Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Firefighter role built from SAP_ALL - proof of fraudulent changes

Former Member
0 Kudos

SAP colleagues - if a firefighter role, built manually from SAP_ALL, allows all access EXCEPT SAP security related authorizations (including global auth check switch) can a user during firefighting activities:

- delete security / transaction logs to hide fraudulent acts?

Would the database tables or any other system tables retain proofs of some or any of the fraudulent changes. Would there be any other proofs of what was done?

Any other worst case scenarios and explanations in this case would be greatly appreciated.

Thank You!

4 REPLIES 4

jurjen_heeck
Active Contributor
0 Kudos

This is a very difficult question to answer as risks may vary from company to company. I suggest you log on to a sandbox system, switch on ana uthorization trace and perform all activities marked as 'fraudulent' one at a time.

After this you should be left with an idea of what to remove from SAP_ALL. Once that's done you wil probabely have broken it so with some retesting and fixing you may end up with the disired role. My suggestion is to focus on blocking user and role management as well as restricting acces to the operating system through SAP.

0 Kudos

Thank Jurjen! User and role mgmnt is blocked. I will also have most other system admin related authorizations removed, including external commands to OS. However, external auditors want proof that we can account for any deleted change / security logs and thus hidden actions.

Is it true that SAP does not allow deletion of security / audit logs less then 3 days old? Also, if someone deletes logs (what are the diffierent ways to do it?) would tables on the db side record some of these actions that could be used as a proof of tempering? Thanks!!

0 Kudos

I think you can better try the forum for that question.

0 Kudos

Jurjen, thank you, I will give GRC forum a try, too.