This policy establishes the governance framework, requirements, and processes for protecting data and personal information on the SAP Business Technology Platform — classification, encryption, data residency, personal-data handling, retention, and minimization.
This policy establishes the governance framework, requirements, and processes for logging, monitoring, and detecting security-relevant activity across the SAP Business Technology Platform — audit logging, application and runtime logs, alerting, SIEM integration, retention, and detection and response.
This policy establishes the governance framework, requirements, and processes for maintaining a complete and accurate inventory of assets across the SAP Business Technology Platform — global accounts, subaccounts, environments, services, entitlements, and related identity and connectivity assets.
This policy establishes the governance framework, requirements, and processes for governing the SAP Business Technology Platform as a cloud service and for defining the shared responsibility for security between SAP and the organization — account model, entitlement governance, region strategy, guardrails, and provider dependency.
This policy establishes the governance framework, requirements, and processes for managing compliance, data residency, and provider assurance for the SAP Business Technology Platform — obligation mapping, data location, provider certifications and attestations, subprocessor governance, and audit evidence.
This policy establishes the governance framework, requirements, and processes for securing connectivity and network communication across the SAP Business Technology Platform — the Cloud Connector, destinations, private connectivity, transport encryption, exposure, and identity propagation.
This policy establishes the governance framework, requirements, and processes for securing integration and APIs on the SAP Business Technology Platform — API authentication and management, integration flows, event and messaging security, partner governance, and payload protection.
This policy establishes the governance framework, requirements, and processes for managing secrets, keys, and certificates across the SAP Business Technology Platform — service keys and bindings, application secrets, credential storage, encryption keys, and certificate lifecycle.
This policy establishes the governance framework, requirements, and processes for secure development and extension on the SAP Business Technology Platform — extension governance, the secure development lifecycle, CI/CD and transport, dependency governance, application security, and workload security.
This policy establishes the governance framework, requirements, and processes for identity and access management across the SAP Business Technology Platform — identity federation and trust, authentication, authorization through role collections, administrative and emergency break-glass access, non-human identities, and identity lifecycle across all BTP environments.
This policy establishes the governance framework, requirements, and processes for securely configuring and hardening the SAP Business Technology Platform — from the global account and directory structure through subaccounts, entitlements, and the Cloud Foundry, Kyma, and ABAP environments — and for keeping configuration in a known-good state.
Establishes the governance framework, requirements, and control standards necessary to define, implement, and maintain secure configuration settings across SAP Business Technology Platform environments to ensure secure tenant configuration, identity and access management, service consumption, and integration controls, reducing the risk of unauthorized access, data exposure, and insecure cloud operations.