<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAP Audit Check &#8211; Jitendra Zaa</title>
	<atom:link href="https://www.jitendrazaa.com/blog/tag/sap-audit-check/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.jitendrazaa.com/blog</link>
	<description>AI, Salesforce, ServiceNow &#38; Enterprise Tech Guides</description>
	<lastBuildDate>Mon, 31 Mar 2014 05:39:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
<site xmlns="com-wordpress:feed-additions:1">87744916</site><atom:link rel="search" type="application/opensearchdescription+xml" title="Search Jitendra Zaa" href="https://www.jitendrazaa.com/blog/wp-json/opensearch/1.1/document" />	<item>
		<title>SAP R/3 Audit Review Checklist</title>
		<link>https://www.jitendrazaa.com/blog/others/sap/sap-r3-audit-review-checklist/</link>
					<comments>https://www.jitendrazaa.com/blog/others/sap/sap-r3-audit-review-checklist/#comments</comments>
		
		<dc:creator><![CDATA[Santosh Karemore]]></dc:creator>
		<pubDate>Fri, 02 Jul 2010 17:37:00 +0000</pubDate>
				<category><![CDATA[SAP]]></category>
		<category><![CDATA[SAP Audit Check]]></category>
		<guid isPermaLink="false">http://JitendraZaa.com/blog/?p=509</guid>

					<description><![CDATA[It is always advisable to perform a check on SAP R/3 system a couple of times a year to ensure the tight security of SAP System. Below are few useful Do&#8217;s which can help to achieve the high degree of Security: Review the following:-   System security file parameters (TU02) (e.g. password length/format, forced password sessions,  [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><a href="https://i0.wp.com/jitendrazaa.com/blog/wp-content/uploads/2010/07/SAP.jpg?ssl=1"><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="size-medium wp-image-510 alignleft" src="https://i0.wp.com/jitendrazaa.com/blog/wp-content/uploads/2010/07/SAP-291x300.jpg?resize=291%2C300&#038;ssl=1" alt="" width="291" height="300" /></a>It is always advisable to perform a check on SAP R/3 system a couple of times a year to ensure the tight security of SAP System. Below are few useful Do&#8217;s which can help to achieve the high degree of Security:</p>
<p><strong><span style="text-decoration: underline">Review the following:- </span></strong></p>
<p> System security file parameters (TU02) (e.g. password length/format, forced password sessions,  user failures to end  session etc.) have been set to ensure confidentiality and integrity of password.</p>
<p><strong>      Security-Parameter-Settings-Documentation</strong></p>
<p>1.  Setup and modification of user master records follows a specific procedure and is properly approved by management. </p>
<p>2. Setup and modification of authorizations and profiles follows a specific procedure and is performed by someone <br />
   independent of the person responsible for user master record maintenance. </p>
<p>3. An appropriate naming convention for profiles, authorizations and authorization objects has been developed to help security maintenance and to comply with required SAP R/3 naming conventions. </p>
<p>4. A user master record is created for each user defining a user ID and password. Each user is assigned to a user group, in the user master record, commensurate with their job responsibilities. </p>
<p>5. Check objects (<span style="color: #cc6600">SU24</span>) have been assigned to key transactions) to restrict access to those transaction. </p>
<p>6. Authorization objects and authorizations have been assigned to users based on their job responsibilities and ensuring the SOD (Segregation of duties). </p>
<p>7. Users can maintain only system tables commensurate with their job responsibilities</p>
<p>     <strong>Select a sample of :- </strong></p>
<p>1. Changes to user master records, profiles and authorizations and ensure the changes were properly approved. (The changes can be viewed with transaction (<span style="color: #cc6600">SECR</span>). </p>
<p>2. Verify that a naming convention has been developed for profiles, authorizations and in-house developed authorization objects to ensure that theycan be easily managed and will not be overwritten by a subsequent release upgrade (for Release 2.2 should begin with Y_ or Z_ and for Release 3.0 by Z_ only.) </p>
<p>3. Assess and review of the use of the authorization object <strong>S_TABU_DIS</strong> and review of table authorization classes <br />
   (TDDAT)  whether all system tables are assigned an appropriate authorization class and users are assigned system table maintenance access (Through S_TABU_DIS) based on authorization classes commensurate with their job responsibilities. </p>
<p>4. Assess and review of the use of the authorization objects <strong>S_Program</strong> and <strong>S_Editor</strong> and the review of program classes (TRDIR) whether all programs are assigned the appropriate program class and users are assigned program classes commensurate with their job responsibilities.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.jitendrazaa.com/blog/others/sap/sap-r3-audit-review-checklist/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">509</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Minified using Disk

Served from: www.jitendrazaa.com @ 2026-06-23 12:55:32 by W3 Total Cache
-->