<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008515#M409700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Kamal,&lt;/P&gt;&lt;P&gt;Just read this nice explanation on SAP help..&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04/helpdata/en/63/a30a4ac00811d2851c0000e8a57770/content.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04/helpdata/en/63/a30a4ac00811d2851c0000e8a57770/content.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It shdould help u in getting the over view...&lt;/P&gt;&lt;P&gt;Ping back to us in case of questions...&lt;/P&gt;&lt;P&gt;VBr,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;P&gt;Award points for helpful answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Mar 2007 19:24:13 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2007-03-19T19:24:13Z</dc:date>
    <item>
      <title>security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008514#M409699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey,&lt;/P&gt;&lt;P&gt;in all the business scenarios there r DEV,QA,PRD.can som1 kindly explain what is actually happening in these systems n the role of sap security guy in all these three?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2007 19:04:31 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008514#M409699</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-19T19:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008515#M409700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Kamal,&lt;/P&gt;&lt;P&gt;Just read this nice explanation on SAP help..&lt;/P&gt;&lt;P&gt;&lt;A href="http://help.sap.com/saphelp_nw04/helpdata/en/63/a30a4ac00811d2851c0000e8a57770/content.htm" target="test_blank"&gt;http://help.sap.com/saphelp_nw04/helpdata/en/63/a30a4ac00811d2851c0000e8a57770/content.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It shdould help u in getting the over view...&lt;/P&gt;&lt;P&gt;Ping back to us in case of questions...&lt;/P&gt;&lt;P&gt;VBr,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;P&gt;Award points for helpful answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2007 19:24:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008515#M409700</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-19T19:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008516#M409701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kamal,&lt;/P&gt;&lt;P&gt;High level overview:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In SAP most work is done in development then transported to QA for testing.  Once testing passes it is moved into PRD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DEV&lt;/P&gt;&lt;P&gt;Used for development and configuration.  The security person needs to insure only approved developers and configurers have change access.  In addition modifications  requiring transport should go through a change control process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;QA&lt;/P&gt;&lt;P&gt;Used For testing.  Should resemble production as much as possible in order to produce accurate testing.   Direct access to development and config should be restricted in this instance (generally speaking).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PRD&lt;/P&gt;&lt;P&gt;End users have transaction access and administrators should be limited.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2007 19:24:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008516#M409701</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-19T19:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008517#M409702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A security guy, handles on  a number of times the Authorizations and related issues in these systems....&lt;/P&gt;&lt;P&gt;Ideally he makes the changes in DEV systems, moves them to QTY for the tests and once the Tests are successull, the transports would be moved ot PRD.&lt;/P&gt;&lt;P&gt;In a nut shell, thats how every change mkoves across in trhe SAP system.,&lt;/P&gt;&lt;P&gt;Hope it helps...&lt;/P&gt;&lt;P&gt;VBr,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;P&gt;Award poiints for helpful answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2007 19:25:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008517#M409702</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-19T19:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008518#M409703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;dev ,qa prd are the three diff clients in sap system,rite?so in dev ,customizing  refers to the functional guy ,developers according to the business need they edit sap.then these changes are transported to qa.wat is the actuall purpose of qa?it just checks whethr the transport is done r any missing links?so the role of sap security in dev is to restrict developers and functional guys and exclusively creates role for devlopers etc not for the end users?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;    In prd again the security guy creates the role according to the business needs inorder to assign to end user?  pls let me b clear....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 01:50:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008518#M409703</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-20T01:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008519#M409704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi kamal,&lt;/P&gt;&lt;P&gt;The securoty guy does not develop any thing for business in PRD. the same is developed in DEV system only and tested in QTY by a few people who don the cap of a End user... so the security guy has to take care of both the consultant roles and buisness users roles...&lt;/P&gt;&lt;P&gt;also in QTY integration testing etc... once a developer developes a programm, module or a user exit, we test that development in DEV system as a unit...&lt;/P&gt;&lt;P&gt;so its called unit testing... and once we move it to QTY, it is tested on a different angle, like does this change affect any other module, does it have a impacxt on any other working programm etc etc... once all the checks are made and if it has got a satisfactory perfromance then only the new program, new tcode or whatever be it is moved to production...&lt;/P&gt;&lt;P&gt;The same procedure is even followed while applying SAP Notes to the systems..&lt;/P&gt;&lt;P&gt;Hope it is clear now..&lt;/P&gt;&lt;P&gt;VBr,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;P&gt;Award points for helpful answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2007 05:42:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/security/m-p/2008519#M409704</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-03-20T05:42:49Z</dc:date>
    </item>
  </channel>
</rss>

