Expert Guided Implementation (EGI) for
Security Optimization
Agenda
Overview
Customer benefits
Technical prerequisites
© 2011 SAP AG. All rights reserved. 3
EGI for Security Optimization - Overview
Security Optimization - Tools and Procedures
For effective security management, organizations need tools
and procedures to monitor security relevant topics.
In this session you will learn
how to analyze and improve the security level of your SAP
landscape
how to track relevant key figures
how to document the security status
how to derive an action plan
using
the SAP Guided Security Optimization Self Service (SOS)
security topics in the SAP EarlyWatch Alert service (EWA)
Customer benefits
Customers benefits
Fast project setup, less investment of time
Analyze and monitor Security Topics – ad hoc and
continuously
Establish a sustainable process for security monitoring
Using standard tools and SAP recommendations
Direct remote access to SAP expert
Minimize travel expense
Target Group
SAP security responsible
System and user administrators
Expert-guided
implementation is a
new optimized,
short-term setup
service to configure
basic scenarios
without long-term,
in-house consulting
Training, practical experience, remote consulting
Participants have direct access to an SAP expert who directly supports them remotely, if necessary, during the execution
Participants execute demonstrated steps using training materials within their own SAP system
landscape and develop an action plan
SAP expert explains the steps to analyze and
improve the security of an SAP system landscape.
The Security Optimization Service , the tool
RSECNOTE as well as the security content of the EarlyWatch Alert will be shown.
Empowering, Web session, 2-3 h. each morning
Expertise on demand, during execution
Execution, 2-3 h. on the same day
© 2011 SAP AG. All rights reserved. 5
Technical prerequisites
SAP Solution Manager
Minimum Requirement:
SAP Solution Manager release 7.0 EHP1 (SP23) & SAP Notes
Recommended:
SAP Solution Manager release 7.1
ST-SER 701_2010_1 & SAP Service Content Update activated
At least one ABAP based Managed System connected to the SAP Solution Manager
As minimum the SAP Solution Manager can be its own managed system
Add-Ons on the managed system:
ST-A/PI
release 01N SP00(required) & SAP Note 1608969 (recommended)
or
01N SP01
& SAP Note 1664250 (recommended)
ST-PI
release 2008_1_<SAP_BASIS release> SP01 or higher
EarlyWatch Alert scheduled and successfully executed on the Solution Manager for the managed
system
S-User in SAP Marketplace
Participants frontend
We are using an Adobe Acrobat Connect room for the virtual training. Make sure that all tests of
URL
https://admin.acrobat.com/common/help/en/support/meeting_test.htm
pass successfully
Required: SAP GUI and web browser
Recommended: MS Word
Details regarding system prerequisites and required user authorizations are described in
SAP Note
1484124
Schedule
Execution by customer
Perform another Guided SOS using the advanced features
Generate and interpret a service report
Gather experience with accompanying tools EWA and Security Notes Check
Send the SOS and EWA service reports to the SAP expert
Day 2: Analysis
Execution by customer
Check and fulfill prerequisites in own system backed by on-demand expertise and support.
Enable, schedule and perform a Guided Security Optimization Self Service including generation of a MS Word report of the findings.
Day 1: Prepare
Execution by customer
Define customer action plan and further follow-up activities
Day 3 - 5: Follow-up
Individual lesson
for each customer
Discuss customer defined action plan with SAP expert
(Web sessions starting in the afternoon of day3 continued in
Empowering lesson
SAP expert explains
Concept of Expert Guided Implementation
Topics of the Security Optimization Service (SOS)
Setup of the training scenario
Check of the prerequisites
Enable Guided Service procedure
How to schedule and perform a Guided Security Optimization Self Service including report generation.
(Web session in the morning)
Empowering lesson
SAP expert explains
Review of day 1
Re-execute the SOS session and
demonstrate customizing and sharpening options
Report interpretation
Accompanying tools
EarlyWatch Alert (EWA)
SAP Security Notes Check (RSECNOTE)
(Web session in the morning)
Empowering lesson
SAP expert explains (morning of day 3)
Review of day 2
Sample session and report
Strategy to create an action plan