ERP & SAP Security in 2010

Become a member of the site to sign up for this event.

07-Sep-2010

As one of the leading business applications in the world, an SAP-system is typically a complex environment that serves many business processes and support a variety of business decisions. It is typically integrated with many other applications and tightly integrated with applications servers and networks. Like with any similar type of environment, these applications are challenging from an Information Security perspective.
During this seminar, we want to focus on the general Information Security challenges with SAP, but also with some of the particular issues typically found with companies that work with SAP environments.
Some of our experts will be able to show and share some of their experiences, from and with customer environments.

Besides, we will also zoom into some of the typical business challenges such as GRC, Identity Management, R/3 Security, Single Sign On, Compliancy issues and Web Application Security, next to typical policy challenges such as Segregation of Duties, Access Management and ICT and Business Audit and Controls.

Some of the topics that will be addressed during this seminar :
- R/3 Security, BW Security, Enterprise Portal, CUA,
- Single Sign On,
- SOX/ SoD,
- OSS,
- HR Security
- Other SAP Apps
- GRC setup
- Identity Management
- Integration with other systems such as MS or Oracle databases and other applications
- Challenges for integration due to mergers or de-mergers
- …

Download the CA SAP Security White Paper CA Technologies Improving SAP Security CA Identity 2010.pdf

Preliminary Program

9.00 : Registration & Welcome Coffee

9.45 : Introduction & Opening Notes

10.00 : Experiences Securing business information in SAP and managing user access risk effectively: Facing today’s challenges and adopting security standards with good practices, , by Wouter Janssen, Axl-Trax

Abstract : Organizations deploying SAP solutions to facilitate their business rely heavily upon the correct processing, manipulation and reporting on business-critical information. Due to the integrated nature of mySAP ERP as well as the interconnectivity and interaction between different components in the information architecture, risk is the keyword that must be properly addressed.
The challenge of security SAP implementations is not new and dates back from the early 90ies when the ERP-component R/3 became available. Many organizations have grown a good practice in securing what is important to them, others have learned the hard way. Business drivers, threats and risk appetite have shifted in recent years and during this presentation, the trends and good practices in managing user access risks effectively will be discussed

About : Wouter Janssen CISSP CISA CISM CGEIT CFE is a security specialist working as a director for Axl & Trax in Belgium. Working in the security consulting and audit field for many years, he has combined his technical skills and security knowledge with business insight and experience to assist customers in finding tailored solutions for security challenges.
He has over 10 years of professional experience in the areas of IT security, identity & access management, SAP security, governance, compliance and control. He has been involved in and managed large-scale IT security projects and advised various multinationals across Europe.

10.50 : Vulnerabilities of SAP systems : history and trends, by Fred van den Langenburg (ERP Security) and Joris van de Vis

Abstract : A modern SAP system based on the Netweaver based architecture may employ several different software components located on different servers and is connected to the Interne. This means that a SAP Netweaver system has many more possible entry points or attack vectors1 than the older R3 systems which were not connected to the Internet. Modern SAP systems based on Netweaver are more vulnerable and prone to attacks than their R/3 predecessors.
During this presentation we will learn about the evolution of the potential threat vectors in SAP-systems, in order to get a better understanding on how we might learn from history to avoid similar mistakes in the future.

About : Fred van de Langenberg has been working as a freelance SAP technical consultant for the past 13 years for various multi-nationals including Heineken, Shell, Ericson and Philips. His experience also includes working for IT companies such as Atos Origin, IBM and currently T-Systems. Over the years he has acquired in-depth knowledge of SAP systems through hands-on experience. In addition to being an all-round SAP Basis consultant, he is also a certified ABAP programmer. The introduction of the SAP Netweaver platform brought new challenges in the field of security which triggered his interest in SAP platform security.

About : Joris van de Vis has been working in many technical roles. Next to developing and working as a Netweaver Technical consultant his special interest goes out to the SAP Security domain. He helps customers securing their business by hardening their SAP platform. He is also a SAP vulnerability researcher. Over the past 10 years he has been working for large fortune-500 companies like Philips and Heineken and he helped several governmental departments with implementing SAP Security related solutions.

11.40 : Coffee Break & Networking

12.10 : Building an enterprise-wide GRC solution with the SAP environment at the core, by Chris Van den Abbeele, Atos Origin

Abstract : Session abstract:
Organizations today are looking for ways to leverage their investments in SAP by extending their SAP policies to other non-SAP systems.
This session present how to extend the reach of SAP Access Control, SAP Process Control and SAP Risk Management to build an enterprise-wide GRC solution that includes non-SAP applications.

In particular, this session covers a solution which spans SAP- and non-SAP applications, that enforces Roles Based Access Control, alerts in near-real-time if access to enterprise systems violates business policies, shows how roles granted in SAP can be easily mapped to non-SAP systems, and how roles granted in non-SAP systems can be mapped back into SAP, while respecting the defined restraints like Separations of Duty and business approvals.

All too often, we see enterprises take a siloed approach to solve tactical issues. When new compliance regulations, eg PCI, arise, a new project is put into place to solve that specific need.

At TechEd on October 13, 2009, SAP and Novell announced the expansion of their global partnership to include the delivery of integrated governance, risk, and compliance solutions. As a dedicated integration partner of both SAP and Novell, Atos Origin is in a privileged position to turn this vision into a working ensemble.

The modular approach presented in this session shows how to drive towards a consistent, sustainable enterprise-wide GRC strategy that reduces risk, lowers costs and provides improved business performance.

About : Chris Van Den Abbeele is Solution Manager for Identity and Security solutions at Atos Origin. He is responsible for defining and managing the Identity and Access Management offering at Atos Origin Belgium.  Chris has over ten years experience in designing Identity and Access Management solutions.  He has a clear view on the technology, the market and the players.  Prior to joining Atos Origin, Chris worked as a Technology Specialist at Novell for about ten years.

13.00 : Walking lunch & Networking

13.45 : Keynote Address : Achieving comprehensive Security for SAP in a Heterogeneous Environment with CA and SAP, Phil Allen, Director Security Practice EMEA, CA Technologies

Abstract : Abstract: CA and SAP have been long term partners. This talk will explore how you can achieve comprehensive and effective security for SAP environments that are implemented in a heterogeneous environment.

14.35 : SAP GRC-AC implementation: challenges encountered at customer implementation, by Melissa Dielman Deloitte Enterprise Risk Services

Abstract : Segregation of Duties conflicts are an ongoing issue in audit reports, particularly in the context of SoX (Section 404) or similar legislation worldwide. SAP’s response consists of the GRC application suite “Access Control (5.3)”. A proper implementation should ensure that typical application-level fraud scenarios are identified and controlled.

Access control over key information assets and SoD compliance are among the most effective safeguards against fraud and mistakes, and a prerequisite for compliance to various regulations. SAP GRC Access Control consists of 4 modules, each with specific functionality to maximize this level of control. In our presentation, we will highlight the functionalities of the components and more important, the way they can efficiently interact together.

Where technically, AC projects contain few challenges, we know the great pitfalls lie elsewhere. The most difficult part of each implementation is the proper alignment of functionality with the enterprise’s (GRC) maturity level. Implementing a GRC application suite is not just implementing another tool, it is implementing a new culture; requiring a lot of input, effort and cooperation from the entire business.
Our best practice implementation consists of a phased approach. The goal is gradually evolving from a focus on getting clean, to remaining in control of the situation and staying clean. We will list the different phases to go through in order to simultaneously prepare business, IT and audit stakeholders for the ownership of a Risk controlled environment. We will also clarify the need for a diverse implementation team to ensure a successful implementation.
Summarizing, in this session, we (Deloitte ERS) will elaborate on our strategy of implementing a suitable customized instance of SAP GRC Access Control. We will include various lessons learned from passed implementations, focusing on the different challenges encountered and analysing root cause of both successful and failing implementation projects.

About : Melissa is Senior Manager at Deloitte-ERS in the Security & Data Privacy department. She is responsible for the SAP Security service offerings & teamlead. Over the years Melissa has a built a solid expertise in SAP authorization management & GRC, having participated and led different size projects in Belgium and Europe. Her education, interests and working experience allow her to get a combined view on all components of the SAP Security management, from business processes, risk & control to technical implementation perspective.

15.15 : Coffee Break

15.45 : SoX/ SoD or GRC setup, by Paul Albertini, Manager, KPMG

Abstract : Understand and resolve the insecurities with your ERP system. Understand the basic security threats and see a live demo of how insecure some sytems can be. Learn how to protect your vulnerabilities and find some solutions that can help protect you also further in the future.

About : Paul is a manager in the Antwerp practice of KPMG Advisory. He is specialized in advisory services in the fields of ERP Advisory. Over the last years Paul was involved in several SOD projects. For these engagements he assisted clients in their strategy, building the business case and performing project management activities as well as developing security policies and procedures. Paul is also a member of the Information System and Control Association (ISACA) and a certified information system auditor (CISA). Other main certifications that he obtained in his career can be summarized as follows: SAP Solution Architect and Prince2.

16.35 : Aligning access rights in SAP R3 & BW through a uniform authorization concept, by Pieter Lenaerts, Deloitte Enterprise Risk Services

Abstract : Companies have been investing in increased security restriction, monitoring & ownership in their daily transaction systems due to the increased attention to Good Governance in the Data & Fraud protection area, and the growing legislative requirements (SOX, Basel II,..). To enable this drive, a SAP R3 environment offers one of the most flexible and therefore complex authorization mechanisms on the market. SAP BW adds to this complexity with an additional security layer controlling access to data.

SAP BW, being mainly a reporting tool, is easily overseen as a key information provider on business sensitive data, financial results & HR information. As a consequence SAP BW security is often perceived to be less sensitive while it is imperative that the access rights between SAP R3 and SAP BW are aligned across the different authorization environments.

This presentation intends to give a broad audience, from BW project management via BW developers to R3 authorization specialists, a conceptual overview of the main role design strategies made possible by the new BW authorization mechanisms to secure access to data, and compare these strategies in the long – operational – run. It will show some of the do’s and don’ts based on hands on experience aligning authorizations for R3, BW and SAP Portal. To ensure your BW concept works for your business we will highlight the different stakeholders and their role in this process.

About : Pieter is Senior Consultant at Deloitte-ERS in the Security & Data Privacy department. Starting as IT auditor, Pieter has expanded and increased his knowledge on SAP security & GRC to become a true expert in this area. He has conducted projects on SAP security within R3, BI & CRM and specializes in automation of SAP authorizations maintenance.

17.00 : ABAP backdoors and compliance killers, by Andreas Wiegenstein, Managing Director & CTO Virtualforge

Abstract : based upon the experience of having reviewed many SAP / ABAP applications, Andreas will present an overview of some of the most common and some of the more interesting security issues, being them real threats, leaks, backdoor channels, ... simply from the missing or incorrect authority checks, bypass mechanisms and other.

Andreas Wiegenstein has been working as a professional SAP security consultant for 8 years. He performed countless SAP code audits and has been researching security defects specific to SAP / ABAP applications. Andreas has spoken at SAP TechEd on security on several occasions and is co-author of the first book on ABAP security (SAP Press 2009).

17.50 : Panel Discussion

18.30 : Closing Notes, Reception & Networking

19.00 : Close of Event

Practical Details

Auditorium Kasteel, Kasteelpark Arenberg, 3001 Heverlee
Tuesday, September 7th, 2010
Day Seminar : from 10 AM until 6 PM
Free to register for enterprises and industry. Non-SAP customers, systems integrators and consultants (without operational SAP-systems) will be invoiced 150 € (ex VAT) participation fee.

You can also register at : the Eventbrite registration prages

Become a member of the site to sign up for this event.

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< September 2010 >>

S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 1 2

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Bluekrypt

Security Expert in Crypto, Information Security and Training

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: arrowUp

arrowUp - member of the Lykos Group

Expert: Research In Motion - RIM - Blackberry

Research In Motion - RIM - Blackberry

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: Traxion

Traxion - Identity Management - cornerstone for your company

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: Approach

Approach specializes in Application Security, Identity Management and financial transactions.

Expert: Global Knowledge

Global Knowledge is the worldwide leader in IT and business training.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Novell

Comprehensive Identity, Security and Systems Management Solutions.

Expert: Exclusive Networks

Value added Distributor specialized in information security. Operational in Belgium, France, Switzerland and Luxemburg.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: D Soft

D Soft is an expert in electronic distribution of digital documents.

Expert: Scanit

Scanit is an IT security boutique specializing in ethical hacking, penetration testing, vulnerability assessments and security configuration reviews.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: Microsoft

At Microsoft, we're motivated and inspired every day by how our customers use our software to find creative solutions to business problems.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: Intesi

Intesi Belgium is the R&D competence center of Intesi Group, focusing on Internet Security, using state-of-the-art ICT technologies.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Cisco

Cisco Internet Protocol (IP)-based networking solutions are the foundation of the Internet.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: BT - British Telecom

One of the world's leading providers of communications solutions.

Expert: Alcatel Lucent

Alcatel provides communications solutions to telecommunication carriers, Internet service providers and enterprises for voice, data and video.

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: IBM

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: Norkom Technologies

Norkom is a market-leading provider of innovative financial crime and compliance solutions to the global financial services industry.

Expert: Telindus

Telindus has expertise in all aspects of modern telecommunications technology, including LAN, WAN, Internet and e-networking, network access and security, VOIP (Voice over Internet Protocol), VPN, fixed and mobile communications.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.