on ‎2020 Sep 15 1:00 PM
Hi
I would like to create CCM to monitor SAP Standard Users SAP*, DDIC and EARLYWATCH to make sure:
1) they are locked.
2) their default passwords are changed.
Questions:
A) What are the tables suggested for the Data Source?
B) My issue is these standard users are in the default clients (000, 001, 066), so what to do in this case? There is nothing for GRC to monitor in these clients therefore we have not got connections to these cleints (and really don't see much value to build them).
Thanks
Reza Ahoui
Request clarification before answering.
Hi Reza,
I will suggest to leverage Manual Control Test process for this and have test steps documented on how to verify and validate this control in respective clients 000, 001, 066.
Control: SAP System user IDs is adequately secured via changing the initial password from SAP. This is to prevent unauthorized access to the system using default passwords
Test Steps:
Step 1: Determine that the passwords of SAP standard users have been changed in all clients in the production environment from the SAP shipped passwords.
Step 2:Execute transaction code SA38 with program RSUSR003. Also execute SA38 with program RSUSR200 to check if passwords have just been changed.
Step 3:New password should be secured in a sealed envelope or equivalent and kept by appropriate personnel (system owners) other than the system administrators.
Regards,
Madhu
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks Madhu, useful as always
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 41 | |
| 9 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.