Cloud 101CircleEventsBlog
Gain exclusive access to CSA’s extensive network of cloud security experts by becoming a corporate member. Learn how today.

CSA Official Press Release

Published 01/06/2020

Cloud Security Alliance Releases First in a Series of Critical Controls Implementation for SAP Guidelines

Cloud Security Alliance Releases First in a Series of Critical Controls Implementation for SAP Guidelines

Document to help organizations securely migrate to operate ERP applications in the cloud

Seattle – Jan. 6, 2019 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced the release of Critical Controls Implementation for Systems Applications and Product (SAP) (Part 1), the first in a series of implementation documents focusing on specific ERP technologies. This document, authored by CSA’s Enterprise Resource Planning (ERP) Working Group, takes a more technical, granular approach and is designed to help organizations securely migrate to and operate ERP applications in the cloud.

This document and its companion piece, scheduled for release in Q1 2020, act as follow-ups to the Top 20 Critical Controls for Cloud Enterprise Resource Planning (ERP) Customers (June 2019), which took a more general approach to the 20 critical controls required to secure cloud ERP applications. Now, with Critical Controls Implementation for SAP (Part 1), SAP administrators have a more detailed examination of controls implementation, as well as a set of checklists for the for the first set of 10 controls:

  • APP01 - Secure Landscape
  • APP02 - Baseline Secure Configurations
  • APP03 - Security Vulnerabilities
  • INT01 – Secure Integrations and API
  • DAT01 – Continuous Monitoring
  • DAT02 – Data Separation
  • DAT03 – Data Encryption
  • BUS01 - Inventory of Business Assets, Data and Processes
  • BUS02 - Business Process Controls
  • BUS03 - Continuous Compliance

“Without a framework that aligns with standard controls, security configurations and vulnerabilities for cloud ERP applications can be difficult to navigate. Because ERP applications are so complex and diverse, for any guidance document to be truly useful from an implementation perspective, specific technologies must be addressed. It’s our hope that this set of guidelines serves as a springboard for SAP administrators in their journey to implementing and securing their ERP solutions,” said Juan Perez-Etchegoyen, chair of the Enterprise Resource Planning working group, and CTO of Onapsis.

The controls implementation and the checklists apply to SAP NetWeaver(C) ABAP(C) and all its versions and provide a detailed description of the control implementation. The checklists provide general steps as well as some direction on how to carry out the implementation of the controls. Combined with the previously released Top 20 Critical Controls document, it explains who would be typically responsible in an IaaS or SaaS scenario.

The Enterprise Resource Planning WG seeks to develop best practices to enable organizations that run their business on large ERP implementations, such as SAP or Oracle applications, to securely migrate to and operate in cloud environments. Individuals interested in becoming involved in future ERP Working Group research and initiatives are invited to visit the join page.

Download the Critical Controls Implementation for SAP (Part 1).

Share this content on your favorite social network today!

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.

For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.