This policy establishes the governance framework, requirements, and processes for authentication and trust in SAP NetWeaver AS Java — login modules and authentication stacks, password policy, single sign-on and federation, and ticket and certificate trust.
This policy establishes the governance framework, requirements, and processes for securely configuring and hardening SAP NetWeaver AS Java — engine, service, and ICM parameters, default account hardening, service and port reduction, administrative-interface protection, secure-store protection, and support-package management.
This policy establishes the governance framework, requirements, and processes for securing communication and network access for SAP NetWeaver AS Java — transport encryption, administrative and internal channel protection, network segmentation and port access control, and certificate material.
This policy establishes the governance framework, requirements, and processes for securing integration and interfaces for SAP NetWeaver AS Java — destinations, RFC/JCo, web services, messaging, and principal propagation and interface credentials.
This policy establishes the governance framework, requirements, and processes for securing development and application security on SAP NetWeaver AS Java — application authorization and Java EE security, secure coding, session and input handling, dependency governance, and secure deployment.
This policy establishes the governance framework, requirements, and processes for configuration-driven business controls in business applications hosted on SAP NetWeaver AS Java — functional configuration control, approval and workflow enforcement, delegation of authority, thresholds, and segregation of duties.
This policy establishes the governance framework, requirements, and processes for logging, monitoring, and detecting security-relevant activity in SAP NetWeaver AS Java — security audit logging, application and system logging, log protection and retention, SIEM integration, and monitoring, alerting, and detection.
This policy establishes the governance framework, requirements, and processes for identity and access management in SAP NetWeaver AS Java — UME users, groups, roles, and actions, Java EE and portal authorization, segregation of duties, and privileged and default-account governance.
Establishes the governance framework, requirements, and control standards necessary to define, implement, and maintain secure configuration settings across SAP NetWeaver Application Server Java environments to enforce identity and access management, secure communication, and platform hardening, reducing the risk of unauthorized access, data exposure, and system compromise.