Role of a Security Consultant in an SAP implementation Project

Hi All,
What is the role of a Security Consultant in an SAP implementation Project and the stages in which he is involved?

Hello Mohammed,
The role of a Security consultant in any SAP product implementation (not just GRC) is wide enough and it's hard for anyone to sum up on a single forum post. Still I can give you some pointers.
Security consultants come from different backgrounds, some from networking, database administration, infrastructure and even development like me. They contribute enormously to any product implementation from scratch (landscape design) to go-live (and continuous maintenance) so they are active on every phase of the implementation.
Following are some of the activities they may perform (or participate)
-System Landscape Design (work closely with BASIS and DBAs)
-Check Infrastructure feasibility from security perspective (For Portals exposed to internet or extranet work closely with network providers for firewall security, VPS etc.)
-Propose security guidelines, access policies, disaster recovery plan, business continuity roadmap (work closely with information security consultants and internal auditors or risk management teams)
- Implement SAP solution specific Security measures (involves almost every SAP solution) for example: SAP R/3 security, GRC, BW/BI, HR, FI, Portal security etc.
- participate in application integration for example: LDAP, IDM, SAP UME, shared directories etc (User master records security is on high priority).
-   Check for any possible backdoor access vulnerabilities (ex: open RFCs, function modules like ping_rfc), and it involves almost all SAP solutions and there are special procedures to analyze such vulnerabilities.
there are many such activities that a security consultant perform on day to day basis. Please do not interprete the above mentioned activities (entirely) as a criteria for any security consultant profile. There are many many possibilities for a security consultants to work from pen testing to SoD violation remediation. That's why I said it's not easy to sum up security.
Always remember, Security and GRC are two sides of a coin they work together. however GRC is more of a combination of policy, regulation, events and involves management participation whereas security is a purely technical practice.
You may also be interested to know what it takes to become a forensic security specialist.  Take a quick look at [http://amudee.com/?p=378|http://amudee.com/?p=378]
Best Regards,
Amol Bharti

Similar Messages

  • Roles & Responsibilities of a Basis consultant in an SAP implementation

    Hi All,
    What are the Roles & Responsibilities of a Basis consultant before/during/after an SAP implementation project?
    Please list all of them separately.
    Regards,
    Nivas

    1.    1. Perform User administration and role/profile assignment.
    2.   2.  Perform Role Creation, Modification and Full trouble shooting support for the users authorization failures in all SAP applications and resolving the Security issues and support in integration testing of Roles/Profiles.
    3.  3. Maintain the integrity of the SAP environment by managing the SAP Correction and Transport System (CTS) to ensure all configuration and development objects are promoted properly.
    4.    4. Distribute the online SAP user workload and monitor and manage the SAP background job workload.
    5.   5. Perform OSS / SAP Service Marketplace: Searching notes & creating OSS messages for the respective queries to improve the Performance. And software download, Maintain System Data, License Key & Maintenance Certificate, Developer & object registrations and connection maintenance etc.
    6.     Starting and Stopping SAP instance/(s).
    7.   6. Preventive Maintenance activities - Support Pack/Plug-in implementations, Kernel upgrades, OSS note applications and to apply support pack for Java using JSPM.
    8.    7. SAPGUI/SAPLGPAD troubleshooting and maintenance/upgrades/installations.
    9.    8. Prepare and maintain system documentation, procedures, and standards.
    10. 9. Perform SAP Database Administration – Space management, database reorganizations, design and implement backup and restore strategy, maintain database security, administer database performance, database problem determination and resolution, etc.
    11. 10. Perform SAP Installation, Post installation, client administration, System Refresh and Post-Refresh activities as required.
    12. 11. Perform parameter modification, Buffer, memory management, performance tuning and troubleshoot.
    13. 12. Perform SAP Licensing – Indentify inactive user, user classification and prepare System Measurement result for SAP Global Audit team.

  • USA Based SAP Implementation Projects

    Hi,
    I need the details of 5 SAP implementation projects based in USA. I need the details of the following :-
    1) Client name (Implemented for)
    2) SAP consultancy name (Implemented by)

    Hi:
    Normally, Nobody will give such kind of information.
    Projects that are implemented by the comapny are confidentail. When an employee joins a organization, the offer letter clearly states that the employee should not disclose organization details, which will help the competitor company to gain an unfair advantage.
    At the time of induction, The Hr clearly specifies not to disclose the project details to even close friends.
    My suggest use google and search for infomation.contact your friend circle who can help you out.
    Please let me know if you need more information.
    Assign points if useful.
    Regards
    MSReddy
    Edited by: Sridhar M on May 7, 2008 10:31 PM

  • SAP Security On A New SAP Implementation

    Hi Gurus,
    I'm going to be part of a team that will be implementing SAP Security with a company that's implementing SAP. My experience has always just been on the maintenance and support and I was wondering security wise, what's involved during the implementation stage. What are the things to be done or considered when implementing SAP Security? Are there steps to be followed? What is the best strategy for implementing authorizations?
    Thanks in advance for answering my questions and enlightening my junior mind.
    JB

    Hi,
    SAP Security implimentation process follows the Authorisation Methodology. In this we need to follow the phases which are 
    1._Requirement_ :In this Implimenting parttner team comunicates with end user and prepare the S.O.D.  As per S.O.D implimenting partners prepare the _Role matrix ._
    2._Analsys:_ as per role matrix based on rules and regulations consultants educate the end user.
    3. *Implimentation* :   As per role matrix Single role,composite rople,derive role will be Develop and securing table ,reports.transaction which are critical.
    4. Quality check and test: developed roles are move to qulity system and testing will be done  as per approval from the decision maker role are move to the production server.
    5.Cutover: this roles are assigned to the users and system goes to live.
    Underlined and bold words plesase cocentrate deep.
    Thank you.

  • I am new in sap implementation project.

    somebody  gives me ideas about requirements gathering in gl & ap in manufacturing industry.thank you
    kind regards,
    puja desai

    Hi,
    These are the sap sites its very helpfull to you go through this help.sap.com, deleted
    In deleted you will find the total configuration.
    Its very helpfull to you,
    Regards,
    Harinath.K

  • Does ALE techniques frequently used in SAP Implementation Project

    As the title

    ALE (Application Linking and Enabling)
    ALE Technology is SAP’s technology to support distributed yet integrated processes across several SAP systems.
    ALE & IDoc
    http://www.sapmaterial.com/idoc_sample.html
    ALE/ IDOC
    http://help.sap.com/saphelp_erp2004/helpdata/en/dc/6b835943d711d1893e0000e8323c4f/content.htm
    http://www.sapgenie.com/sapgenie/docs/ale_scenario_development_procedure.doc
    http://edocs.bea.com/elink/adapter/r3/userhtm/ale.htm#1008419
    http://www.netweaverguru.com/EDI/HTML/IDocBook.htm
    http://www.sapgenie.com/sapedi/index.htm
    http://www.sappoint.com/abap/ale.pdf
    http://www.sappoint.com/abap/ale2.pdf
    http://www.sapgenie.com/sapedi/idoc_abap.htm
    http://help.sap.com/saphelp_erp2005/helpdata/en/0b/2a60bb507d11d18ee90000e8366fc2/frameset.htm
    http://help.sap.com/saphelp_erp2005/helpdata/en/78/217da751ce11d189570000e829fbbd/frameset.htm
    http://www.allsaplinks.com/idoc_sample.html
    http://www.sappoint.com/abap.html
    http://help.sap.com/saphelp_erp2004/helpdata/en/dc/6b835943d711d1893e0000e8323c4f/content.htm
    http://www.sapgenie.com/sapgenie/docs/ale_scenario_development_procedure.doc
    http://edocs.bea.com/elink/adapter/r3/userhtm/ale.htm#1008419
    http://www.netweaverguru.com/EDI/HTML/IDocBook.htm
    http://www.sapgenie.com/sapedi/index.htm
    http://www.allsaplinks.com/idoc_sample.html
    ALE/ IDOC/ XML
    http://www.sapgenie.com/sapgenie/docs/ale_scenario_development_procedure.doc
    http://www.thespot4sap.com/Articles/SAP_XML_Business_Integration.asp
    http://help.sap.com/saphelp_srm30/helpdata/en/72/0fe1385bed2815e10000000a114084/content.htm
    IDOC Convertion
    /people/kevin.wilson2/blog/2005/12/07/changing-fields-in-an-idoc-segment

  • Role of associated functional consultant

    hi experts,can ant body tell mewhat is the role of an associated functional consultants in sap fi/co?

    Hi,
    The role of associate functional consultant
    http://www.sap-img.com/general/role-of-a-sap-functional-consultant.htm
    Please let me know if you need more information.
    Regards
    Sridhar M

  • Tasks/activities of a Basis consultant during SAP implementation

    Hi,
    Could someone share the list of tasks/activities of a Basis resource to handle during an SAP Implementation project.
    Thanks in advance,
    Srinivas

    HI,
    i think these are the simplest Basis activities in an sap implementation.
    1. Preapration of the Landscape of the systems
    2. Connectivities btw. different systems like SAP R/3 - BW and so on
    3. Transport Administation i.e TP creation, release, importing to QA - PRD and so
    4. configuration of RFCs and TRFCs if needed
    5. Config. of Data Transmissions
    6. Config. of IDOCs and Message Types
    7. Cutover plan preparation for the Go-Live
    8. System back ups and Logs Maintanance
    9. Installation of all required Patches and Notes
    10. system down time estimatations and planning
    Rgds
    Radhakrishna D S

  • Preparation beforehand SAP implementation

    Hello Gurus, I'm an OCP in developer track. I look after the customized software of one of the production unit of a big company. Our company runs SAP in other production units and corporate. In a recent move, management decided to bring this unit under SAP and implementation will start by a month. It is also decided that I will get functional role in the project. Now how can I be prepared myself earlier than the implementation starts. Please looking for your expert advice...

    Dear Mr. Md. Iqbal,
    In my view, you may do some of the tasks mentioned under as per your role in the project:
    1) Start building team consisting of IT and functional persons. Functional persons must be champion in their area. these team members should be full time dedicated to the project-take commitment from higher management on this.
    2) Inform the functional team to start preparing their processes with flow charts.
    3) Get demo of SAP running at other production unit so that your functional team members can start thinking of mapping their processes in SAP.
    4) Start learning ABAP if you are going to be ABAPer OR start understanding business processes slowly and gradually. Material management (purchase, warehouse) would be most important part to start with. You may get into other processes as per your area of interest and background.
    Most IMP : find out project owner and project manager at your location for this project.
    Documentation may seem boring but it will help in longer run so if possible, try to document each and every task, meeting, requirement, commitments from implementation partner, etc. Signing on the document is equally important.
    If you are going to be project manager or similar to that, ERP Demystified by Alex, SAP Project Management by Joy Ghosh and many other books may help you further.
    God bless you and your company grand success  in the SAP implementation project.

  • SAP XI project - proof of concept

    What will be tasks of an XI consultant for a SAP XI project - proof of concept stage.
    Thanks,
    -Naveen.

    Hi Naveen,
    As an SAP XI proof of concept...
    First you need to understand what what Business System your are integarting or migrating any existing Interfaces in that case...you need to analysis how the interface is developed in that particular Tool..you need to analys the code if and business functionality with the Buiness Analyst and with the endusers..
    This will be done usually for set of interfaces but not a single interface as an when the requirements,Business Process list,architecture,Communication plan,logic data model,usecase ...
    you need to do design documents  in which you need to explain you interace design and flow of it and design mapping documents for partiuclar inteface...
    accoding to the time factor the initial face takes some time but designing document and mapping spec takes around 2 to 4 days
    Amaresh

  • Searching for SAP certified project manager for project

    Please post a response if you know someone who has a BS or BA degree and has:
    General SAP Functional Knowledge and Experience
    8 - 10 years of previous experience as
    an SAP Project Manager with SAP, an SAP Partner, or large companies doing SAP
    implementation projects.
    A minimum of 5 full lifecycle
    implementations of SAP in a Project Manager role.
    Would prefer a candidate that is an SAP
    Certified Associate Project Manager, or have some other type of Project
    Management certification combined with significant SAP project and implementation
    experience on a number of different SAP implementation projects at different
    customers and in different industries. 
    Candidate should be certified in the
    use of SAP Solution Manager.
    Candidate should be certified in the
    use of ASAP Methodology.
    Candidate should be willing to provide
    two professional references.
    Required SAP Functional Knowledge and
    Experience Specifically for this Project:
    SAP Solution Manager
    Solution Manager Implementation
    (SMI210)
    Implementation Projects with SAP
    Solution Manager (SMI310)
    ASAP 8.0 Methodology for Implementation
    (ASA380)

    Hi,
    this might help you
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/40fde890-0201-0010-fa86-ee9a507bc62e
    Regards
    Agasthuri Doss

  • Steps and documentation help in SAP implementation

    Hi Experts,
    I need some documents and documentation help.i have never worked in SAP implementation projects.
    So,any body knows the steps and documentation when implementing SAP.
      please,tell me details and example documents with steps.and tell me the difference between support and implementation.What we will do extrain implementation.
    As a ABAP programmer what can i fill in se38 documentation.
    Please tell me.
    It'll be very helpful to me.
    Thanks in advance.
    Regards,
    Nandha

    Any SAP R/3 implementation is a big effort which is done by a team of experts from different backgrounds, not by an individual. So if you are going to be on a project as technical person, in all probability you will join the team as a member of the technical team during the implementation phase. By this time, the blueprint and design phases would have been almost complete and some standards and procedures with regards to documentation, coding, transports and migration accross systems will have been established.
    A team lead will brief you all the requirements of the project as far as documentation standards are concerned and migration of the objects, testing procedures etc. You don't have to worry about that. This will be specific to the project, so you cannot generalize it and apply it to every project.
    Now the difference between a new implementation and support is that the first one is new one which goes through the phases of blueprinting, design, implementation, testing and go-live. The support phase comes after go-live. You will just be supporting the production system, in that you will be fixing any bugs in the existing programs or change some existing programs to add some more logic or remove some logic, or write new reports or programs as per the users' request.
    Srinivas

  • What are the Essentials for a Sap Security Consultant.

    Hi Gurus,
    I have completed a Implementation in which I alone handled the entire Security . It is a defense client .
    Now I am technically expert at security. But I have no functional knowledge.
    Implementing Security in SAP one needs to have knowledge of funtional process as well. The course that are purely technical stuff and I have good idea of techincal stuff.
    The Question is what is a Sap Security Consultant expected to know . And how to go about acquiring that knowledge?

    Hi Hussain,
    There is a little bit of release-dependent-everything in this thread: Authorization for VAP2 in conflict with VD02 for F_KNA1_GRP
    Try solve it and you will understand that you need the requirements (without that you are anyway doomed) and the knowledge and the appropriate access to create / test it.
    BAPI's are remote enabled stable interfaces to SAP standard functionality. They are the best examples of combining functional, technical and standard skills in a sustainable way without creating a mess (a mess, way beyond the bounds of your concerns...).
    If you learn to use the available tools and information sources, then you dont need to stress about the essentials, even if your customer makes a design error before or after your advice.
    Cheers,
    Julius

  • Role For Security Consultant During Upgradation

    <b>Dear Friends,
    Here One Question.
    During Upgradation from 4.6C to ECC 6.0
    What Special Responsibility Comes To A Security Consultant.
    Just Need Idea of Those Jobs.
    Thank You.
    Sumanta</b>

    Hi,
    few info i got can share with you, hopefully you find it good source.
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/com.sap.km.cm.docs/oss_notes/sdn_oss_bc_jas/~form/handler
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/f18c632a-0a01-0010-38b8-9ac82ea98a4e
    http://help.sap.com/saphelp_nw04/helpdata/en/9d/d38c4024d26e1de10000000a1550b0/frameset.htm
    THnaks,
    AKL
    <removed_by_moderator>
    Edited by: Julius Bussche on Jul 25, 2008 12:08 PM

  • Role of a technical consultant in SAP E-Recruiting

    Hi all,
    i would like to know the <b>role of a technical consultant in SAP E-Recruiting</b> Implementation.
    anyone with relevant experience and any little reliable knowledge please reply.
    Any also kindly suggest some documents where i can find the same information.
    Useful answers will be rewarded with points for sure...;-)
    thanks in advance...
    -Tejas

    Hi,
    Check out TBIT40 course material on TBIT40 - SAP NetWeaver Process Integration | SAP Training and Certification Shop and have a look at related courses
    The content of these courses should give you an overall impression of all tasks that could be performed by a development or technology consultant. Both roles are technical
    Kind regards
    Dimitri

Maybe you are looking for

  • Re: Report output header text longuage change

    Hi Dear's, Ataually my issue is am unable to change report output header field text to user specific login longuage.... I.e. if user login to ITALY/GERMANY then report output header text should be displayed on same  Longuage for this can any body giv

  • Transaction code for Report painter

    Hi Experts, I have created reports using Report Painter (GRR1). I want to create Transaction code (TCODE) for reports which was done using Report painter. Could you please help me how to do this. Thanks in Advance Regards Bujji

  • Change item category Display mode  in sales order (Third Party )

    Hi all, I am creating sales order with reference to sales contract but at the time of sales order we don't have enoff stock to deliver to customer , so we have deiced to Third party sales process But the problem is while creating a sales order with r

  • Itunes 9.0.1 crashes just after starting every time.

    Hello, Hopefully someone can help me out. Any advice would be most gratefully received. I never had any problems previously running Itunes. I downloaded and used Itunes 9.0 immediately after it was released for a while without any problems. A week or

  • Problem with Shape Hints

    My professor and I are both stumped, so maybe someone can help me out? I'm using Flash CS4 (on a mac) and I'm trying to use shape tweens between two parallelograms. They are shapes and not symbols, since I hear you can't shape tween symbols. The tran