Security Recommendations for SAP BTP Services

Deliverables / More

Contact: m.shea@sap.com

Motivation

Customers have complained that it is difficult to find our recommendations for the secure configuration of our products. In response, SAP Global Security has decided that all cloud-based lines-of-business must provide a list of security recommendations for configuration settings of their products and services. They have enshrined this requirement in the product security standard SEC-377.

For more information about the background of the project, see the Security PMO Security Configurations Guidelines.

Product owners get a separate set of instructions here.

Process

  1. You are contacted by a product owner for a particular service about the security recommendations.

  2. Together with the product owner and the security responsible for the service, you generate the list of security recommendations for the service.

  3. In the Ixiasoft DITA CMS, use the Copy with new LOIO command to create a copy of the object REFCONT: Template Security Recommendations (loiof28d4ae446044a318f1702d69b910190) in the appropriate container:

    1. In ODS_NEO for CF, Neo, and core services.
    2. In BTP_TOP for ABAP, Kyma, and other core services.
    3. In your own container under CP_TOP.
    4. In CP_TOP if your container is outside the CP_TOP dependency.
  4. Follow the instructions in the template. Keep your content profiled with the information_classification internal.

  5. Review the content with your team.

  6. Your product owner has your content reviewed by the central security recommendations team.

  7. When ready, remove the profiling from your content and notify the central security recommendations team.

  8. The central team publishes the security recommendations with your content.