Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP Security Notes - application cadence?

Former Member
0 Likes
719

Our auditors have suggested that we need to increase the frequency of which SAP security notes are applied to our systems, i.e. Hot News/Severity 1 within 30 days, Highs/Severity 2 within 60 days, etc.

I can understand the desire/need but feel that might not be the right balance between keeping the systems secure and meeting the needs of the business through enhancements much more "tangible" to them, especially given tight IT resources.

Best practice aside, I'm interested in knowing more about what others are actually doing in this regard. How often are others applying security notes depending on their severity?

1 REPLY 1
Read only

former_member612251
Participant
632

CVSS score is a good place to start. Anything from 6.9 or higher I would implement immediately. All others could be fitted around the usual patching.