<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Blueprint doc in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458115#M1056719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't think of anywhere where blueprint docs are available.  Blueprint docs usually take quite a while to put together &amp;amp; there is obvious reluctance of people to make available work which likely remains the property of their company/client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hussein did well to mention ASAP, you can download it and get some useful templates from there.  More info here: &lt;A href="https://websmp101.sap-ag.de/roadmaps" target="test_blank"&gt;https://websmp101.sap-ag.de/roadmaps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a think about stuff like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Objectives&lt;/P&gt;&lt;P&gt;Security Approach&lt;/P&gt;&lt;P&gt;TX to Role Mappings&lt;/P&gt;&lt;P&gt;Restriction Requirements&lt;/P&gt;&lt;P&gt;Compliance Requirements (SOX, internal security standards)&lt;/P&gt;&lt;P&gt;Build Standards&lt;/P&gt;&lt;P&gt;Developer Security standards&lt;/P&gt;&lt;P&gt;User Management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically all the stuff you need to be able to build from your set of blueprint docs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun &amp;amp; good luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Sep 2008 14:21:36 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-09-19T14:21:36Z</dc:date>
    <item>
      <title>Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458110#M1056714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Do we have document / template for SAP security blueprint?&lt;/P&gt;&lt;P&gt;2. What is meaning of AS-IS processes, with respect to security?&lt;/P&gt;&lt;P&gt;3.How do we go about documenting To-Be processes, with respect to security?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;VJ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 22:47:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458110#M1056714</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-18T22:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458111#M1056715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Yes thankyou&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. As-Is means the current procesess.  Your question can be interpreted in 2 ways.  &lt;/P&gt;&lt;P&gt;i. your security design supports the business processes, e.g. transactions &amp;amp; restrictions used and allocation of those to users so they can run those business processes.  &lt;/P&gt;&lt;P&gt;ii. Your current security processes e.g. your user &amp;amp; role creation process etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. The functional team will document the to-be processes.  They (and you) can use these processes to identify inscope transactions, important restrictions (e.g. new doctypes being used) and creation of roles.  There are lots of ways of documenting it, at the minimum you want to capture the new tx to role mapping, important restrictions per business process or functional area &amp;amp; to-be organisational structure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 06:36:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458111#M1056715</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-19T06:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458112#M1056716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;alex&lt;/P&gt;&lt;P&gt;&amp;gt;1. Yes thankyou&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are talking of ASAP doc then I am sorry to say the ASAP security plan is very complex to follow and doc are not comprehensive. &lt;/P&gt;&lt;P&gt;There is nothing as in blue print. Requirements gathering and Testing of role (its and documentation) is not properly explained.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 09:00:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458112#M1056716</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-19T09:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458113#M1056717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &amp;gt;alex&lt;/P&gt;&lt;P&gt;&amp;gt; &amp;gt;1. Yes thankyou&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; If you are talking of ASAP doc then I am sorry to say the ASAP security plan is very complex to follow and doc are not comprehensive. &lt;/P&gt;&lt;P&gt;&amp;gt; There is nothing as in blue print. Requirements gathering and Testing of role (its and documentation) is not properly explained.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not referring to ASAP, though from a security perspective, in my experience, ASAP is fine to follow &amp;amp; use if you spend the time required to get used to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen many, many security blueprints which would benefit from using the various ASAP elements, despite it's weak points.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 09:38:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458113#M1056717</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-19T09:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458114#M1056718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello  Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for answers.&lt;/P&gt;&lt;P&gt;Is there any place i can get a sample of document / template of security blueprint.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Vijay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 12:25:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458114#M1056718</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-19T12:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458115#M1056719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't think of anywhere where blueprint docs are available.  Blueprint docs usually take quite a while to put together &amp;amp; there is obvious reluctance of people to make available work which likely remains the property of their company/client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hussein did well to mention ASAP, you can download it and get some useful templates from there.  More info here: &lt;A href="https://websmp101.sap-ag.de/roadmaps" target="test_blank"&gt;https://websmp101.sap-ag.de/roadmaps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a think about stuff like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security Objectives&lt;/P&gt;&lt;P&gt;Security Approach&lt;/P&gt;&lt;P&gt;TX to Role Mappings&lt;/P&gt;&lt;P&gt;Restriction Requirements&lt;/P&gt;&lt;P&gt;Compliance Requirements (SOX, internal security standards)&lt;/P&gt;&lt;P&gt;Build Standards&lt;/P&gt;&lt;P&gt;Developer Security standards&lt;/P&gt;&lt;P&gt;User Management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically all the stuff you need to be able to build from your set of blueprint docs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun &amp;amp; good luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 14:21:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458115#M1056719</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-09-19T14:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Blueprint doc</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458116#M1056720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I can't think of anywhere where blueprint docs are available.  Blueprint docs usually take quite a while to put together &amp;amp; there is obvious reluctance of people to make available work which likely remains the property of their company/client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very well put Alex! Julius, Maybe a small text like this one could enter the sticky?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 14:25:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security-blueprint-doc/m-p/4458116#M1056720</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-09-19T14:25:22Z</dc:date>
    </item>
  </channel>
</rss>

