Security for Military Data --- our Options -- Share your experiences

Hi,
We want to secure military specific data in SAP.
We also want to comply with ITAR requirements.
One option is to create roles and profiles and then assign it to users who can view that data. In this approach the biggest problem is over head of maintaining 100's of profiles and roles. Our company does not have suffecient funds or team to do that.
Second option was to use development and here is how we envisioned it.
Maintain an indicator for foreign nationals in HR and also maintain an indicator for military personal in HR. (We are allready doing that, for some other busines process) So this table will tell us if an employee if foreign national or a military personal.
If Military person.
give access for military specifc data.
else.
error message.
endif.
similarly
if foreign national.
give error message.
esle.
let him view data
endif.
Now we are not sure if SAP has a common routine for authorizations, which we can change and add these conditions in it. (We will do core mod by getting access key).
If we follow this approach will we have to modify a single routine (for all SAP modules) for all master and transaction data transactions, or will it be multiple routines which we will have to modify.
We also need to cover authorization for table maintenence, transaction codes, org structure level...etc.
Can you please provide your inputs/point of view on this.
Will apprecaite if you can share any other option.
Thanks in advance.

Agreed with Wolfgang, roles & profiles are better in the long run than system mod.
There are ways to redesign roles to make them manageable. Example: Derived roles.
If you already maintain the users thru HR, you can assign roles in R/3 to Job, Position, Work Center, etc. Another idea to help you automated the roles assignment.
Regards,

Similar Messages

  • Upgrade R11.5.10 to R12.1.3-- please share your experience

    Please help me to note the most important steps while upgrading Oracle financials from 11i to R12.
    Assuming client has GL, AP, HR, Payroll, ipayments ( R11.5.10 to R12.1.3)
    Please share your experiences. It will be a greta learning experience for us.
    Thanks in advance

    user13648035 wrote:
    Please help me to note the most important steps while upgrading Oracle financials from 11i to R12.
    Assuming client has GL, AP, HR, Payroll, ipayments ( R11.5.10 to R12.1.3)
    Please share your experiences. It will be a greta learning experience for us.
    Thanks in advancePlease see old threads for similar discussion -- https://forums.oracle.com/forums/search.jspa?threadID=&q=Upgrade+11+to+R12&objID=c3&dateRange=all&userID=&numResults=15&rankBy=10001
    Thanks,
    Hussein

  • Sony ignoring issues of flagship phone owners - share your experience

    Dear fellow owners, I've go to understanding that Sony is putting effort to ignore issues that owners of flagship phones are having. For example my thread "Xperia Z1 mic issue (low volume) when using WeChat" is ignored by Sony staff. Could you share your experience with Sony support?

    Inside
    Outside

  • Running executable on clients,Share your experience

    I have installed Oracle 9i AS on application server environment and deployed my forms and big application on this env.
    Now I tried to run my reports (created as executable files) and they opened at the server and hangs the client till I close the exe. on the server.
    Any body knows how can I deal with the client to run executable or share your experience.
    Many Thanks
    Adel Yousef

    I've done some evaluation of Forms and Reports 6i. Of the two, Reports seems to have most of the problems, but that is another discussion. From my notes I can recall:
    Forms layout: If you delete a frame, all prompts dissapear. Reappear
    when you close and open layout again.
    Forms generic: Readme says 6i is patch compatible with 6.0. If you modify a form with a static record group in 6.0.8 it works ok. If you then recompile with 6.0.5 all static record group values are gone!
    The bug where you may not get the property palette by pressing F4
    before other windows have been activated still exists.
    It appears that the (layout) window has focus, and from GUI point
    I think it does, but cant receive events.
    This behaivour can something be noticed in runtime also.
    I don't think it is a problem with Windows as no other application
    has this behaviour.
    The issue of existing state of package
    still exists, must try it with sql+
    If you change a stored procedure in a way
    that its signature doesnt change, forms
    runtime still complains the first time
    you call the procedure. The second time
    it works ok. Strange.
    Could not generate form with Ctrl+T. Tried Sh+Ctrl+K but got
    PDE-PER001 Internal error (depep 2).
    Tried again, worked.
    Runtime: Why are all my prompts with background=white?
    Charles M Kivio
    Carus Ab
    Certified Oracle Solution Partner
    null

  • Report help for multiple Date Select options

    Hi Friends,
    For a particular year wise report, the client wants 12 date select-options which are changeable and informal every year .The report will also be displayed as per the given date selection period wise. Please help me how to fetch the datas from the table as per the given selection period. Currently the report have one date select-option where the user gives selection range as 1.04 to 31.03. It's related to EB power consumption report and hence the new requirement on date selection which are informal and not a fixed date of every year.
    Ex:Selection-Screen
    Period 1 : 08.04.2008 to 12.05.2008
    Period 2: 12.05.2008 to 20.06.2008
    Period 3: 21.06.2008 to 28.07.2008
    Period 4: 29.07.2008 to 15.08.2008
    Period 5: 15.08.2008 to 21.09.2008
    Period 6 : 21.09.2008 to 14.10.2008
    The data will derive as per the above selection ranges.......
    Please advise with example.
    thanks & regards
    Sankar.

    >
    sankar babu wrote:
    > Ex:Selection-Screen
    > Period 1 : 08.04.2008 to 12.05.2008
    > Period 2: 12.05.2008 to 20.06.2008
    > Period 3: 21.06.2008 to 28.07.2008
    > Period 4: 29.07.2008 to 15.08.2008
    > Period 5: 15.08.2008 to 21.09.2008
    > Period 6 : 21.09.2008 to 14.10.2008
    Hi,
    In this case just derive all records matching dates between 08.04.2008 (low in first select-options) and 14.10.2008(high in last select-options.
    Also my advice is to use a single select-options and prompt the user to give the dates as ranges in the multiple entries dialog which can be opened by clicking the button on the right side of the select-options.
    Regards
    Karthik D

  • Please share your experience with the universal dock for iphone 3g

    Hi There,
    1. Can people share their experience of the universal dock with the iphone 3g adapter. My concern is that does the tight fit scratch the black lower back of the iphone plastic everytime we remove it or put it in? OR is there enough gap for the iphone to slip in and out without scratching.
    2. Anyone having issues with the universal dock or does it work fine for most?
    thanks in advance,
    cheers,
    Sunil

    Thanks for your advice.
    I recently purchased a universal dock for my iphone 3g. It works great. I just had one question. When my iphone is sitting on it for lets say 20 - 30 minutes. Then if i press the buttons on the remote. nothing happens! If I then press the home button while it is on the cradle then, the remote, it plays music. There after lets say if I stop stop the music through the remote and again press the remote button after a few minutes it starts playing. So what happens after a long time. Why do i have to press the home button on the iphone for the remote to work. Is that how it is supposed to work???
    Thanks

  • DP Security for certain data view

    Hi all,
            Did anyone know if there is authorization object for a specific data view in planning book ? I want user to have access to just a certain data view not all of them in the planning book.
    Thank you in advance for your help,
    Paranee

    Hello Paranee -
    <b>Planning Area, Book</b>
    <b>C_AP0_PB</b> - Planning book
    <b>C_APO_SEL3</b> - Selections in planning books
    Authorization objects C_APO_SELE (Release 2.0) and C_APO_SEL2 (Release 3.0 up to Support Package 9) still exist in the system. They are however obsolete. If <b>C_APO_SEL2</b> has been assigned to a profile, set all field values to "*".
    <b>C_APO_IOBJ</b> – Key figure
    <b>C_APO_CPY</b> – Copy function in data realignment
    <b>C_APO_ RLG</b> – Realignment, maintain realignment table
    <b>Authorization Checks in SDP</b>
    All authorization checks in SDP are performed by the function module
    <b>/SAPAPO/MCP_PERMISSION_CHECK2</b> for individual data objects and<b> /SAPAPO/MCP_PERMISSION_SELECT</b> for a range (table) of objects such as products, locations, or planning books. This second function module incorporates the first one.
    If you want to adjust the result of the check, or program your own authorization check, you can do so by using user exit <b>/SAPAPO/SAPLMCPR_015</b> in function group <b>XDMUSER</b>.
    Hope this Helps.
    Regards,
    Suresh Garg

  • Can you please share your experience in implementing / upgrading the Primavera EPPM R8.3?

    Hi,
    In our company various versions (V7, R8.1 and R8.3) of Primavera being used in various locations. To bring all the location to a common platform, management has decided to implement  / upgrade Primavera EPPM P6 R8.3 and also planned to integrate Primavera P6 R8.3 EPPM with Oracle (EBS) Projects application . Hence, If any of you implemented Primavera P6 EPPM R8.3 or upgraded the earlier versions to Primavera P6 R8.3. Please share your ideas and also the pros and cons of implementing R 8.3 EPPM. For your information we are going to have SQL database since all the existing databases are in SQL.
    Please share your ideas and experiences.

    Hi,
    we have done a lot of implementations and migrations to the P6 EPPM R8.3 from different former versions and this is working fine. the dbsetup does a good job.
    A good way in my point of view is to set up a new P6 EPPM R8.3 system with a new PMDB Instance which will keep the configurations so that you easily can migrate or exchange the instances. Always remind to have a validated backup of any instance before migrating.
    Before migration you should mind the following points:
    The source version of the old P6 PMDB instance is:
    P6.2.1 or before => first you need to migrate it to P6 V7.0 before you can migrate it to P6 R8.3
    P6 V7.0 => check if you have used P6 WebAccess: if not okay, else check if you used jackrabbit (look for migration tool), Workflows (close all before migrating); Check if using Jobservice XER-Export (no longer available); Jobservice Batchreport (only Workaround available see Knowledgebase); Risks in the P6 Client (need to be manually migrated)
    P6 R8.0 to R8.2 => Using Extended Schema, Enterprise Reporting Database, own BI Publisher Reports => Check stept to be taken for migration
    Other questions are:
    Which authentication method will you use (native, LDAP, SSO)? If not using native and you want to connect the BI Publisher then you need also to use that authentication there.
    The migration itself is pretty easy if you take care that all sessions are closed (no users or unclosed primavera sessions settings  on that instance, stop all Applications, interfaces or Services connected to the instance. Cleanup your refrdel_deletes, logical_deletes and (if used before), extended Schema tables.
    Then you can migrate with dbsetup, use additional Service Packs and Fixpacks (actually Service Pack 1) on the instances and then you can connect them into the environment by adding it to the P6 Configuration.
    I mentioned you don't want to put all data into one final PMDB-Instance.
    Regards,
    Daniel

  • Please share your experiences moving from Quark to InDesign

    My company's design group is pushing to move from Quark to Indesign, starting with one of my projects, which is our largest (400 pages), highest profile document (it is currently in Quark, and the plan is to pour the text and graphics into InDesign). Our schedule is very lean--leaving little room for surprises. None of the compositors in the design group have used InDesign. They are expected to recieve some formal training--but only about 1 week's worth total over a period of several weeks. I am all for making the transition to InDesign, but feel that the wiser path to take is to start on smaller and less high-profile documents that have more time in the schedule for the learning curve. However the design manager is adament that the transition will be problem-free. My experience is that any transition like this has bumps, and most are unexpected, and create havoc and panic. This document has only gone to print on time once (in 10+ years)--with me managing the project and with much sweat and tears. My hope that this year we could go to print on time AND do it with less wear and tear on all who work on it. I just don't think this will happen making this tranisiton now. Can anyone share their experiences when they made the transition?

    Everyone else has had really good advice about starting with a 400 page doc, particularly if it's complex. If it's just text with a couple illustrations every 4 or 5 pages, it might be do-able, but if it's a complex document with lots of stuff on every page, it could be tricky.
    Try this link for the official converter's guide.
    http://www.adobe.com/designcenter/indesign/articles/indcs3ip_quarkmigration.pdf
    Some practical tips for the beginning XPress converter that I learned the hard way...
    - Cmd-shift-click pulls stuff off the master page.
    - The lack of master anchors may limit your ability to accomplish certain master page layouts (with prelinked text boxes) that are easy to do in XPress. Everyone here will tell you to simply use the margins to control your text flow, which may or may not work well for your particular case.
    - Always scroll around a document by holding down option+spacebar. This insures that you will get the scroll hand tool every time instead of accidentally inserting a zillion spaces into your text.
    -Cmd-shift-A deselects everything in a text box so that you can select another tool. There is no next/prev tool shortcut, but rather keys for each tool. (T is text, A is the white arrow, V is the black arrow)
    - You "thread frames" rather than "link text boxes" despite how I wrote this. :)
    - Don't set text wrap to effect only the stuff underneath in the prefs because...
    - All text should go in a separate layer on top of the graphics layer because...
    - InDesign dynamically resolves transparency effects at print time, which means if part of your text is layered under a transparent element it may get rasterized.
    - If you need to get text to show even when it's on top of an object with a text wrap, select the text box and check the "Ignore text wrap" option.
    - Overprint Preview is your friend. It'll help show you all those things that you didn't notice were going to print strangely before you commit them to print. (Overprinting white type, etc)
    - When you're just starting out, so is the Flattener Preview because you will start to get a feel for what is going to be bitmapped and what won't.
    - XPress documents imported into InDesign should always be exported as Adobe InDesign Interchange and reimported one more time. .inx is the equivalent of the "thumb-nail drag" trick in XPress to clean up a document that is acting funny.
    - XPress documents with placed EPS files may come in with the "Non-printing object" attribute checked on some of the EPS graphics. There's a script floating around that Dave Saunders wrote to fix this. Also, turning Overprint Preview will help you spot this (look for the disappearing objects).
    - If you are placing EPS objects, be sure to set your import options to "Render preview from postscript" or your previews won't look right and/or may be deceiving.
    - Don't every base your paragraph styles off of "Basic Paragraph Style", because if it ever changes in another document your type will suddenly change when you paste it from one document to another.
    - Don't base anything off of "Basic Object Style" for the same reasons.
    - Your defaults change whenever your change the options in a palette/panel without anything selected. Curious why every new object you draw comes in with a drop shadow or a 3pt rule, for example? You accidentally set those options with nothing selected.
    - InDesign's paragraph composer may drive you (or your proof-readers) wonky because it will change the flow of text paragraph-wide if you redo a line of text. You can either adjust it for decent text flow and leave it alone OR turn it off by basing all your stylesheets on single-line composer. People in here will largely recommend option one, but if it doesn't work for your stuff, don't be afraid to disable it.
    - Make sure to upgrade to the latest CS3 update, because CS3 v5.00 had some fairly crashy behavior.
    - If CS3 feels really sluggish, try turning off page previews in the Pages palette.
    - CS3 and OS X 10.5 are not fully compatible yet.
    Best of luck! It's not really that big a change, but everything is slightly different so expect a bit of time to really get your feet under you.

  • Table controlled partitioning - please share your experiences.

    hello ,
    is anyone using table controlled partitioning in the sap on db2 for z/os enviroment?
    can you please share your [good/bad]experiences on the subject ?
    is there anything we should all watchout for ?
    thanks
    omer brandis
    visit the sap on db2 for z/os blog
    http://blogs.ittoolbox.com/sap/db2/

    hello ,
    is anyone using table controlled partitioning in the sap on db2 for z/os enviroment?
    can you please share your [good/bad]experiences on the subject ?
    is there anything we should all watchout for ?
    thanks
    omer brandis
    visit the sap on db2 for z/os blog
    http://blogs.ittoolbox.com/sap/db2/

  • OnyX for Snow Leopard, How has been your experience with it?

    What is OnyX? it's in the apple download page, I know it is a maintenance tool. However I have a few questions about it, it is safe to use? Can it cause system instability? (Cache out X does that), How has been your experience with it?
    I'm asking this just to know if its worth installing in my Mac, because I don't want a tool that says it will increase system performance, and then when you run it, you'll end up with an under performing system giving you a lot of error logs that take hard drive space away.
    Thank You.

    Kurt Lang wrote:
    Yes, that was an assumption on my part that the person already knew the admin password. Should have said so to avoid confusion.
    Well, if the person already knows the admin password, then he is an administrator. He can then promote his own account to admin and take over the whole machine.
    Hmm. I don't see how that would work. Once you enter the admin password, you'd be able to do anything OnyX had in its feature set.
    Exactly. I, as an admin user, but who uses a non-admin account for everyday use, could launch OnyX in my non-admin account, enter the admin password, and then use it. Completely secure. A non-admin user who doesn't know the admin user would still be prevented from using OnyX at all. That allows for the same level of security as exists right now, and is how all other system utilities, even ones provided by Apple, work.
    We'll have to agree to disagree there. It's a good safety net for the less computer savvy. Like keeping your kids away from such utilities.
    All I'm asking for is for OnyX to ask for admin credentials when being launched from a non-admin account. Then, if the non-admin user can't enter the admin password, then the program would simply quit. If an administrator is there to authenticate, then the administrator can launch and use it to maintain and/or repair the non-admin account. That is 100% completely as secure as the situation now.
    But the current situation is that it will simply refuse to open at all under a non-admin account, meaning that not even an administrator can use it to repair or maintain a non-admin account. That isn't any additional layer of security. It's quite the contrary; it's preventing an administrator from administering the computer.
    Right now the only workaround to get OnyX to do any maintenance on a non-admin account is to temporarily promote that account to admin. I would argue that that is a heck of a lot less secure than simply allowing an administrator to launch the app from the non-admin account without having to promote the whole account to admin.
    All admin utilities provided by Apple - Software Update, all the secure System Preferences, Disk Utility, Workgroup Manager, even sudo on the command line, all allow themselves to be run from any non admin account, by an administrator who can enter the admin password. All of this conforms to Apple's security guidelines. OnyX is broken if it doesn't follow those guidelines.
    The OnyX developer seems to assume that everyone runs all the time in an admin account, and it will only clear browser caches in admin accounts. The fact that Apple warns against even browsing the web while logged in to an admin account shows that the OnyX developer has a thing or two to learn about security configuration.

  • Can anyone of you who own a Thinkpad R61 Share your experience?

    I Just get a Thinkpad R61, and it freeze on Windows Vista 3 time out of 6 boots, and it is making a high pitch noise. I do a few test with it before I return to the dealer for replacement. I didn't even bother to install Linux on it because if it is a hardware problem, it would be waste of time, and might get reject for replacement --.--!
    Here is what I get:
    I try it with xubuntu 8.04, (the closest Live CD I can get). The high pitch sound still occurs, however, everything else seem working fine. NO freeze, no nothing.
    I boot up into Windows Vista safe mode with network(wifi). Everything work fine and no high pitch noise. I would be really happen if it stay like this every time I boot my system.
    I took the laptop apart in to a point where wouldn't effect the warranty and boot my system into both normal and safe mode with network. The Fan is not moving, the CD-rom is not moving, and the HHD is moving however not the one who make the noise.
    I do a CLI ram test, and doing the whole thing, no high pitch noise is made.
    At last the most making sense test, put my ear right in front of the speaker, and none of them are making any sense. in fact, I hear less noise when I do that.
    So clearly, sense many people say it is one of the most silent and coolest laptop ever make in the Thinkpad R series. The high pitch noise is not one of the feature I offer. And Sense this noise is not make by any move part, The only two possibility is the audio chip or the graphic chip. It can't be any of the moving part because they also work under safe mode which make no high pitch noise. And it is not the CPU, RAM, or Battery making the Noise, sense they work the same under safe mode, and CLI mode. The only thing that is power up that is not power up in safe mode or CLI mode are the Sound chip, and the Graphic acceleration. Sense I can't really take those thing apart without avoid the warranty. I don't really know which of the one is making that high pitch noise. You might think I am crazy to think that non movie part is making noise, but it is true. Any that is my story. hehe
    I hear all over the place that Thinkpad are great laptop, but it really doesn't give me a good first impression. So How's your experience with your Thinkpad R61?
    Last edited by ioky (2008-10-04 10:31:33)

    Some Thinkpads are known for high pitch noises, with many newer models it seems to be related to running on battery. See here for details. I have this problem on my T61, but as I have it plugged in most of the time I didn't really care.  I had problems with the preinstalled vista as well, no freezes, but I couldn't get wireless to work. Apart from that, I'm really happy with the laptop, the build quality is just great, it has this rock solid feeling to it and it works like a charm with Arch. The pre installed windows was clearly below my expectations, but I'd buy this machine again any time.

  • Mobile Supply Chain Applications(MSCA) - Share your Experiences?

    All,
    Any one is using MSCA?we starting rolling out across globa,i feel there is not much documentation also we are continuously getting issues with either scanners or terminal emulators.
    I would be happy listen and learn from your experiences? and also we should have a seperate section for MSCA.
    Rgds,AP

    Hi;
    Please see below notes which could be helpful on your issue:
    MWA Troubleshooting Tips for Release 12 [ID 782162.1]
    Oracle Mobile Supply Chain Applications Documentation Resources, Release 12 [ID 397154.1]
    Oracle Mobile Supply Chain Applications Release Notes, Release 12.1.3 [ID 1101625.1]
    Oracle Mobile Supply Chain Applications Release Notes, Release 12.1.2 [ID 968776.1]
    Release 12.1.1 New and Changed Features in Oracle Mobile Supply Chain Applications [ID 872933.1]
    Also see:
    http://download.oracle.com/docs/cd/B53825_01/current/html/docset.html
    http://oracleappscommunity.com/oracle/blog/tags/msca/
    Regard
    Helios

  • Need additional security for schema data

    Hi All,
    I am using Oracle Database 11g Enterprise Edition Release 11.2.0.1.0.
    Our client want to secure there data at schema level.
    Suppose even though i logging to schema by providing the userid and password the data should not be visible until i provide with some more verification like one more password or something like this.
    Please if anybody have idea of such scenario please share with me.
    Thanks
    Jamsher

    That kind of security needs to be implemented on the application level. If the client logs on from the command line tools like sql*plus, there is nothing like a dual log-in which is going to be there . Yes, you can use FGAC to restrict the data based on some business rules if you want but whether that's what your client needs, you need to clarify .
    Aman....

  • Data security for multiple data sources

    Dear BO guru's,
    I am struggling with a brainbraker on authorizations on Universes since quite some time.
    I am not a BO guru so hopefully someone can help me with this.
    I (more or less) know the concept of data security in BO: users can be restricted on data level in (mainly) two ways:
    1) with roles in CMC and with restrictions in Universe Designer.
    OR
    2) with a DB table that contains all authorized values per user and per field (i.e. John can see data for country UK)
    The first is easy to set up, but hard to maintain.
    The second is difficult to set up, but very flexible.
    Now here is the problem...
    Supporse your BO server is connected to different source systems (i.e. an SQL server, an Oracle server...) and you want only one universe to get data from all systems at the same time and display it in one report.
    If I am not mistaken, this means we need a data federator.
    ...My questions:
    1) Is there a possibility to do this without a data federator (but still have one universe to build my report or dashboard on)?
    2) Where do I keep the table with authorizations for the users? Is that a database of the BO Enterprise server, a seperate data base, or in a table of one of the source systems (SQL, Oracle...)?
    As this questions keeps me busy since long time, I would be very grateful to have your help.
    It seems hard to find information on this.
    Thanks a lot in advance!
    UniverseDummy

    1) Is there a possibility to do this without a data federator (but still have one universe to build my report or dashboard on)?
    Apart from the Data Federator, you can either use an ETL tool to load your data into a single Datawarehouse or wait until XI 4.0
    2) Where do I keep the table with authorizations for the users? Is that a database of the BO Enterprise server, a seperate data base, or in a table of one of the source systems (SQL, Oracle...)?
    If you are going to use the Data Federator then you can create the table in one of your source systems and add it as a data source in your DF project.
    Regards,
    Stratos

Maybe you are looking for

  • HP Pavilion 750n - Windows XP Blue Screen of Death Error

    Hello everyone - I hope I can get a reply to fix my son's computer (I can't afford to buy a new one). I received the blue screen of doom and I was not aware that Windows had a patch to fix this before the error occurred.  I tried to restore my system

  • I photo will not open - no photos appear -how to solve

    I photo does not open appropriately - no images or pictures appear in I photo All folders etc are not visible - how to solve?

  • Comparing SQL Data Results with CSV file contents

    I have the following scenario that I need to resolve and I'm unsure of how to approach it. Let me explain what I am needing and what I have currently done. I've created an application that automatically marks assessments that delegates complete by co

  • Radio remote destroyed my Apple Ear Buds

    Hi I was using my apple ear buds for 4 months now, all he sudden after i got the radio remote, the left ear bud's volume dropped by 2 db, that is allot, not to mention bass frequencies out of phase now. I can say from 16 years of recording records th

  • Viewing downloaded tv series from itunes

    I downloaded a tv series from itunes, and moved it to my ipad, but I can't find it when I go to look on the actual ipad? It's not in ipod or videos. Any help would be appreciated!