Technology: HANA


  • This policy establishes the governance framework, requirements, and processes for securely configuring and hardening SAP HANA — configuration parameters, multitenant isolation, standard and default account hardening, service, feature, and port reduction, secure-store protection, revision management, and configuration change control.

  • This policy establishes the governance framework, requirements, and processes for securing communication and network access for SAP HANA — client-server transport encryption, internal and system-replication encryption, network segmentation and port access control, and certificate and cryptographic material.

  • This policy establishes the governance framework, requirements, and processes for protecting data held in SAP HANA — data-at-rest encryption, encryption key management, data masking and anonymization, and data retention, aging, and secure deletion.

  • This policy establishes the governance framework, requirements, and processes for securing integration and data provisioning for SAP HANA — remote sources and Smart Data Access, Smart Data Integration and replication, data-provisioning agents and adapters, and integration credentials.

  • This policy establishes the governance framework, requirements, and processes for securing development and application security on SAP HANA — SQLScript and stored procedures, calculation views and analytic privileges, XS and XSA applications, repository and HDI-container objects, and the secure development lifecycle.

  • This policy establishes the governance framework, requirements, and processes for logging, monitoring, and detecting security-relevant activity in SAP HANA — audit policy configuration, mandatory auditing, audit trail protection and retention, SIEM integration, and monitoring, alerting, and detection.

  • This policy establishes the governance framework, requirements, and processes for identity and access management in SAP HANA — database users, the catalog, repository, and HDI role model, the full privilege model (system, object, analytic, package, and application privileges), grant-option control, segregation of duties, and privileged and emergency access across single-container and multitenant systems.

  • This policy establishes the governance framework, requirements, and processes for authentication and trust in SAP HANA — authentication methods, password policy, external identity-provider and single sign-on integration, trust configuration, and certificate and credential material.

  • Establishes the governance framework, requirements, and control standards necessary to define, implement, and maintain secure configuration settings across SAP HANA database environments to protect data integrity and confidentiality, enforce database-level access controls, and reduce the risk of unauthorized access, data compromise, and system exploitation.