This policy establishes the governance framework, requirements, and processes for protecting data held in SAP HANA — data-at-rest encryption, encryption key management, data masking and anonymization, and data retention, aging, and secure deletion.
This policy establishes the governance framework, requirements, and processes for securely configuring and hardening SAP HANA — configuration parameters, multitenant isolation, standard and default account hardening, service, feature, and port reduction, secure-store protection, revision management, and configuration change control.
This policy establishes the governance framework, requirements, and processes for securing communication and network access for SAP HANA — client-server transport encryption, internal and system-replication encryption, network segmentation and port access control, and certificate and cryptographic material.
This policy establishes the governance framework, requirements, and processes for identity and access management in SAP HANA — database users, the catalog, repository, and HDI role model, the full privilege model (system, object, analytic, package, and application privileges), grant-option control, segregation of duties, and privileged and emergency access across single-container and multitenant systems.
This policy establishes the governance framework, requirements, and processes for authentication and trust in SAP HANA — authentication methods, password policy, external identity-provider and single sign-on integration, trust configuration, and certificate and credential material.
This policy establishes the governance framework, requirements, and processes for protecting data and personal information on the SAP Business Technology Platform — classification, encryption, data residency, personal-data handling, retention, and minimization.
This policy establishes the governance framework, requirements, and processes for securing connectivity and network communication across the SAP Business Technology Platform — the Cloud Connector, destinations, private connectivity, transport encryption, exposure, and identity propagation.
This policy establishes the governance framework, requirements, and processes for securing integration and APIs on the SAP Business Technology Platform — API authentication and management, integration flows, event and messaging security, partner governance, and payload protection.
This policy establishes the governance framework, requirements, and processes for managing secrets, keys, and certificates across the SAP Business Technology Platform — service keys and bindings, application secrets, credential storage, encryption keys, and certificate lifecycle.
This policy establishes the governance framework, requirements, and processes for secure development and extension on the SAP Business Technology Platform — extension governance, the secure development lifecycle, CI/CD and transport, dependency governance, application security, and workload security.
This policy establishes the governance framework, requirements, and processes for identity and access management across the SAP Business Technology Platform — identity federation and trust, authentication, authorization through role collections, administrative and emergency break-glass access, non-human identities, and identity lifecycle across all BTP environments.
This policy establishes the governance framework, requirements, and processes for securely configuring and hardening the SAP Business Technology Platform — from the global account and directory structure through subaccounts, entitlements, and the Cloud Foundry, Kyma, and ABAP environments — and for keeping configuration in a known-good state.