您好,欢迎访问三七文档
当前位置:首页 > 办公文档 > 其它办公文档 > SAP Audit Information and Approach
SAPAuditInformationandApproachAuthorizationExample1.UserMasterRecordUser:FrankW.LyonsProfile:Example2.Profile:ExampleObject:Authorizations:S_ProgramABAP:3.Authorization:ABAP:Object:S_ProgramValues:Fields:*ProgramGroupSUBMIT,VARIANTActivityAuthorizationSystem:1.ProfilesOneormoreassignedtoauser2.ObjectsMustbeuniquenameswithoneormorefields3.FieldsContainvaluesforauthoritychecking4.AuthorizationsCanhavethesamenamesastheyarephysicallyandphysicallylinkedtoanobjectFieldgroupforanobjecthasmultiplevaluesandcanbesharedacrossobjectsInitialDefaults1.InitialClientsClient000StandardmodelClient001Modelforuserdefinedclients.(template)2.InitialUserIdsSAP*Defaultsuperuser.AusermasterrecordiscreatedduringinstallationbutitisnotneededbySAP*toaccessthecompletesystem.IftheSAP*masterrecordisdeleted,theSAP*accounthasthefollowingspecialprivileges:ItisnotsubjecttoauthorizationchecksandthereforehasallauthorizationsIthasthepassword“PASS”,whichcannotbechangedwithoutcreatinganewusermasterrecord.Topreventdeletion,assignSAP*usertoagroupcalledSUPERandonlysuperusershouldbeabletomaintainusergroupSUPER.3.InitialSecurityParametersParametersforuserlogonlogin/min_password/lngMinimumpasswordlengthdefaultis(3)login/password_expiration_timeNumberofdaysafterwhichapasswordmustbechanged.Thedefaultiszero,whichdoesnotenforcepasswordchanges.Recommendedvalue=45.login/fails_to_session_endNumberoftimesausercanenteranincorrectpasswordbeforethesystemendstheloginattempt.Thedefaultis(3).login/fails_to_user_lockNumberoftimesausercanenteranincorrectpasswordbeforethesystemlockstheuseragainstfurtherlogonattempts.Thedefaultis(12).Recommend(3).Whenapasswordislockedinthismanner,itisautomaticallyunlockedbythesystematthestartofthenextday(midnight).AddingUsers1.Eachusermusthaveamasterrecord.2.Eachusermasterrecordreferstooneormoreprofilesthatdeterminetheaccessrightsfortheuser.3.Masterrecordcontains:UserIDPasswordUsergroupsUsertypePeriodofvalidityreferencestoauthorizationprofilesMasterrecordscanbedeletedbutitwillaffecttheaudittrail.Bettertolocktheuser’smasterrecordMenuPath:Tools-Administration-UserMaintenance-User-Lock/Unlock.4.UserGroupIfapersonisassignedtoausergroup,onlytheadministratorswhoareauthorizedforthatusergroupcanalterusermasterrecords.Ifauserisnotassignedtoagroupthenanyuseradministratorcanaltertheusermasterrecord.AddingProfilesProfilesandAuthorizationsexistinbothmaintenanceandactiveversions.Allowsforupdatestomaintenancebeforeitisactivated.Separationofmaintenanceandactivationfunctions.1.SystemProfilesSAPStandardandSuperUserProfilesS_A.SYSTEMUnlimitedaccesstoallusers,profiles,andauthorizationsS_A.ADMINAuthorizationsforSAPsystemadministration.Thisincludesallauthorizationsexceptfor:MaintenanceofusersinusergroupSUPERMaintenanceofprofilesandauthorizationswithnamesbeginning“S_A.”S_A.CUSTOMIZAuthorizationsforuseintheSAPCustomizingsystemS_A.DEVELOPAuthorizationsforuseintheSAPDevelopmentenvironment(excludesanyuserorprofileauthorizations)S_A.USERBasissystemauthorizationsforend-users(e.g.,S_Program,S_DBC_MONI,etc.2.StartupProfilesProfileNameDescriptionS_ABAP_ALLAllABAP/4authorizationsS_ADMI_ALLAllsystemadministrationfunctionsS_BDC_ALLAllbatchinputactivitiesS_BTCH_ALLAllbatchprocessingauthorizationsS_DDIC_ALLDDIC:AllauthorizationsS_DDIC_SUDataDictionary:AllauthorizationsS_NUMBERNumberrangemaintenance:AllauthorizationsS_SCD0_ALLChangedocuments:AllauthorizationsS_SCRP_ALLAllSAPscripttext,styles,layoutsetsmaintenanceS_SPOOL_ALLAllspoolauthorizationsS_SYST_ALLAllsystemauthorizationsS_TABU_ALLStandardtablemaintenance:AllauthorizationsS_TSKH_ALLAllsystemadministrationauthorizationsS_USER_ALLUsermaintenance:AllauthorizationsSAP_ALLProvidesunlimitedaccesstomaintainallSAPR/3systemauthorizations,withthefollowingexceptions:MaintenanceofusersinusergroupSUPERMaintenanceofprofilesandauthorizationswithnamesbeginningS_USERSAP_ANWENDAllSAPR/3(excludingsystem)applicationauthorizationsSAP_NEWProvidesunlimitedaccesstoallauthorizationsaddedwithnewreleasesofSAPR/3.Z_ANWENDAlluserauthorizations(excludingBCsystem)3.ProfilesandtheirassociatedauthorizationvaluesetsarestoredinUSRxxtables.AddingAuthorizationsAuthorizationobjectsareusedtocheckauser’sauthoritytoperformactionsandaccessdatainR/3.Auser’sactionisapprovedonlyiftheuserpassestheauthorizationtestforeachfieldlistedinanobject.1.AuthorizationObjectsSAPcontainsanumberofauthorizationobjectsthatareusedtorestricttheabilityofuserstoperformcertainfunctionsandaccessinformation.AuthorizationobjectscancontainuptotenauthorizationIDsrepresentingsuchsystemelementsastransactions,tables,fields,orprograms.AuserisallowedaccessifthetheirmasterrecordliststheobjectforwhichtheauthorizationisbeingtestedandtheuserpassestheauthorizationtestforeachauthorizationID.Anauthorizationvaluesetisrequiredforaccess02=changeAuthorizationProfilesareusedtogranttheauthorizationvaluesetstoauser.Theusermasterrecordreferstoprofilesandtheprofiles,inturn,refer,tovaluesetsthatdeterminetheaccesscapabilitiesoftheuser.NewauthorizationobjectscanbecreatedbyMenuPath:S
本文标题:SAP Audit Information and Approach
链接地址:https://www.777doc.com/doc-12272 .html