SAP · Security, BASIS & Operations
Every change passes one path, and every control sits on it.
Noble designs and runs the controls beneath an SAP landscape: an authorisation model built on what people do rather than on what they ask for, segregation of duties that an auditor can read, BASIS administration and patching on SAP’s cadence, a transport path where nothing reaches production without a record, HANA administered as the database it is, and monitoring that reaches a person before a user does.
Why this is one discipline
Security, BASIS and operations are usually three teams, and the seams between them are where an SAP landscape is weakest. A role is designed by one team, transported by another and monitored by a third; a patch is applied by BASIS and its effect on authorisations is discovered by the help desk. Noble treats them as one discipline with one register of controls, because a control that nobody owns end to end is not a control.
The register on this page is written for two readers at once: the administrator who has to run it, and the auditor who has to be satisfied by it. Each control names what it protects, how it is evidenced, and who owns it. That is the whole design — the products beneath it change on SAP’s schedule, and the register does not.
The register of controls
Roles and the authorisation concept
An authorisation model designed from the jobs people do — a buyer, a plant controller, a payroll administrator — rather than accumulated from what each person has asked for over ten years. Roles are built to a naming and structure standard, derived where organisational levels differ, and reviewed on a cycle with the business owner who can say whether the access is still needed.
- Authorisation concept designed from job function
- Role build to a naming and structure standard
- Derived roles across organisational levels
- Periodic access review with the business owner
Segregation of duties and GRC
The rule set that says a person who can create a vendor should not also be able to pay one, applied to the roles before they are assigned rather than discovered at audit. Where the organisation runs SAP GRC, the rule set, risk analysis and emergency access are built there; where it does not, the same analysis is done against the authorisation data directly.
- Segregation-of-duties rule set agreed with finance and audit
- Risk analysis before assignment, not after
- Emergency access with a record and a reviewer
- SAP GRC configured where the organisation runs it
BASIS administration and patching
The technical administration of the landscape: system parameters, kernel and support package levels, client strategy, printing and spool, background processing, and the SAP security notes applied on a cadence the organisation has agreed rather than when an incident forces them. Each patch is assessed for what it changes and rehearsed on the path before it reaches production.
- System administration across the landscape
- Security notes and support packages on an agreed cadence
- Kernel, parameter and client strategy
- Background processing and spool kept healthy
The transport path and change control
Every configuration and code change moves through the same path — development, quality, production — and nothing reaches production without a transport request, a test record and an approval. The path is the control: it makes a change traceable, reversible and, when it fails, attributable. Retrofit is managed where a project landscape runs beside the maintenance one.
- Three-system path with approval at each gate
- Transport requests tied to test evidence
- Retrofit between project and maintenance landscapes
- Emergency changes recorded and reviewed after
HANA database administration
HANA administered as a database: memory and table placement, backup and point-in-time recovery rehearsed rather than assumed, system replication for the landscapes that need it, encryption at rest and in transit, and the housekeeping that keeps an in-memory system inside the memory it has.
- Backup, recovery and replication rehearsed
- Memory, table placement and housekeeping
- Encryption at rest and in transit
- Database user and privilege management
Monitoring, logging and audit
The landscape watched as one system: availability and performance, background jobs, interface queues, failed logons, security audit log events, and changes to critical objects, each with a threshold and an owner. The security audit log and change documents are configured to what the organisation’s auditors will ask for, and retained for as long as they will ask.
- Availability, performance and job monitoring with owners
- Security audit log configured to the audit requirement
- Alerts that reach a person, with an escalation path
- Evidence retained for the period the auditor needs
The transport path, with its gates
The one flow every change passes through. Three gates: the change is tested before it leaves development, approved before it enters production, and reviewed after it lands. A change that skips a gate is an incident, by definition.
- 01Change requestOwner, reason, scope
- 02DevelopmentTransport created
- 03QualityTested, evidence attached
- 04ApprovalBusiness and technical
- 05ProductionImported in a window
- 06Post-reviewEffect confirmed
Where this connects
- Managed SAP ServicesThe controls on this page are what a managed service runs, day after day. That page describes the service; this one describes the register it keeps.
- S/4HANA & RISEUnder RISE, SAP operates the infrastructure and the customer keeps the authorisation model, the transport path and the audit. This page is the customer’s half.
- BTP, Integration & ExtensionsExtensions and interfaces are authorised and transported by the same controls; an API is a door, and this register decides who holds the key.
The services alongside
- SecurityEnterprise identity, the security operations centre and the governance framework the SAP controls report into. SAP is one system in that programme.
- Managed IT ServicesMonitoring, patching and backup for everything beneath and beside SAP — the network, the endpoints, the servers that are not HANA.
- CloudThe landing zone, network boundary and backup design when SAP runs on a hyperscaler, whether under RISE or on the organisation’s own subscription.
SAP, SAP HANA, SAP GRC and S/4HANA are products of SAP SE, named to identify what the work is done on. All marks belong to their owners.
Start from the last audit finding.
An open finding — a role with too much in it, a transport nobody approved, a log that was not kept — is the most precise brief an SAP control programme can receive.
