{"id":110491,"date":"2022-02-17T08:00:00","date_gmt":"2022-02-17T07:00:00","guid":{"rendered":"http:\/\/e3mag.com\/?p=110491"},"modified":"2024-01-19T11:30:10","modified_gmt":"2024-01-19T10:30:10","slug":"after-the-test-is-before-the-test","status":"publish","type":"post","link":"https:\/\/e3mag.com\/en\/nach-der-pruefung-ist-vor-der-pruefung\/","title":{"rendered":"After the Test is the Same as Before the Test"},"content":{"rendered":"<p>SAP authorization concepts are subject to constant change. This is precisely why authorizations such as \"SAP_ALL\" or the protection of SAP standard users, but also SoD risks (Segregation of Duties), are checked anew by auditors every year. The list of necessary measures is long, from applying security patches to controlling and reducing critical authorizations.<\/p>\n\n\n\n<p>Often, security specialists such as Sast Solutions are then hired at short notice to ensure that the finding list from last year's auditor's audit is<br>has been thoroughly processed and that no serious risks have been added since the cleanup, whether debug and replace, deletion of change documents or start of all reports for individual critical authorizations. One reason for these ad hoc orders is that, due to a lack of resources in the meantime, there was no follow-up review of the cleanups after the previous audit.<\/p><div id=\"great-1327147108\" class=\"great-fullsize-content-en great-entity-placement\" style=\"margin-bottom: 20px;\"><a data-no-instant=\"1\" href=\"https:\/\/www.youtube.com\/watch?v=6ZGXMPyM-nU\" rel=\"noopener\" class=\"a2t-link\" target=\"_blank\" aria-label=\"banner_26-04_29_1200x150\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1.jpg\" alt=\"\"  srcset=\"https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1.jpg 1200w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-400x50.jpg 400w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-768x96.jpg 768w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-100x13.jpg 100w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-480x60.jpg 480w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-640x80.jpg 640w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-720x90.jpg 720w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-960x120.jpg 960w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-1168x146.jpg 1168w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-18x2.jpg 18w, https:\/\/e3mag.com\/wp-content\/uploads\/2026\/03\/banner_26-04_29_1200x150-1-600x75.jpg 600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" width=\"1200\" height=\"150\"  style=\" max-width: 100%; height: auto;\" \/><\/a><\/div>\n\n\n\n<p>If one restricts oneself to this reactive procedure, the annual cycle is programmed. If all old findings have just been eliminated or mitigated before the next audit, the auditor will not only test them, but of course also perform further audits, create a new finding list - and the game starts all over again.<\/p>\n\n\n\n<p>To prevent damage in the short term, a point-in-time action is therefore necessary, but not promising. The compliance status of the system immediately deteriorates again due to the assignment of new authorizations, and creeping back in is not proactively prevented. New risks are often not identified during the course of the year, but only when the next audit is due. Thus, there is no continuous work on improving the situation, nor is there permanent risk control. This is because each audit is only a snapshot. A finding list always shows only a small section of the risks in an SAP system.<\/p>\n\n\n\n<p>The solution to this problem is relatively simple: don't wait until the next audit, but become aware of your own vulnerabilities now. This is the only way to ensure the security of SAP systems throughout the year and maintain a rapid response capability in the event of anomalies. The easiest and most thorough way to do this is to use a tool-based, holistic solution for SAP threat detection and access governance such as Sast Suite. This not only takes care of comprehensive real-time monitoring, but also integrates cyclical checks up to the creation of an audit plan with its own policy for the auditor's finding list.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/e3mag.com\/partners\/sast-solutions-ag\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"112\" src=\"https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner.jpg\" alt=\"https:\/\/e3mag.com\/partners\/sast-solutions-ag\/\" class=\"wp-image-69882\" srcset=\"https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner.jpg 1000w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-768x86.jpg 768w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-100x11.jpg 100w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-480x54.jpg 480w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-640x72.jpg 640w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-720x81.jpg 720w, https:\/\/e3mag.com\/wp-content\/uploads\/2020\/10\/Sast-CI-Banner-960x108.jpg 960w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><\/figure>","protected":false},"excerpt":{"rendered":"<p>Every year, as every SAP and security manager knows, the auditor's audit is due. And yet there is often uncertainty about the current risk situation of SAP systems.<\/p>","protected":false},"author":2207,"featured_media":137347,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"pmpro_default_level":"","footnotes":""},"categories":[40127,6],"tags":[13400,40130,39537,31],"coauthors":[38401],"class_list":["post-110491","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mag-21-12","category-wirtschaft","tag-audit","tag-mag-21-12","tag-sast-solutions","tag-wirtschaft","pmpro-has-access"],"acf":[],"featured_image_urls_v2":{"full":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"thumbnail":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-150x150.jpg",150,150,true],"medium":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-400x180.jpg",400,180,true],"medium_large":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-768x346.jpg",768,346,true],"large":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"image-100":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-100x45.jpg",100,45,true],"image-480":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-480x216.jpg",480,216,true],"image-640":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-640x288.jpg",640,288,true],"image-720":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-720x324.jpg",720,324,true],"image-960":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-960x432.jpg",960,432,true],"image-1168":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-1168x526.jpg",1168,526,true],"image-1440":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"image-1920":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"1536x1536":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"2048x2048":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"trp-custom-language-flag":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-18x8.jpg",18,8,true],"bricks_large_16x9":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"bricks_large":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"bricks_large_square":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps.jpg",1200,540,false],"bricks_medium":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-600x270.jpg",600,270,true],"bricks_medium_square":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-600x540.jpg",600,540,true],"profile_24":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-24x24.jpg",24,24,true],"profile_48":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-48x48.jpg",48,48,true],"profile_96":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-96x96.jpg",96,96,true],"profile_150":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-150x150.jpg",150,150,true],"profile_300":["https:\/\/e3mag.com\/wp-content\/uploads\/2022\/02\/Steps-300x300.jpg",300,300,true]},"post_excerpt_stackable_v2":"<p>Alle Jahre wieder, das ist jedem SAP- und Security-Verantwortlichen klar, steht das Wirtschaftspr\u00fcfer-Audit an. Und trotzdem herrscht dann oft Unsicherheit \u00fcber die aktuelle Risikosituation der SAP-Systeme.<\/p>\n","category_list_v2":"<a href=\"https:\/\/e3mag.com\/en\/category\/mag-21-12\/\" rel=\"category tag\">MAG 21-12<\/a>, <a href=\"https:\/\/e3mag.com\/en\/category\/wirtschaft\/\" rel=\"category tag\">Wirtschaft<\/a>","author_info_v2":{"name":"SAST SOLUTIONS","url":"https:\/\/e3mag.com\/en\/author\/sast-solutions\/"},"comments_num_v2":"0 comments","_links":{"self":[{"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/posts\/110491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/users\/2207"}],"replies":[{"embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/comments?post=110491"}],"version-history":[{"count":1,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/posts\/110491\/revisions"}],"predecessor-version":[{"id":137348,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/posts\/110491\/revisions\/137348"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/media\/137347"}],"wp:attachment":[{"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/media?parent=110491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/categories?post=110491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/tags?post=110491"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/e3mag.com\/en\/wp-json\/wp\/v2\/coauthors?post=110491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}