<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: basis? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150984#M454129</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamal,&lt;/P&gt;&lt;P&gt;From SAP Release 3.1G, SAP has continued to develop the Profile Generator to allow quicker development of authorization profiles. All authorizations should now be created using the Profile Generator, as most new functionality relies upon the assignment of roles to users rather than authorization profiles. It should be noted that assigning a role to a user will automatically assign the corresponding profile.&lt;/P&gt;&lt;P&gt;Benefits provided through the use of the profile generator to define authorization profiles include:&lt;/P&gt;&lt;P&gt;&amp;#149; reduced complexity and ease of use; and&lt;/P&gt;&lt;P&gt;&amp;#149; simplification of role and profile administration. &lt;/P&gt;&lt;P&gt;Mass maintenance of user access security design and structure can now be performed in the profile generator, which will significantly improve efficiency and accuracy of changes being made to a large number of records. When in the menu tab of the profile generator, transaction code names can be toggled on/off by selecting the magnifying glass icon in the top right of the tab. &lt;/P&gt;&lt;P&gt;SIGNIFICANT RISKS&lt;/P&gt;&lt;P&gt;&amp;#149; Unauthorized, or inappropriate, changes to user security resulting in excessive access, or&lt;/P&gt;&lt;P&gt;users not having access to perform functions. &lt;/P&gt;&lt;P&gt;&amp;#149; Authorization values may be inaccurately defined, granting inappropriate access to users.&lt;/P&gt;&lt;P&gt;&amp;#149; SAP standard delivered roles if allocated without configuration may not provide adequate organizational restrictions, or may contain transactions that the organization has deemed to be segregation of duties conflicts.&lt;/P&gt;&lt;P&gt;&amp;#149; Passwords provided to users by security administration staff are standard, or easily guessable, resulting in unauthorized users gaining access to the SAP system.&lt;/P&gt;&lt;P&gt;A significant amount of attention is currently focused on Section 302 (Disclosure) and Section 404 (Internal Controls) of  &amp;lt;b&amp;gt;Sarbanes-Oxley Sections&amp;lt;/b&amp;gt;. This is how Security has become a very bif concern for all the companies.&lt;/P&gt;&lt;P&gt;&amp;lt;b&amp;gt;Frequently used security T-codes&amp;lt;/b&amp;gt; &lt;/P&gt;&lt;P&gt;SU01 Create/ Change User SU01 Create/ Change User &lt;/P&gt;&lt;P&gt;PFCG Maintain Roles&lt;/P&gt;&lt;P&gt;SU10 Mass Changes&lt;/P&gt;&lt;P&gt;SU01D Display User&lt;/P&gt;&lt;P&gt;SUIM Reports&lt;/P&gt;&lt;P&gt;ST01 Trace&lt;/P&gt;&lt;P&gt;SU53 Authorization analysis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whereas a Basis Consultant will have to deal with Installations, Upgradation, Spool Administration, Etc....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Please award points if it is useful.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 Apr 2007 06:46:05 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2007-04-14T06:46:05Z</dc:date>
    <item>
      <title>basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150982#M454127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi all.,&lt;/P&gt;&lt;P&gt;  wats the major diffnce between basis guy n security?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2007 04:04:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150982#M454127</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-14T04:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150983#M454128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Some yrs back thre was a very thin line of difference between system admin and security. Now the concept of Information Security Managent has changed drastically and a lot of emphasis is being given to this. Basically it deals with recognising threats towards information and taking protective measures in this regard.International standards has been formulated to provide a model for  establishing,implementing, operating, monitoring,reviewing,maintaining and improving an Information Security MAnagement System(ISMS). ISO 270001 deals with these things.&lt;/P&gt;&lt;P&gt;To know about Security (not only relating to SAP but relating to Information system as a whole) pl visit :&lt;/P&gt;&lt;P&gt; &lt;A href="https://community.sap.com/www.stqc.nic.in" target="test_blank"&gt;www.stqc.nic.in&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It feels good to see that SAP has intelligently taken care of this aspect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this throws some light on your querry.&lt;/P&gt;&lt;P&gt;Pl dont forget to award points suitably.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2007 05:50:58 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150983#M454128</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-14T05:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150984#M454129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamal,&lt;/P&gt;&lt;P&gt;From SAP Release 3.1G, SAP has continued to develop the Profile Generator to allow quicker development of authorization profiles. All authorizations should now be created using the Profile Generator, as most new functionality relies upon the assignment of roles to users rather than authorization profiles. It should be noted that assigning a role to a user will automatically assign the corresponding profile.&lt;/P&gt;&lt;P&gt;Benefits provided through the use of the profile generator to define authorization profiles include:&lt;/P&gt;&lt;P&gt;&amp;#149; reduced complexity and ease of use; and&lt;/P&gt;&lt;P&gt;&amp;#149; simplification of role and profile administration. &lt;/P&gt;&lt;P&gt;Mass maintenance of user access security design and structure can now be performed in the profile generator, which will significantly improve efficiency and accuracy of changes being made to a large number of records. When in the menu tab of the profile generator, transaction code names can be toggled on/off by selecting the magnifying glass icon in the top right of the tab. &lt;/P&gt;&lt;P&gt;SIGNIFICANT RISKS&lt;/P&gt;&lt;P&gt;&amp;#149; Unauthorized, or inappropriate, changes to user security resulting in excessive access, or&lt;/P&gt;&lt;P&gt;users not having access to perform functions. &lt;/P&gt;&lt;P&gt;&amp;#149; Authorization values may be inaccurately defined, granting inappropriate access to users.&lt;/P&gt;&lt;P&gt;&amp;#149; SAP standard delivered roles if allocated without configuration may not provide adequate organizational restrictions, or may contain transactions that the organization has deemed to be segregation of duties conflicts.&lt;/P&gt;&lt;P&gt;&amp;#149; Passwords provided to users by security administration staff are standard, or easily guessable, resulting in unauthorized users gaining access to the SAP system.&lt;/P&gt;&lt;P&gt;A significant amount of attention is currently focused on Section 302 (Disclosure) and Section 404 (Internal Controls) of  &amp;lt;b&amp;gt;Sarbanes-Oxley Sections&amp;lt;/b&amp;gt;. This is how Security has become a very bif concern for all the companies.&lt;/P&gt;&lt;P&gt;&amp;lt;b&amp;gt;Frequently used security T-codes&amp;lt;/b&amp;gt; &lt;/P&gt;&lt;P&gt;SU01 Create/ Change User SU01 Create/ Change User &lt;/P&gt;&lt;P&gt;PFCG Maintain Roles&lt;/P&gt;&lt;P&gt;SU10 Mass Changes&lt;/P&gt;&lt;P&gt;SU01D Display User&lt;/P&gt;&lt;P&gt;SUIM Reports&lt;/P&gt;&lt;P&gt;ST01 Trace&lt;/P&gt;&lt;P&gt;SU53 Authorization analysis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whereas a Basis Consultant will have to deal with Installations, Upgradation, Spool Administration, Etc....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Please award points if it is useful.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2007 06:46:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150984#M454129</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-14T06:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150985#M454130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt; need link about how  transports are done within the system r  between the system?what are all the transactions used for it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2007 16:50:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150985#M454130</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-14T16:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150986#M454131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamal,&lt;/P&gt;&lt;P&gt;With in the system we use SCC1 tcode to copy transports form one client to other.&lt;/P&gt;&lt;P&gt;Across systems we use STMS  as the tcode.&lt;/P&gt;&lt;P&gt;Hope it helps and also advice u to open a new thread as this is a solved thrd.&lt;/P&gt;&lt;P&gt;Award points for helpful answers&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Apr 2007 07:38:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150986#M454131</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-15T07:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: basis?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150987#M454132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kamal, in addition to what the previous posters have stated, there are also different skills required for security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While there is a reasonable element of technical understanding needed, a security resource should also have an understanding of the major business processes, how SAP implements them, the main risks in each of and between them, and how the security mechanisms in SAP can be used as a control point to mitigate those risks.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Increasingly, a working knowledge of general IT controls and an understanding of compliance and control frameworks is necessary.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 08:47:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/basis/m-p/2150987#M454132</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2007-04-16T08:47:51Z</dc:date>
    </item>
  </channel>
</rss>

