SAP security is not only about Segregation of Duties (SoD) and user access rights but should also consider the layer below application security, being the infrastructure and kernel security. Since systems are more and more interconnected the security on communication layer as well as on kernel as become one of the top security priorities. It’s all about keeping the bad guy out to avoid risk of sabotage, fraud and cyber attack.
Infrastructure vulnerability analysis helps identifying security weaknesses on the layer below application security. Generally speaking, infrastructure management and SAP system administration are two different worlds and there tends to be a gap of knowledge and ownership in between the two. The technical foundation of a system reliability is assessed through the infrastructure vulnerability analysis, the SAP security specialists inspect the vulnerability of the installed SAP components, kernel and services for any known weaknesses.
The results of this (technical) analysis help remediate the quickfixes and may disclose the gaps in administrative policy and procedures within the IT department to pro-actively manage SAP system-security at infrastructure / kernel level.