SAP Insider: RISE with SAP and its Impact on Security and Compliance

This article explains the following three topics that you should tackle when embarking on your RISE with SAP journey from a security and compliance perspective: Business transformation (business adoption), technical system transformation, and post-go-live activities. Download the Document

RISE with SAP focuses on bringing corebusiness systems (SAP S/4HANA Cloud,private edition) into a customer environ-ment that is cloud based, process driven,easy to scale, and easy to use.Geopolitical tensions, environmental challenges, andthe COVID-19 pandemic are forcing companies to changetheir business processes more quickly than ever. RISE withSAP is designed to help organizations adapt to this rapidpace of change by running their processes in the cloud.Hyperscalers like Amazon Web Services (AWS), Google,Microsoft Azure, or Alibaba are running well-managed andhighly secured (physically and technically) data centersworldwide, but where do their responsibilities and liabilitiesend? What does this mean for customers who want toutilize those environments? How can customers make surethat every aspect of their current landscape’s security isbeing reflected? How does security for hybrid landscapeswork?While tr ying to answer these questions, you canuncover additional questions about tooling (are there new/RISE WITH SAP ANDITS IMPACT ONSECURITY ANDCOMPLIANCEUemit Oezdurmus, SAP Global Head of Managed Security Services, and Gunnar Kosche,SAP Service Offering Manager for Cybersecurity and Compliance ServicesGunnar Kosche joined SAP in 2015 and has more than 10 years of ITSecurity expertise. Specializing in identity and access management asa security architect, he is defining customer-specific roadmaps alignedwith the SAP security strategy and product portfolio. In his role asService Offering Manager for Cybersecurity and Compliance Services,Kosche applies his technical knowledge to meet customer demand.Uemit Oezdurmus began working at SAP in 1993 as a student andbecame a permanent employee working in global marketing in 1996.He subsequently worked in internal consulting and NetWeaver presalesbefore leaving SAP in 2007 to co-found Secure Integration Software (laterSecude) in Turkey. In 2011, Oezdurmus re-joined SAP as Global Head ofthe SAP Security Practice and became SAP Global Head of ManagedSecurity Services in 2016.This article appears here with permission from SAPinsider. Copyright © 2021 WIS Publishing. All rights reserved.SAPinsiderOnline.com
additional solutions to be used?) and processes (do weneed to re-design security-related processes?) that relateto the organization’s setup.When embarking on a RISE with SAP journey, theauthors of this article recommend that you tackle thefollowing three topics in parallel: Business transformation (business adoption) Technical system transformation Post-go-live activitiesThe following sections will shed some light on the mainconcerns involving the process and try to answer themost relevant questions.Let’s start with a look at liabilities and responsibilities(Figure 1). In the classical on-premise world, everythingwas under the control and responsibility of the customer.Now, with the transformation approach, SAP customersare required to re -think roles, responsibilities, andliabilities.In the new working model, hyperscaling vendors mustfulfill their part of security and compliance while the restof the tasks remain with the customer.RISE with SAP offers the following: Business transformation in the cloud with predefinedpackages Bundling several products into one offering One contract covering service level agreements (SLA),operations, and issue managementThe idea is to offer a solution for the transition ofbusiness processes to a cloud environment. This includesone of the key pillars — business process intelligence — toreview and refine the customer business processes.Additionally, SAP is offering process discovery forSAP S/4HANA transformation and RISE with SAP. Thisprovides insights to understand an organizatoin’s currentbusiness process performance and identify SAP S/4HANAfunctionalities to support ongoing business goals.RIS E with S A P also contains the integration ofoperations to get the application as a cloud offering.RISE with SAP is an offering provided by SAP thatincludes business advisory services supporting businesstransformation and collaboration with the SAP partnerecosystem (Figure 2).This article is focused on the SAP Customer Successprogram, which includes consulting, suppor t, andoperations.Secure Operations MapThe transformation to a cloud model hands over partsof cybersecurity to a company’s hyperscaler partner andFigure 1 RISE with SAP in a NutshellSAPinsiderOnline.com
SAP. SAP takes care with certified processes to keepyour data secure — but some responsibility and tasksremain with you.To address cybersecurity areas from differentperspectives like identity and access management(IAM) or for a specific solution like SAP S/4HANA, SAPdesigned the Secure Operations Map (SOM).The SOM (Figure 3) offers you guidance on how tobuild a strong security and compliance foundation foryour SAP landscape.The SOM is a reference model that structures thebroad areas of cybersecurity and creates a solidbase for a 360-degree review of cybersecurity andcompliance practices in customer landscapes.The SOM was designed based on SAP’s viewof security topics, needs, and branches, but it canbe mapped to other widely known cybersecurityframeworks such as the National Institute ofStandards and Technology’s Cybersecurity Frameworkor the German Federal Cyber Security Authority’sIT-Grundschutz. What is particular to the SOM is thatit can be used globally for the SAP environment.The SOM is further interpreted in the context of SAPsystems, although the model also could be applied tonon-SAP realms.Business Transformation with BusinessProcess IntelligenceThe intelligent business process re-design as part ofRISE with SAP affects cybersecurity and compliance.It uses constant benchmarking to analyze, design,improve, roll out, and monitor business processes(Figure 4). From this perspective, cybersecurity andcompliance follow the same approach.The authors of this article recommend that yourevisit security on a regular basis. New functionalityand new technologies require new security measures.New attack patterns arise and need to be countered,and your processes need adjustments.Remember, security involves measuring risk, soyou can have a higher or lower level of security basedon risk.In the case of SAP S/4HANA and IAM, the businessprocess re-design with RISE with SAP impacts severalSOM layers. The “organization” and “process” layersare the less technical side of the SOM compared to theother layers. At the “organization” layer, it is importantto define the environment for SAP systems and SAPcloud solutions. It sets the stage and defines needsand requirements as inputs to be considered.Figure 2 Overview of RISE with SAPSAPinsiderOnline.com
General security awareness is an important pre-condition to achieve security. Not everyone has to bea security expert, but everyone needs to contributeto the security of the organization. Ignoring or evencircumventing security rules and mechanisms canendanger the whole landscape. Awareness thus isdirectly linked to user-friendliness and ease of handlingsecurity mechanisms or configurations.A re-design of an intelligent hire-to-retire businessprocess as part of RISE with SAP — using automateddistribution, modern user interfaces, and a securesingle sign-on with multi-factor authentication androbust IAM — will significantly improve your securityawareness.Technical System Transformation — What toConsider When Transforming Your Businesswith SAP S/4HANAA good starting point to get an overview of yourlandscape and security settings is using the SAP EarlyWatch Alert as part of SAP’s services and supportofferings. (Read the blog post “Displaying SecurityAlerts in the SAP EarlyWatch Alert Workspace” andlearn how to get information about the security statusof your system landscape.) With this dashboard youget an overview and details about your landscape, soyou can understand in which areas you could benefitthe most from the different cloud options we offerwith RISE with SAP. It depends on your requirementsand adoption level of the “as a service” offerings.This decision also changes the level of detail youmust manage regarding different cybersecurity andcompliance topics.RISE with SAP is a holistic enterprise transformationand change process. SAP pulls its knowledge fromthe SAP Customer Success program and packagesthat knowledge to help customers with their technicalmigration. You can benefit from the improvedautomation to roll out the recruit-to-retire businessprocess and the corresponding IAM processes, tools,and knowledge. You have the choice to extend yourIAM or redefine it with SAP’s Software as a Service(SaaS) solutions.An SAP S/4HANA transformation with IAM alreadycontains changes like the use of HTTP interfaceswith web services and SAP Fiori apps. The existingSAP GUI-based authorization concept requires areview, including SAP Fiori catalogs and our SAP bestpractices recommendations. This information guidesyou through the process and offers authorizationconcepts created automatically based on yourauthorizations and usage.SAP S/4HANA also introduced the concept of thebusiness user, which combines the detailed data of abusiness partner with a user and reduces the redundancyin the corresponding user entity. This requires a reviewFigure 3 Overview of SAP Secure Operations MapSAPinsiderOnline.com
of the user flows, including new interfaces to manage theentities. In the SAP One Domain Model, the user includes asubset of attributes of a person and other information like IDsand authorizations. This split of entities is important for themaster data flows and user flows of the intelligent enterprise.RISE with SAP comes with SAP Business TechnologyPlatform (BTP) as a Platform as a Service (PaaS) solutionthat integrates and extends your SAP landscape. The SAPBTP includes new user, authentication, and authorizationconcepts.The different cybersecurity and compliance topicsfor business transformation are covered with templates,reference architectures, and guidance from servicesand suppor t as par t of the RISE with SAP offering.Cybersecurity and compliance follows a benchmarkingand review process, which includes a hand-over after theSAP S/4HANA transformation to the SAP Cloud ApplicationServices to operate the solutions.Post-Go-Live ActivitiesOnce a successful implementation and configuration hasbeen achieved following SOM best practices, the journeystarts with the new hybrid cloud environment (Figure 5).Now, the day-to-day activities running in a highly secureand compliant system landscape must be planned andprocessed, keeping a focus on static system security.While it is advisable to cover static system security witha sophisticated patch management program, there mustbe a security strategy plan and execution for all aspectsof a dynamic system as well. Here the managed securityservices provided by the SAP Cloud Application Servicesteam come into play with a holistic and mature portfolio ofservices. It is very helpful to outsource day-to-day activitiesto SAP experts and free up resources internally for otherinnovative topics and activities of the core business.For example, the initial segregation of duties (SoD)checks and the new authorization enhancements are abase for building and adjusting roles and authorizationsas requested by the lines of business. All adjustments andnewly created roles and authorizations need to complywith regulations and must be auditable. The challenge hereis that the entire landscape must be considered: Where tocreate the users, roles, and authorizations? How to ensureSoD? What should reporting look like? What is the processfor creating and changing roles and authorizations?There is a need to add, delete, connect, and disconnectsystems securely. Managed security services providedby SAP Cloud Application Services deliver sophisticatedadvisory, planning, and execution of these tasks, with afocus on hardening systems and interfaces and regularpenetration testing.When it comes to custom coding, it must be madesecure prior to release. Custom code needs to be checkedfor any security gaps, miscoding, or even hard-codedbackdoors. Only coding checked for vulnerabilities shouldbe released to avoid any breaches or misuse.Another very important aspect is security monitoring.Having SAP’s Early Watch Alert Management service isFigure 4 RISE with SAP BPI ComponentSAPinsiderOnline.com