cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP_ALL and SAP_NEW - Usage Log Review

former_member245311
Participant
0 Kudos
2,344

Dear Firends, We have dialog user id's [ DDIC & SAP* ] & couple of Service User id's with SAP_ALL & SAP_NEW. Audit has requested that a monthly review be put in place.

Please let me know the following: -

1. Can SM20 security logs be activated only for specific id's. If yes, please let us know how ?

2. Or Can STAD logs suffice the need ?

3. Please share if any additional best practices.

Thanks

Raj

Accepted Solutions (1)

Accepted Solutions (1)

mostafa_signifysolution
Active Participant

As Warren has mentioned, SAP generic IDs should be locked and not used, especially SAP*; this account should never be really used after implementation. There are some cases where you would need to use DDIC but that should follow your firefighter process.

Also, for non-dialog users should also follow least privileges principles; giving them every single role/profile in SAP is not required and most importantly not needed.

In terms of responding to your audit requirement,

1. You need to clean up your user/role assignment that is and should be your first task.

2. Once you clean up your roles & profile assignment, if you want to monitor specific elevated accounts, then you can use multiple sources to evaluate the user activities beyond just execution of a program or a tcode (i.e. by looking at the STAD data). Each of these logs will serve a different purpose, including looking at AUT10 tcode (table logs & change docs document), STAD logs for transaction/programs history, Security Audit Logs (SM20) for transaction & client maintenance activities and System logs (SM21) for system activities (e.g. debug).

At the end of the day, the "remediation" is not to put in place a monitoring activity, because monitoring activity should not reduce the risk to the acceptable level. Your options is to remediate by fixing your roles/profile assignment and then mitigating the residual risk by putting monitoring activities for what matters.

PS: Yes SM20 can be enabled for targeted users. You configure that though SM19. There are tons of notes and SAP articles that shows you how to configure SAP Security Audit Logs (SAL - SM20) reports.

    Answers (2)

    Answers (2)

    warren_angerstein3
    Active Participant

    Best practice is DDIC and SAP* are locked and not usable without approval and specific needs. Service users also should have only the authorizations they need to fulfill their function. Both of these practices are a security risk if not followed.

    S_Sriram
    Active Contributor
    0 Kudos

    Hi Raja.

    1. Yes, you can activate the specific user id's, basically used for auditing purpose, kindly refer the blog about the SM19 / SM20 - https://blogs.sap.com/2014/12/11/analysis-and-recommended-settings-of-the-security-audit-log-sm19-sm...

    2. STAD used for analyze performance of SAP system and application program.

    Refer the Blog about the details https://blogs.sap.com/2013/06/11/how-to-use-stad-to-show-historical-data/

    Regards

    SS