NIST CSF Function: Protect


  • This policy establishes the governance framework, requirements, and processes for protecting data held in SAP HANA — data-at-rest encryption, encryption key management, data masking and anonymization, and data retention, aging, and secure deletion.

  • This policy establishes the governance framework, requirements, and processes for securely configuring and hardening SAP HANA — configuration parameters, multitenant isolation, standard and default account hardening, service, feature, and port reduction, secure-store protection, revision management, and configuration change control.

  • This policy establishes the governance framework, requirements, and processes for securing communication and network access for SAP HANA — client-server transport encryption, internal and system-replication encryption, network segmentation and port access control, and certificate and cryptographic material.

  • This policy establishes the governance framework, requirements, and processes for identity and access management in SAP HANA — database users, the catalog, repository, and HDI role model, the full privilege model (system, object, analytic, package, and application privileges), grant-option control, segregation of duties, and privileged and emergency access across single-container and multitenant systems.

  • This policy establishes the governance framework, requirements, and processes for authentication and trust in SAP HANA — authentication methods, password policy, external identity-provider and single sign-on integration, trust configuration, and certificate and credential material.

  • This policy establishes the governance framework, requirements, and processes for protecting data and personal information on the SAP Business Technology Platform — classification, encryption, data residency, personal-data handling, retention, and minimization.

  • This policy establishes the governance framework, requirements, and processes for securing connectivity and network communication across the SAP Business Technology Platform — the Cloud Connector, destinations, private connectivity, transport encryption, exposure, and identity propagation.

  • This policy establishes the governance framework, requirements, and processes for securing integration and APIs on the SAP Business Technology Platform — API authentication and management, integration flows, event and messaging security, partner governance, and payload protection.

  • This policy establishes the governance framework, requirements, and processes for managing secrets, keys, and certificates across the SAP Business Technology Platform — service keys and bindings, application secrets, credential storage, encryption keys, and certificate lifecycle.

  • This policy establishes the governance framework, requirements, and processes for secure development and extension on the SAP Business Technology Platform — extension governance, the secure development lifecycle, CI/CD and transport, dependency governance, application security, and workload security.

  • This policy establishes the governance framework, requirements, and processes for identity and access management across the SAP Business Technology Platform — identity federation and trust, authentication, authorization through role collections, administrative and emergency break-glass access, non-human identities, and identity lifecycle across all BTP environments.

  • This policy establishes the governance framework, requirements, and processes for securely configuring and hardening the SAP Business Technology Platform — from the global account and directory structure through subaccounts, entitlements, and the Cloud Foundry, Kyma, and ABAP environments — and for keeping configuration in a known-good state.