<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question on Sensitive T-Codes in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658436#M292076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello gurus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our few remaining open Internal Audit issues is - use of t-code SM01&lt;/P&gt;&lt;P&gt;to lock sensitive t-codes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main problem we have with this one is that we do not have any&lt;/P&gt;&lt;P&gt;information on which t-codes are considered 'sensitive' enough to be&lt;/P&gt;&lt;P&gt;locked, or what is considered best practice in this area.&lt;/P&gt;&lt;P&gt;I checked the SAP Notes website but there is no guidance there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which ones were considered to be sensitive)&lt;/P&gt;&lt;P&gt;or if you have any guidelines or other information on which-codes should be&lt;/P&gt;&lt;P&gt;locked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Ricky Orea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Nov 2006 17:08:50 GMT</pubDate>
    <dc:creator>former_member184386</dc:creator>
    <dc:date>2006-11-22T17:08:50Z</dc:date>
    <item>
      <title>Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658436#M292076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello gurus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our few remaining open Internal Audit issues is - use of t-code SM01&lt;/P&gt;&lt;P&gt;to lock sensitive t-codes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main problem we have with this one is that we do not have any&lt;/P&gt;&lt;P&gt;information on which t-codes are considered 'sensitive' enough to be&lt;/P&gt;&lt;P&gt;locked, or what is considered best practice in this area.&lt;/P&gt;&lt;P&gt;I checked the SAP Notes website but there is no guidance there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which ones were considered to be sensitive)&lt;/P&gt;&lt;P&gt;or if you have any guidelines or other information on which-codes should be&lt;/P&gt;&lt;P&gt;locked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Ricky Orea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 17:08:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658436#M292076</guid>
      <dc:creator>former_member184386</dc:creator>
      <dc:date>2006-11-22T17:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658437#M292077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ricky,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would discourage you from just obtaining a list and locking them.  If it were as simple as this blanket approach, then the tcodes probably would be locked as a default!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you obtain this information from the Internal Controls Framework to determine the activities, and therefore the tcodes that are of a critical nature as you may find that due to other mitigating controls in place, you may not need to lock many, if any, at all.  That is, the inherent risk may be high, but the residual risk may be low due to the control activities already in place according to the Internal Controls framework, such as roles that adequately restrict from executing the critical transactions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Internal Audit group is normally the custodians/owners of the Internal Controls documentation, so just ask them for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS.  'Sensitive' normally relates to &amp;lt;b&amp;gt;information&amp;lt;/b&amp;gt; that is of a sensitive nature (ie, risk of display) such as HR salary information.  'Critical' normally refers to tcodes that are able to perform an activity that may put the environment at risk (ie, risk of maintain) such as client administration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 02:46:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658437#M292077</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-11-23T02:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658438#M292078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ricky&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Nov 2006 16:46:53 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658438#M292078</guid>
      <dc:creator>former_member184386</dc:creator>
      <dc:date>2006-11-24T16:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658439#M292079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Usually SE* codes are considered critical based on their functionalities especially in PRD system. SM* codes too can be considered critical because it gives accessibility to some critic al tables where information about the operating procedure resides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Senstive could mean your custom codes that gives access to pulling reports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Nov 2006 15:49:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658439#M292079</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-11-25T15:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658440#M292080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ricky,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Main info of the above can be obtained from Tcode SECR.&lt;/P&gt;&lt;P&gt;List of Critical transactions /Critical authorizations can be found.&lt;/P&gt;&lt;P&gt;But they are not specific to Business but generally recommended&lt;/P&gt;&lt;P&gt;by SAP which even auditors refer. Filter and review those which&lt;/P&gt;&lt;P&gt;your require.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards / Jayaraman Krishnamurthy&lt;/P&gt;&lt;P&gt;Intelligroup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2006 05:55:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658440#M292080</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-12-01T05:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658441#M292081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jayaraman,&lt;/P&gt;&lt;P&gt;Was just looking through this topic and you had mentioned looking at transaction code SECR. Would this be in BW because I'm getting a message saying this transaction does not exist!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jayashree&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Dec 2006 20:38:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658441#M292081</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-12-05T20:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658442#M292082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jayashree,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In BIW you may not find the tcode. Here it is auditing is Role based. Certain predefined roles exist which you need to use as template and assign&lt;/P&gt;&lt;P&gt;to the user master record. (note 754273)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ricky,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;critical transaction are many. from technical point of view i would list&lt;/P&gt;&lt;P&gt;some of them below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SCC* transactions&lt;/P&gt;&lt;P&gt;Many of SE* transactions are critical.&lt;/P&gt;&lt;P&gt;SPRO&lt;/P&gt;&lt;P&gt;All basis transactions are critical if assigned to non technical users.&lt;/P&gt;&lt;P&gt;SLICENSE&lt;/P&gt;&lt;P&gt;SM49&lt;/P&gt;&lt;P&gt;SM59&lt;/P&gt;&lt;P&gt;and so on &lt;/P&gt;&lt;P&gt;regards / Jayaraman Krishnamurthy&lt;/P&gt;&lt;P&gt;Intelligroup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2006 09:49:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658442#M292082</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-12-06T09:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658443#M292083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ricky Orea,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The most sensitive t-codes people consider in SAP .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AL01	SAP alert monitor&lt;/P&gt;&lt;P&gt;AL02	Database alert monitor&lt;/P&gt;&lt;P&gt;AL03	Operating system alert monitor&lt;/P&gt;&lt;P&gt;AL04	Monitor call distribution&lt;/P&gt;&lt;P&gt;AL05	Monitor current workload&lt;/P&gt;&lt;P&gt;AL06	Performance: Upload/Download&lt;/P&gt;&lt;P&gt;AL07	EarlyWatch Report&lt;/P&gt;&lt;P&gt;AL08	Users logged on&lt;/P&gt;&lt;P&gt;AL09	Data for database expertise&lt;/P&gt;&lt;P&gt;AL10	Download to Early Watch&lt;/P&gt;&lt;P&gt;AL11	Display SAP Directories&lt;/P&gt;&lt;P&gt;AL12	Display table buffer (Exp. Session)&lt;/P&gt;&lt;P&gt;AL13	Display shared memory (Expert mode)&lt;/P&gt;&lt;P&gt;AL15	Customize SAPOSCOL destination&lt;/P&gt;&lt;P&gt;AL16	Local alert monitor for operating system&lt;/P&gt;&lt;P&gt;AL17	Remote alert monitor for operating system&lt;/P&gt;&lt;P&gt;AL19	Remote file system monitor&lt;/P&gt;&lt;P&gt;AL20	EarlyWatch data collector list&lt;/P&gt;&lt;P&gt;DB01	Analyze exclusive lockwaits&lt;/P&gt;&lt;P&gt;DB02	Analyze tables and indexes&lt;/P&gt;&lt;P&gt;DB03	Parameter changes in database&lt;/P&gt;&lt;P&gt;DB12	Overview of backup logs&lt;/P&gt;&lt;P&gt;DB14	Show SAPDBA action logs&lt;/P&gt;&lt;P&gt;OS01	LAN check with ping&lt;/P&gt;&lt;P&gt;OS02	Operating system configuration&lt;/P&gt;&lt;P&gt;OS03	O/S parameter changes&lt;/P&gt;&lt;P&gt;OS04	Local system configuration&lt;/P&gt;&lt;P&gt;OS05	Remote system configuration&lt;/P&gt;&lt;P&gt;OS06	Local operating system activity&lt;/P&gt;&lt;P&gt;OS07	Remote operating system activity&lt;/P&gt;&lt;P&gt;PFCG	Profile Generator&lt;/P&gt;&lt;P&gt;RZ01	Job Scheduling Monitor&lt;/P&gt;&lt;P&gt;RZ02	Network graphics for SAP instances&lt;/P&gt;&lt;P&gt;RZ03	Presentation, Control SAP instances&lt;/P&gt;&lt;P&gt;RZ04	Maintain SAP instance&lt;/P&gt;&lt;P&gt;RZ08	SAP Alert Monitor&lt;/P&gt;&lt;P&gt;RZ10	Profile parameters&lt;/P&gt;&lt;P&gt;RZ11	Dynamic change of parameters&lt;/P&gt;&lt;P&gt;SCC4	Client creation &lt;/P&gt;&lt;P&gt;SCC5	Client deletion&lt;/P&gt;&lt;P&gt;SCC7	Post-Client Import Methods&lt;/P&gt;&lt;P&gt;SCC8	Client Export&lt;/P&gt;&lt;P&gt;SCC9	Remote Client Copy&lt;/P&gt;&lt;P&gt;SDBE	Matchcode objects (test)&lt;/P&gt;&lt;P&gt;SE01 	 old, replaced by Workbench Organizer&lt;/P&gt;&lt;P&gt;SE06 	Used to set up and maintain the Workbench Organizer (Dictionary Access)&lt;/P&gt;&lt;P&gt;SE09 - 	Enables the ABAP/4 Development Workbench&lt;/P&gt;&lt;P&gt;SE10 - 	Customizing&lt;/P&gt;&lt;P&gt;SE11	ABAP/4 Data Dictionary Maintenance&lt;/P&gt;&lt;P&gt;SE12	ABAP/4 Data Dictionary Display&lt;/P&gt;&lt;P&gt;SE12	ABAP/4 Dictionary Display&lt;/P&gt;&lt;P&gt;SE13	Maintain Technical Settings (Tables)&lt;/P&gt;&lt;P&gt;SE14	Utilities for Dictionary Tables&lt;/P&gt;&lt;P&gt;SE15	ABAP/4 Repository Information System&lt;/P&gt;&lt;P&gt;SE15	ABAP/4 Repository Information System&lt;/P&gt;&lt;P&gt;SE16	Data Browser&lt;/P&gt;&lt;P&gt;SE30	ABAP/4 Runtime Analysis&lt;/P&gt;&lt;P&gt;SE38	ABAP/4 Editor&lt;/P&gt;&lt;P&gt;SM02	System Messages&lt;/P&gt;&lt;P&gt;SM04	User Overview&lt;/P&gt;&lt;P&gt;SM12	Display and delete locks&lt;/P&gt;&lt;P&gt;SM13	Display update records&lt;/P&gt;&lt;P&gt;SM18	Reorganize Security Audit Log&lt;/P&gt;&lt;P&gt;SM19	Security Audit Configuration&lt;/P&gt;&lt;P&gt;SM20	Security Audit Log Assessment&lt;/P&gt;&lt;P&gt;SM21	System log&lt;/P&gt;&lt;P&gt;SM28	Installation check&lt;/P&gt;&lt;P&gt;SM37	Background job overview&lt;/P&gt;&lt;P&gt;SM39	Job analysis&lt;/P&gt;&lt;P&gt;SM50	Work Process Overview&lt;/P&gt;&lt;P&gt;SM51	List of SAP servers&lt;/P&gt;&lt;P&gt;SM52	Unix command line&lt;/P&gt;&lt;P&gt;SM56	Number Range Buffer&lt;/P&gt;&lt;P&gt;SM58	Asynchronous RFC Error log&lt;/P&gt;&lt;P&gt;SM59	RFC Destinations (Display/Maintain)&lt;/P&gt;&lt;P&gt;SM65	Background processing analysis tool&lt;/P&gt;&lt;P&gt;SM66	Systemwide work process overview&lt;/P&gt;&lt;P&gt;SMGW	Gateway monitor&lt;/P&gt;&lt;P&gt;SMLG	Maintain logon group&lt;/P&gt;&lt;P&gt;SP01	Output controller&lt;/P&gt;&lt;P&gt;ST01	System Trace 	In file /usr/sap/&amp;lt;SID&amp;gt;/&amp;lt;Instance&amp;gt;/log/Trace000&lt;/P&gt;&lt;P&gt;ST02	Setups/Tune Buffers	Contains a list including all authorization objects &lt;/P&gt;&lt;P&gt;ST03	Performance, SAP statistics, workload	that were checked and their required values, for&lt;/P&gt;&lt;P&gt;ST04	Select activity of the databases	each entered transaction code.&lt;/P&gt;&lt;P&gt;ST05	SQL Trace	&lt;/P&gt;&lt;P&gt;ST06	Operating System Monitor	&lt;/P&gt;&lt;P&gt;ST07	Application Monitor	&lt;/P&gt;&lt;P&gt;ST08	Network Monitor	&lt;/P&gt;&lt;P&gt;ST09	Network Alert Monitor	&lt;/P&gt;&lt;P&gt;ST10	Table call statistics	&lt;/P&gt;&lt;P&gt;ST11	Display developer traces	&lt;/P&gt;&lt;P&gt;ST12	Application monitor	&lt;/P&gt;&lt;P&gt;ST14	Application analysis	&lt;/P&gt;&lt;P&gt;ST22	ABAP/4 Runtime Error Analysis	&lt;/P&gt;&lt;P&gt;STAT	Local transaction statistics	&lt;/P&gt;&lt;P&gt;STUN	Menu performance monitor	&lt;/P&gt;&lt;P&gt;SU01	Maintain users	&lt;/P&gt;&lt;P&gt;SU02	Allocate authorizations to a profile	&lt;/P&gt;&lt;P&gt;SU03	Maintenance of Authorizations	&lt;/P&gt;&lt;P&gt;SU10	Delete/add a profile for all users	&lt;/P&gt;&lt;P&gt;SU12	Delete all users	&lt;/P&gt;&lt;P&gt;SU24	Auth. Obj. Check Under Transactions	&lt;/P&gt;&lt;P&gt;SU50	Maintain user defaults	&lt;/P&gt;&lt;P&gt;SU53	Authorization Trace	&lt;/P&gt;&lt;P&gt;TKOF	Turn off oracle trace	&lt;/P&gt;&lt;P&gt;TKON	Turn off oracle trace	&lt;/P&gt;&lt;P&gt;TKPR	Display trace file	&lt;/P&gt;&lt;P&gt;TU01	Call statistics	&lt;/P&gt;&lt;P&gt;TU02	Parameter changes	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shyam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2006 21:13:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658443#M292083</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-12-07T21:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Sensitive T-Codes</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658444#M292084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be aware however, that many of the above transactions are business critical.  That is, if you lock them, your production system will not be administered properly (eg, SU01 is used to maintain users.  If you lock it, then you can't create users!).  They may have a certain level of risk associated with these tcodes, but they shouldn't all be 'forbidden' to be used in a production system.  If you follow fundamental role design (ie, ensure risks are appropriately mitigated), then the more 'risky' tcodes will only be assigned to the appropriate users, under the appropriate conditions, with the appropriate mitigating controls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I maintain that you should consult the internal audit/compliance/internal controls team for their internal controls framework and from that you can extrapolate the transactions that should be locked (if any).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2006 04:19:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/question-on-sensitive-t-codes/m-p/1658444#M292084</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-12-12T04:19:19Z</dc:date>
    </item>
  </channel>
</rss>

