<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP security for all T_code in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588616#M265136</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;lt;i&amp;gt;"The auditors will KILL you ;)"&amp;lt;/i&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The chances are very good that this role is &amp;lt;b&amp;gt;for&amp;lt;/b&amp;gt; the auditors. They will LOVE you! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Try take SA38 / SE38 away from an auditor! Their working papers grind to a screaching standstill)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Sep 2006 14:19:15 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2006-09-14T14:19:15Z</dc:date>
    <item>
      <title>SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588608#M265128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i need help with making a role that has all possible t_code   which has display authorization only&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2006 20:59:06 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588608#M265128</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-13T20:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588609#M265129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Naimesh,&lt;/P&gt;&lt;P&gt;We used a hard way fo rthis during the creation of a display all role. In the S_Tcode we use ranges so that all tcodes are covered under their ambit. Then the value of the ACTVT has been changed to 03 so that only display role is active,..also note, the Tocdes shd not have sensitive tcodes and basis transactions and hence there the ranges comeinto place. i remember in earlier versions there used to be Display all role in SAP. as tandrd display role and we used to base the new role after modifying the same.&lt;/P&gt;&lt;P&gt;But now its the harder way...&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;P&gt;Award points if this info is helpful...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2006 21:52:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588609#M265129</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-13T21:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588610#M265130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hopefully someone gives a better method for this activity &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt; so that i benefits me aswelll...&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2006 21:52:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588610#M265130</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-13T21:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588611#M265131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are working on version below 4.6c you can find&lt;/P&gt;&lt;P&gt;SAP_ALL_DISPLAY role.&lt;/P&gt;&lt;P&gt;otherwise you got to spend time pulling SAP_ALL,SAP_NEW&lt;/P&gt;&lt;P&gt;and changing the actvities under objects to 03.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2006 23:53:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588611#M265131</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-13T23:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588612#M265132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't find role sap_all_display or sap_all or sap_new&lt;/P&gt;&lt;P&gt;in the activity field do i have to manually change to value to 03 or is there a easy way to change all of them&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2006 02:25:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588612#M265132</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-14T02:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588613#M265133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;until R/3 4.6c SAP used to deliver SAP_ALL_DISPLAY.&lt;/P&gt;&lt;P&gt;i guess they removed it from 4.7 enterprise.&lt;/P&gt;&lt;P&gt;SAP_ALL, SAP_NEW are delivered profiles.&lt;/P&gt;&lt;P&gt;goto PFCG--&amp;gt;authorizations tab.&lt;/P&gt;&lt;P&gt;either you can choose SAP_ALL template or goto edit&lt;/P&gt;&lt;P&gt;insert authorizations--&amp;gt; full authorizations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now you have to maintain ACVT=03 and probably 07 for some objects. this will take lot of time.and you have to be careful with lot other objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;other option,if you have time you can try finding a way to clubb copies of all SAP delivered 'display' roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Keerti Vemulapalli&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Keerti Vemulapalli&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2006 03:13:28 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588613#M265133</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-14T03:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588614#M265134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Option 1 : create a Composite role with copies of all singular standard display roles provided by SAP. (still lot of work to be done)&lt;/P&gt;&lt;P&gt;Option 2 : Download SAP display all from 4.6 to ur desktop and upload it into 4.7 &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt; a small trick used by me initially...and then modify this role accordingly by adding the new Auth objects that exist in 4.7 and higher versions. (unconventional way to do this action but it worked at tht time)&lt;/P&gt;&lt;P&gt;Option 3: SAP_All &amp;amp; SAP_NEW areprofiles and not roles.&lt;/P&gt;&lt;P&gt;Create a new role from PFCG and you have options inthe menu ( Insert authorizations from profile ) there input this profiule and you would get all the auth objects into this role. Then change many things to in ACTVT to 03,16 and 07 and 09 in many cases after checking all the actions. It wd take time but this role is very handy and can be assigned to many non buisness users and developers in Prd environment.&lt;/P&gt;&lt;P&gt;Hope this answer has some inputs for you and points for me&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2006 05:01:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588614#M265134</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-14T05:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588615#M265135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a baaaad idea for so many reasons, I don't even know where to begin &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- NOBODY needs ALL TCodes&lt;/P&gt;&lt;P&gt;- There are many TCodes that can't be restricted by activity&lt;/P&gt;&lt;P&gt;- There are many transactions where even display will have to be considered harmful (HR, conditions, configuration, ...)&lt;/P&gt;&lt;P&gt;- The auditors will KILL you &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need display roles, copy them from the functional roles you have assigned to the workplaces, then check for activities.&lt;/P&gt;&lt;P&gt;Also, this will save you a lot of time because the functional roles will have a LOT less objects to maintain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You really should re-consider your authorizations concept...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Frank.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2006 12:49:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588615#M265135</guid>
      <dc:creator>koehntopp</dc:creator>
      <dc:date>2006-09-14T12:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588616#M265136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;lt;i&amp;gt;"The auditors will KILL you ;)"&amp;lt;/i&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The chances are very good that this role is &amp;lt;b&amp;gt;for&amp;lt;/b&amp;gt; the auditors. They will LOVE you! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Try take SA38 / SE38 away from an auditor! Their working papers grind to a screaching standstill)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Sep 2006 14:19:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588616#M265136</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-14T14:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588617#M265137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is the case - there are pre-configured roles for auditors that do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I definitely wouldn't want an auditor with an all-TCode role in my system... &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2006 07:29:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588617#M265137</guid>
      <dc:creator>koehntopp</dc:creator>
      <dc:date>2006-09-15T07:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588618#M265138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although I principally agree with you... I disagree with you in all other respects. Sorry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out there in the wild the general problem with the auditors and s_tcode is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) there are many of both of them,&lt;/P&gt;&lt;P&gt;b) they look at different things in different ways,&lt;/P&gt;&lt;P&gt;c) it is difficult to know what their entry point is going to be for that which they are going to look at. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in a similar way to how you cannot predict or dictate what an auditor can and cannot look at, you have the same difficulty in S_TCODE most of the time. You are left with even less choice because the accounting companies have audit programs which have "type /nSE38 into the window" etc all over the place and you get harrassed until you give it to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where I also disagree is using the pre-configured role approach (AIS). It limits the auditor to that which SAP "releases" for auditors to look at. Personally I would never accept that.... which may sound nice at first, but at a closer look there are sometimes equally or more hazardous problems lurking there. (E.g. SAP_CA_AUDITOR_SYSTEM -&amp;gt; Post to the G/L? Change SM59 settings? Debug other user's processes? Execute (virtually) any program or c-function? They might give themselves SAP_ALL even if you take all the tcodes away...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you could add a message type "Warning: Transaction &amp;amp; has not been released to be audited" &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2006 09:18:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588618#M265138</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-15T09:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588619#M265139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good points. If that is the case (to be honest - I haven't checked the roles in that detail...), we need to look into that. This should probably not be the default setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point I was trying to make was that there is a better starting point than SAP_ALL. In my opinion, anything that starts by modifying SAP_ALL is doomed from the beginning &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're giving auditors SE38, how do you control that in your environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Frank.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2006 09:32:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588619#M265139</guid>
      <dc:creator>koehntopp</dc:creator>
      <dc:date>2006-09-15T09:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588620#M265140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add that I do find the AIS usefull for finding helpfull reports and transactions which I didn't know about! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can only comment on what I have seen out there in the past years (about 500 SAP systems) which is also the suboptimal starting point you referred to =&amp;gt; Copy SAP_ALL, set the many activity controlling fields to display, remove or restrict a few nasty other objects and range around some naughty tcodes and then give it to the auditors. Given the alternatives, I would say that this is fit-to-purpose. (PS also take a look at the *_display role in the AIS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding SE38, please understand that I do not "have an environment" so I have not controlled this. If I had one, then I would give them SA38 and keep an eye on the reports they are running. When (if) things like RS_TESTFRAME_CALL start turning up then I would move it into a more secure authorization group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also give them SE16 and keep an eye on the tables they are visiting (might even learn a thing or two).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is anyway no substitute for security monitoring, right? And a good auditor should also check that I am doing this!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2006 10:05:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588620#M265140</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-15T10:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588621#M265141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Summary concerning SAP predefined authorization roles for auditors (see note &amp;lt;a href="https://service.sap.com/sap/support/notes/77503"&amp;gt;77503&amp;lt;/a&amp;gt; for details)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The role SAP_CA_AUDITOR_SYSTEM contains authorizations which are needed to access all security related basis functions which might be useful for an system auditor. The role does not contain development authorizations or application authorizations. However, the role contains several other critical authorizations enabling the auditor to change some important system settings. Why? Well, some security related settings are only visible in change mode. You assign this role if you trust the system auditor that he does not misuse his authorizations by accident or knowingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand we deliver the reduced role SAP_CA_AUDITOR_SYSTEM_DISPLAY which contain only these authorizations which offer display-only functionality. A system auditor having this role will be able to perform most system audit steps by himself, but for some areas he will have to ask the system administrators to produce the required reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conclusion: Depending on your requirements you can choose the appropriate role.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2006 13:04:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588621#M265141</guid>
      <dc:creator>Frank_Buchholz</dc:creator>
      <dc:date>2006-09-15T13:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588622#M265142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, if using SAP_ALL is not a good start. How about SAP_ALL_RESTRICTED? Without BC, CA, HR, modify the ACTVT to Display, it should satisfy most needs and without jeopardizing security issues, isn't it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Sep 2006 01:36:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588622#M265142</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-18T01:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588623#M265143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;being an auditor:&lt;/P&gt;&lt;P&gt;I need access to report RSABAPSC - to check source codes for authorization calls.&lt;/P&gt;&lt;P&gt;I need access to S_DEVELOP / DISPLAY for the same reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taking that starting point into account:&lt;/P&gt;&lt;P&gt;If I don't get all the other T-CODEs I need, you will find me using RS_TESTFRAME_CALL a lot &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(BTW: Standard use of RSABAPSC of course is to see whether RS_TESTFRAME_CALL has been patched &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;) On our systems it has been now - but only because we auditors were stupid enough to ask for it. )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The end-result of the whole line of thought is:&lt;/P&gt;&lt;P&gt;If your system is bullet-proof - you will have a lot of work with tight authorizations for the auditors &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I agree:&lt;/P&gt;&lt;P&gt;There is a point where the preventive power of authorizations stops and you have to go for detective measures. And monitoring the auditors is not a bad idea at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ralf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Sep 2006 03:44:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588623#M265143</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-18T03:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: SAP security for all T_code</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588624#M265144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there Ralf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean by auditors were stupid enough?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for RSABAPSC. I used to use RPR_ABAP_SOURCE_SCAN but the bother is that it does not analyze the commented out text or coding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Sep 2006 07:17:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-for-all-t-code/m-p/1588624#M265144</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-09-18T07:17:21Z</dc:date>
    </item>
  </channel>
</rss>

