Understanding SAP security risks

Tags:
ABAP
Basis
CO
Development
ED
FI
Financials
Industry solutions
IS-B
IS-H
IS-Ill
IS-P
IS-Retail
IS-T
MySAP
NetWeaver
RIVA
SAP
SAP APO
SAP careers
SEM
TR
Upgrades / implementations
Windows
What is a good resource to help me understand the risks of assigning the &NC& authorization group to a table? I am worried about these tables being accessed by "unauthorized" users? Please post your thoughts. Thank you!

Answer Wiki

Thanks. We'll let you know when a new response is added.

By assigning &NC& authorization group to a table, you are granting access to this table as per values given to S_TABU_DIS (used by table maintenance transactions such as SE16, SE17, SM30, SM31 etc) authorization object.

Discuss This Question: 1  Reply

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
  • SAPSEC
    sillyITgirl, the history of table group &NC& is that back in the old days, SAP created tables without authorization group restrictions. When they decide to address this issue, they already had many tables created. To same time, they decided to group all table which were unassigned to the &NC& authorization group. Therefore, by giving someone access to this group, you are giving access to many tables for which you don't have a clue as to what the tables provide access to. Therefore, never give access to &NC& if you can help it. There are times where it may be necessary though but you will discover those exceptions with a system trace. Regards, mr
    0 pointsBadges:
    report

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following