{"id":27654,"date":"2020-08-05T07:00:00","date_gmt":"2020-08-05T04:00:00","guid":{"rendered":"https:\/\/www.blue.works\/?p=27654"},"modified":"2024-08-26T11:54:33","modified_gmt":"2024-08-26T09:54:33","slug":"security-made-easy-with-ewa","status":"publish","type":"post","link":"https:\/\/www.blue.works\/en\/security-made-easy-with-ewa\/","title":{"rendered":"Security made easy with EWA"},"content":{"rendered":"\n<p class=\"has-medium-font-size\">SAP Security is one of the most neglected security topics in a company. The misjudgment that an ERP is not a preferred target is in the most heads on C-Level or in the internal IT. But SAP makes it easy for the customer to handle the most important security issues without having special tools:&nbsp;The SAP Early Watch&nbsp;(EWA)&nbsp;alert comes out of the box and gives a quick overview with the solution to fix the issues&nbsp;on a weekly basis with real data.&nbsp;<\/p>\n\n\n\n<p>The Early watch alert can be accessed in classic way as a report generated in SAP Solution Manager&nbsp;and can be accessed via Mail, Tx. DSA, Solution Manager Workcenter&nbsp;or the modern HTML&nbsp;5&nbsp;Version, EWA Workspace&nbsp;in SAP Launchpad.&nbsp;<\/p>\n\n\n\n<p>The following&nbsp;Security Categories are available in EWA:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Standard Users\u00a0<\/li>\n\n\n\n<li>Communication\u00a0<\/li>\n\n\n\n<li>Configuration\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Maintenance\u00a0<\/li>\n\n\n\n<li>Critical Authorizations\u00a0<\/li>\n\n\n\n<li>Review and Monitoring\u00a0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Standard Users&nbsp;<\/h3>\n\n\n\n<p>One of the security quick wins is the Standard Users check:\u00a0This\u00a0checks\u00a0for the behaviour of the preconfigured Users in SAP Systems (ABAP \/ JAVA \/ <a href=\"https:\/\/www.sap.com\/swiss\/products\/technology-platform\/hana\/what-is-sap-hana.html\" title=\"\">HANA<\/a>). The check for Users like DDIC in ABAP or SYSTEM in a HANA Database. The EWA gives a direct advise with links to the support portal of SAP or Notes which should be implemented.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image.jpeg\" alt=\"SAP UI 5 view in SAP EWA Workspace\" class=\"wp-image-27655\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-768x245.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Communication&nbsp;<\/h3>\n\n\n\n<p>In the communications section the EWA shows e.g. insufficient password protection in DB connections or an insecure internl network configuration of a SAP HANA Database. It checks for insecure Gateway configuration or the Access Control List.&nbsp;<\/p>\n\n\n\n<p><strong>SAP Solution Manager \u2013 My Early Watch Alerts Reports<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"314\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-1.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27656\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-1.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-1-768x236.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration&nbsp;<\/h3>\n\n\n\n<p>Configuration shows the Security relevant settings as per recommendation by SAP. It will give advice for password policies&nbsp;in ABAP and HANA, it also shows if the SSFS Master Encryption Key of a HANA is not changes.&nbsp;As in every category SAP gives direct access to documentation and Notes with hints and documents on how to set up everything in a secure way.&nbsp;<\/p>\n\n\n\n<p><strong>EWA-Workspace<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"335\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-2.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27661\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-2.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-2-768x251.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>SAP Solution Manager \u2013 My Early Watch Alerts Reports<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-7.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27676\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-7.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-7-768x402.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Maintenance&nbsp;<\/h3>\n\n\n\n<p>The maintenance category gives adives for the latest support packages or notes which should be implemented to run a most secure SAP Landscape for ABAP, JAVA and HANA&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"331\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-5.jpeg\" alt=\"\" class=\"wp-image-27668\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-5.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-5-768x248.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Critical Authorizations&nbsp;<\/h3>\n\n\n\n<p>This category checks for users with authorizations which they shouldn\u2019t have in an SAP environment. It checks for Roles like SAP_ALL in ABAP or DATA_ADMIN in HANA.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>EWA Workspace<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"410\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-4.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27667\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-4.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-4-768x308.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>SAP Solution Manager \u2013 My Early Watch Alerts Reports<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"317\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-6.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27672\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-6.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-6-768x238.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Review and Monitoring&nbsp;<\/h3>\n\n\n\n<p>In Review and Monitoring SAP checks for the configuration of the Audit logs in SAP HANA.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"344\" src=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-3.jpeg\" alt=\"Ein Bild, das Screenshot enth\u00e4lt.\n\nAutomatisch generierte Beschreibung\" class=\"wp-image-27664\" srcset=\"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-3.jpeg 1024w, https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/image-3-768x258.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">How can blue.works help&nbsp;<\/h3>\n\n\n\n<p>As specialist in SAP Solution Manager, ALM and Security we can help you configure the SAP Solution Manager to give you the informations out of you SAP Systems right into the EWA. In a second step we can assess the findings and solve them for you or lead to&nbsp;solve them. And the last part is to keep you systems secure. Here we can help you to use the SAP Solution Manager as the ALM tool which keeps you up to date across you SAP Landscape and hold it secure.&nbsp;<\/p>\n\n\n\n<div class=\"uk-text-center\"><button class=\"uk-button uk-button-large uk-button-secondary\" uk-toggle=\"#getstarted\">Set up EWA&#8217;s today \u2192<\/button><\/div>\n    <div id=\"getstarted\" uk-modal=\"esc-close:false;bg-close:false\">\n        <div class=\"uk-modal-dialog uk-modal-body\" uk-overflow-auto=\"\">\n             <button class=\"uk-modal-close-default\" type=\"button\" uk-close=\"\"><\/button>\n            <div class=\"uk-modal-header\">\n            <h2 class=\"uk-modal-title\">Get started with EWA<\/h2>\n        <\/div>\n            [contact-form-7 id=&#8221;26123&#8243; title=&#8221;Project quote&#8221;]\n        <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p>SAP Security is one of the most neglected security topics in a company. The misjudgment that an ERP is not a preferred target is in the most heads on C-Level or in the internal IT. But SAP makes it easy for the customer to handle the most important security issues without having special tools:&nbsp;The SAP [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":27679,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[262],"class_list":["post-27654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-alm-insights","tag-security"],"acf":[],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/www.blue.works\/wp-content\/uploads\/2020\/08\/blue-emergency-vehicle-lighting.jpg","_links":{"self":[{"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/posts\/27654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/comments?post=27654"}],"version-history":[{"count":2,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/posts\/27654\/revisions"}],"predecessor-version":[{"id":36736,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/posts\/27654\/revisions\/36736"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/media\/27679"}],"wp:attachment":[{"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/media?parent=27654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/categories?post=27654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.blue.works\/en\/wp-json\/wp\/v2\/tags?post=27654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}