Product Description
SAP is the backbone of operations for thousands of organisations worldwide — and one of the most under-audited systems in the enterprise. When SAP controls fail, the consequences are serious: unauthorized access to financial data, segregation-of-duties conflicts that enable fraud, uncontrolled changes to production, and privileged accounts that give individuals unrestricted power over the entire system.
This SAP System Audit Program gives IT auditors, SAP security reviewers, and internal audit teams a rigorous, structured framework to audit every critical layer of an SAP landscape. With 91 procedures across 13 specialist sections, it covers everything from system configuration and user lifecycle management to privileged account controls, change management, batch processing, interfaces, and the modern S/4HANA and Fiori landscape.
Every section opens with a clearly stated audit objective — what assurance it provides and which risk it prevents — followed by step-by-step test procedures with the exact SAP T-code or report to use. No guesswork. No starting from scratch. Just open it, follow the procedures, and document your findings.
Aligned to the SAP Security Baseline, ISO 27001:2022, COBIT 2019, NIST SP 800-53, and SOX ITGC requirements. Built for practitioners who need to go beyond a checklist and actually test the controls that matter.
Section Descriptions
Section 1 — System Configuration and Security Parameters (7 procedures)
Assurance that the SAP security baseline is applied and maintained — preventing misconfiguration from opening the door to unauthorized access or system failure.
Section 2 — User Management and Account Administration (8 procedures)
Assurance that only legitimate, current users hold active accounts — joiners, movers, and leavers are processed on time, and dormant accounts don’t linger.
Section 3 — Roles, Profiles and Authorizations (7 procedures)
Assurance that access follows least privilege — no excessive combinations, no toxic pairings, no segregation-of-duties conflicts hiding in role design.
Section 4 — Password and Authentication Controls (7 procedures)
Assurance that password policy is enforced at the parameter level and cannot be bypassed through RFC, background jobs, or alternative logon paths.
Section 5 — Security Audit Log and Event Monitoring (7 procedures)
Assurance that the right events are captured, retained, protected from tampering, and actually reviewed — not just switched on and forgotten.
Section 6 — Change and Transport Management (7 procedures)
Assurance that every change is approved, tested, and transported by authorized persons — with a complete trail from request to production release.
Section 7 — Batch Jobs and Background Processing (7 procedures)
Assurance that background jobs run under appropriate accounts, on authorized schedules, and that failures don’t go undetected.
Section 8 — Interfaces, RFCs and Connectivity (7 procedures)
Assurance that all external connections are authorized, secured, and monitored — not left open as an unguarded back door into the system.
Section 9 — Data and Table Access Controls (7 procedures)
Assurance that sensitive tables cannot be read or manipulated directly — bypassing the application controls that everyone assumes are working.
Section 10 — System Availability and Performance Monitoring (7 procedures)
Assurance that system health is tracked, errors are resolved, and capacity is managed before it becomes a business continuity failure.
Section 11 — Privileged and Standard SAP Accounts (7 procedures)
Assurance that the most powerful accounts in the system — SAP*, DDIC, SAP_ALL, firefighter IDs — are necessary, controlled, and watched.
Section 12 — Audit Trail and Evidence Retention (7 procedures)
Assurance that logs and change documents are complete, retained per policy, and cannot be altered — so audit evidence holds up when it matters most.
Section 13 — S/4HANA, Fiori and Modern SAP Landscape (7 procedures)
Assurance that the newer layers of the landscape — Fiori, BTP, HANA — don’t introduce risks that bypass everything tested in the sections above.






Reviews
There are no reviews yet.