance requirements such as the implementation and enforcement of SoD (Segregation of Duties) policies - and to monitor sensitive transactions. They do not provide a comprehensive solution that can prevent security breaches - and do not overcome the significant security omissions in the system. Furthermore, due to the basic structure of SAP security, which is static, the system often fails to identify unwanted events in a timely fashion, and is therefore unable to prevent damage to the organization. These events are often discovered only during an audit, or following a customer query.
|
-Enables Security Officers and Risk Managers to easily access SAP information, with no SAP knowledge
-Overcomes security gaps in SAP
-Prevents security breaches
-Alerts to potentially harmful events in timely fashion
-Controls privileged access