<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: General interview questions in Security R3? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444431#M211161</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Questions that i encountered based on R/3 46C:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. How frequent do you perform transport migration?&lt;/P&gt;&lt;P&gt;2. Understanding of Composite role, Derived Roles, Single Roles&lt;/P&gt;&lt;P&gt;3. Knowledge of SU01, PFCG&lt;/P&gt;&lt;P&gt;4. CUA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Jul 2006 06:19:24 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2006-07-25T06:19:24Z</dc:date>
    <item>
      <title>General interview questions in Security R3?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444430#M211160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;            I just wanted to know what are the questions(in general)to be expected in R3 Security interview(4.6c)&lt;/P&gt;&lt;P&gt;as i am expecting an interview in couple of days..&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;shabana&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jul 2006 17:24:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444430#M211160</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-07-24T17:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: General interview questions in Security R3?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444431#M211161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Questions that i encountered based on R/3 46C:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. How frequent do you perform transport migration?&lt;/P&gt;&lt;P&gt;2. Understanding of Composite role, Derived Roles, Single Roles&lt;/P&gt;&lt;P&gt;3. Knowledge of SU01, PFCG&lt;/P&gt;&lt;P&gt;4. CUA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2006 06:19:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444431#M211161</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-07-25T06:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: General interview questions in Security R3?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444432#M211162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;these are a few quick thoughts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IT-Infrastructure Security, SAP Landscape:&lt;/P&gt;&lt;P&gt;- Network layout and firewalling between systems&lt;/P&gt;&lt;P&gt;- Remote administration, backup, archiving procedures&lt;/P&gt;&lt;P&gt;- Hardening procedures for new systems, new clients, system or client copies&lt;/P&gt;&lt;P&gt;  - examples are locking, unlocking, password changes of users, setting system wide password rules, SM59 configuration, SICF configuration&lt;/P&gt;&lt;P&gt;- Use of cryptographic mechanisms (SNC, SSL)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorizations:&lt;/P&gt;&lt;P&gt;- Does a documented authorization concept exist?&lt;/P&gt;&lt;P&gt;- Of course: Are there SAP_ALL, SAP_NEW users (or any equivalent sort of SAP_ALL)&lt;/P&gt;&lt;P&gt;- How are authorizations of communication / system users managed?&lt;/P&gt;&lt;P&gt;- What kind of functional roles are used (Task roles, job roles, etc.)?&lt;/P&gt;&lt;P&gt;- What kind of technical roles are used (single, composite, derived)?&lt;/P&gt;&lt;P&gt;- Are check indicators used (SU24)?&lt;/P&gt;&lt;P&gt;  - Are there many "manual" authorization objects? (this would indicate that SU24 is not correctly used.)&lt;/P&gt;&lt;P&gt;- Are risky transactions (SU01, PFCG, SM59, SA38, ...) and risky transaction combinations (vendor creation / change and payment processing) known and documented?&lt;/P&gt;&lt;P&gt;- Are procedures in place that control / mitigate the execution of these risks?&lt;/P&gt;&lt;P&gt;- How is user and authorizations management regulated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2006 07:13:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/general-interview-questions-in-security-r3/m-p/1444432#M211162</guid>
      <dc:creator>christian_wippermann</dc:creator>
      <dc:date>2006-07-25T07:13:12Z</dc:date>
    </item>
  </channel>
</rss>

