NIST CSF Function: Protect


  • Establishes an enterprise-grade SAP security awareness, training, and user responsibility framework that enables organizations to reduce human-driven risk through structured education, accountability, and behavioral enforcement across SAP environments. Designed for complex landscapes, this policy bridges the gap between enterprise cybersecurity awareness expectations and SAP-specific risks, including excessive access, improper data handling, misuse of privileged access,…

  • Establishes an enterprise-grade SAP vulnerability, patch, and maintenance management framework that enables organizations to identify, prioritize, and remediate security vulnerabilities with precision, speed, and control across SAP environments. Designed for complex landscapes, this policy bridges the gap between enterprise vulnerability management expectations and SAP-specific risks, including delayed patching, incomplete system coverage, inconsistent prioritization, lack of…

  • Establishes an enterprise-grade SAP change and transport governance framework that enables organizations to manage and execute changes across SAP environments with control, discipline, and accountability. Designed for complex landscapes, this policy bridges the gap between enterprise change management expectations and SAP-specific risks, including unauthorized changes, weak segregation of duties, improper transport sequencing, and limited traceability.…

  • This policy establishes the governance framework, requirements, and processes for configuration-driven business controls in business applications hosted on SAP NetWeaver AS Java — functional configuration control, approval and workflow enforcement, delegation of authority, thresholds, and segregation of duties.

  • This policy establishes the governance framework, requirements, and processes for securing development and application security on SAP NetWeaver AS Java — application authorization and Java EE security, secure coding, session and input handling, dependency governance, and secure deployment.

  • This policy establishes the governance framework, requirements, and processes for securing integration and interfaces for SAP NetWeaver AS Java — destinations, RFC/JCo, web services, messaging, and principal propagation and interface credentials.

  • This policy establishes the governance framework, requirements, and processes for securing communication and network access for SAP NetWeaver AS Java — transport encryption, administrative and internal channel protection, network segmentation and port access control, and certificate material.

  • This policy establishes the governance framework, requirements, and processes for securely configuring and hardening SAP NetWeaver AS Java — engine, service, and ICM parameters, default account hardening, service and port reduction, administrative-interface protection, secure-store protection, and support-package management.

  • This policy establishes the governance framework, requirements, and processes for authentication and trust in SAP NetWeaver AS Java — login modules and authentication stacks, password policy, single sign-on and federation, and ticket and certificate trust.

  • This policy establishes the governance framework, requirements, and processes for identity and access management in SAP NetWeaver AS Java — UME users, groups, roles, and actions, Java EE and portal authorization, segregation of duties, and privileged and default-account governance.

  • This policy establishes the governance framework, requirements, and processes for securing development and application security on SAP HANA — SQLScript and stored procedures, calculation views and analytic privileges, XS and XSA applications, repository and HDI-container objects, and the secure development lifecycle.

  • This policy establishes the governance framework, requirements, and processes for securing integration and data provisioning for SAP HANA — remote sources and Smart Data Access, Smart Data Integration and replication, data-provisioning agents and adapters, and integration credentials.