SAP Basis SAP NetWeaver - SAP Stuff

Direkt zum Seiteninhalt
SAP NetWeaver
RECOMMENDED GATEWAY SETTINGS FOR RFC SYSTEM PROTECTION
The SAP NetWeaver Application Server Add-on for Code Vulnerability Analysis tool, also known as Code Vulnearability Analyzer (CVA), is a tool that performs a static analysis of user-defined ABAP source code to detect possible security risks. The tool is available in the NetWeaver ABAP stack and is based on versions from: 7.0 NetWeaver: in EHP2 SP 14 or higher / 7.0 NetWeaver: in EHP3 SP 09 or higher / 7.3 NetWeaver: in EHP1 SP 09 or higher / 7.4 NetWeaver: in SP05 or higher To use the CVA tool, the execution of system-wide security controls must be enabled with the RSLIN_SEC_LICENSE_SETUP report. Afterwards, the security checks are available in standard ABAP code checking tools such as ABAP Test Cockpit (ATC) or Code Inspector (SCI). The option of these checks is usually referred to as "security analysis in extended program check". Note that the use of the security check feature for custom code separation is licensed and incurs additional costs. The older program that has been around for years is Virtual Forge's "Code Profiler". It is one of the first products in this segment of SAP security and was used by SAP itself for many years. It is very comprehensive and is also able to track individual variables across the entire control flow. This leads to very precise statements and a reduction of false positives.

Soft skills also play an important role in this profession. In everyday life, communication skills are in demand, because SAP administrators are often in close contact with customers and have to respond to their wishes and questions. They also need to be able to work in a structured manner and find creative solutions and decisions. In order not to lose touch, continuous training in this area is advisable.
SM02 System message
In order to drive innovation in the company, it is necessary to establish a team or a few experts whose recognised role is to promote research projects and PoCs, to continuously train themselves in this regard, to develop innovation proposals and to bring them into the committees. They are therefore largely excluded from operational operations. CONSTRUCTION OF A TEST LABORATORY In addition to resources, it is also necessary to create the framework conditions for the implementation of the research and pilot projects. To this end, it is recommended to set up a test laboratory with as few restrictions as possible on company standards. These are often so massive that a quick and effective implementation of pilot projects is severely hindered or completely prevented.

Some missing SAP basic functions in the standard are supplied by the PC application "Shortcut for SAP Systems".


If you want to get more information about SAP basis, visit the website "www.sap-corner.de".

Since pure SAP systems are rather the exception, non-SAP systems can also be controlled and monitored.

SAP Stuff
Zurück zum Seiteninhalt