
Learn how vulnerability management identifies, evaluates, prioritizes, remediates, and reports security weaknesses in SAP systems and software, using SAP security notes and patching practices to reduce cyber risk.
Explore how SAP generates and stores password hashes in the usr02 table, detailing the pcode/pwd salted hash columns and the progression from md5 legacy hashes to iterated random salted hashes.
Identify and remove weak password hashes by using the cleanup password hash values report, verify hashes in US r02 tables, and perform necessary manual resets where needed.
Explore RFC connections that execute operating system commands within SAP, including stopping and starting systems across servers, with emphasis on destination authorization and gateway ACLs and sick info.
See how a misconfigured rec info ACL enables hijacking of registered RFC servers and learn to secure the system by defining precise internal roles for IGs and RFC servers.
Explore the security audit log's integrity protection by auditing its settings, simulating a mischievous activity, and attempting to modify the OS-level log, then enable integrity protection.
review the web dispatcher security logs—access, client, and security logs—with inbound request details such as timestamp, source IP, URL, and return code, mirroring ICM logging.
Description
Dive deep into the secrets of SAP Cyber Security. This course will empower the security consultants, IT professionals and SAP administrators to safeguard SAP environments that keep the crown jewels of most big companies.
We will begin with the basics. You will learn how the standard security processes of vulnerability management and threat detection can be implemented in the SAP world. Next you will learn how to properly design SAP architecture so that it fulfills the security requirements.
You will also learn about hardening of SAP products. That includes SAP WebDispatcher, RFC Gateway, configuration of security logs, UCON and many others. I will also go through several well known technical vulnerabilities and demonstrate why they are dangerous and how they can be remediated.
Here are the highlights of the course:
Section 1: Introduction
Section 2: Vulnerability Management in SAP (security SAP Notes)
Section 3: Threat Detection (SAP Enterprise Threat Detection)
Section 4: Secure SAP Architecture
Section 5: Passwords and Password Hashes
Section 6: RFC Security
Section 7: Security Logs
Section 8: WebDispatcher
Section 9: SAP GUI
Section 10: Remote Enabled FMs and UCON
Section 11: SAP Process Orchestration
Who this course is for:
Security consultants - you will learn how to translate high level security requirements into the SAP world
SAP Basis consultants - you will learn security concepts and methods to harden the SAP systems.
SAP Security and SAP Authorization consultants – you will learn the technical aspect of the SAP security.
SAP system owner and SAP Manager - you most likely you believe that your SAP system is secure. This training will help you to verify it and also challenge your teams.