Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: Best Practices for Securing SAP Business Technology Platform

Onapsis
06/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


there's three key areas of focus, as you can see. BTP security recommendations, I keep hopping on about that, but I just think it really is a really important thing. It's a great bit of work that SAP has done to ensure, A, they're just clearly communicating, this security is something that's a shared responsibility between SAP and their customers. So making sure that their customer's aware of, not only that they have a responsibility, but what types of actions should they take place in order to ensure they're meeting their part of that model. Identity and access management for users, for applications, for systems that are interacting with and through BTP, kind of challenging understanding who they are, what do they need to be able to do ensuring they just have that access as things are decommissioned, ensuring that access goes away, that needs to be done kind of through a more kind of enterprise automated process. So having IAM is really important. And then as I've said, BTP is something for you to build on top of. So making sure you're doing that in a secure way is critical. You could do a lot with the recommendations and others to ensure that the foundations of BTP are all secure. If what you build on top is adding risk, then you're kind of not doing yourself any favors. So ensuring that you're coming in and building secure applications, doing secure development on top of BTP is critical. And on that part, Alex, I think it's, even though it's a simple slide, it really helps us understand what are the drivers or what are the strategies that we should pursue when we start addressing security on BTP, right? On one hand, it's all of those settings, integrations, the configurations around BTP, which are highlighted by SAP on the security recommendations, which is the link that Alex mentioned. It has hundreds of different settings and things that we need to ensure that are properly set. The other is how do we enable access, right? Do we use SAP, a default identity provider? Do we use our own IDP? Do we combine, do we enable rules? Do we use identity and access service, which changed name and it's Cloud Identity Services, I think from SAP. How do we provision on different sub-accounts? How do we grant permissions access, platform users versus users of the cockpit? So there are many different concepts. Again, for me, the key is complexity, right? So when these type of technologies come into play, it's important to understand the building blocks. So we understand how do we do to secure this. And last but not least, are we scanning the code, the security of the code of the applications that we develop on top of BTP? Whereas it's ABAP or JavaScript or any other language, it's important to integrate a secure development lifecycle for the applications, which are gonna be business applications that we develop on top of this platform. Perfect, thanks JP. So in terms of the recommendations, the kind of, again, beating this drum really hard, like pay attention to SAP's recommendations, make sure you kind of review that or the appropriate team within your enterprise is reviewing that. And you have a plan for how you're gonna address, as JP said, it's a very long document. How are you gonna manage and address ensuring which of those parameters are appropriate for you and what's the right value for you to apply those parameters. And then that ongoing practice of ensuring you're still meeting what you've defined as kind of minimum acceptable security for you and your enterprise. It's available, there's a link, as Sean said, the slides will be shared. Kind of, this is the look and feel when you go in. So you can come in and kind of see the types of pieces. There's a lot of content to go through. JP, I know we talked about doing a demo, but I'm not sure we have the time to go through that. How do you feel? I think we can, if I may share a screen. Let me, one second. There we go. So can you see? I see it. Perfect, all right. So this is the SAP documentation, right? So we have different elements of a security guide. This is one example of documentation from SAP. If we go and, for example, search. It's very simple, BTP security recommendations. We can see the content, we can browse it, we can download it. If we go to the bottom of it, we can see that it's 235. So we're talking about hundreds of different recommendations with different criticalities. We can filter. So I would say if security for BTP is something that you're pursuing, then this is the place to start with. This is your guidance in terms of deploying security on a BTP, how it's set up, how it's configured. The starting point is to start with BTP security. The starting point, right? And we can see different examples, logging on different categories. Well, a lot around logging, identity and authentication. And I can select for looking at the 235, but just wanted to give you a look and feel. Everything comes with a recommended value and the value that it has by default. Many of these are settings. So there's a default value, but there's also, we can change that, right? That's the issue with configurations and settings is that even though we can configure them into a secure state, if we don't properly manage who has access to admin to change settings, those settings could go back to insecure state and expose the entire instance. So secure recommendations from SAP, it's a live document. You can see, you can navigate, you can download. This is the starting point.

TL;DR

  • SAP BTP security requires focus on three key areas: implementing SAP's security recommendations, establishing robust identity and access management, and ensuring secure development practices for custom applications.
  • SAP's BTP security recommendations document contains over 235 specific configuration settings and best practices, serving as the essential starting point for securing the platform.
  • The shared responsibility model means customers must actively configure and maintain security settings, as default configurations may not provide adequate protection for production environments.
  • Ongoing security management is critical because configuration settings can be changed by administrators, potentially reverting secure configurations back to vulnerable states without proper access controls.

Three Pillars of SAP BTP Security

Securing SAP Business Technology Platform requires a comprehensive approach across three critical areas. First, organizations must implement SAP's BTP security recommendations—a detailed framework that clarifies the shared responsibility model between SAP and customers. This extensive documentation provides specific guidance on configuration settings, logging practices, and platform hardening. Second, robust identity and access management is essential for controlling user, application, and system interactions within BTP. This includes implementing enterprise-grade IAM processes for provisioning, deprovisioning, and managing permissions across sub-accounts and platform roles. Third, secure application development practices must be integrated into the development lifecycle for any custom applications built on BTP, whether using ABAP, JavaScript, or other supported languages.

Navigating SAP's Security Recommendations

SAP's BTP security recommendations document serves as the foundational resource for platform security, containing over 235 specific recommendations with varying criticality levels. Each recommendation includes default values and recommended secure configurations, covering categories such as logging, identity authentication, and platform settings. The document is available as a live, searchable resource that organizations can browse online or download for internal review. However, the challenge lies not just in understanding these recommendations, but in determining which parameters are appropriate for each organization's specific context, establishing acceptable security baselines, and maintaining ongoing compliance as the platform evolves and new recommendations are added.

Chapters

0:00 - Three Key Areas of SAP BTP Security
1:33 - Understanding Security Strategy Drivers
3:38 - SAP Security Recommendations Overview
4:33 - Live Demo: Navigating SAP Documentation
6:21 - Exploring Recommendation Categories and Values

Key Quotes

0:15 "It's a great bit of work that SAP has done to ensure, A, they're just clearly communicating, this security is something that's a shared responsibility between SAP and their customers."
1:18 "If what you build on top is adding risk, then you're kind of not doing yourself any favors. So ensuring that you're coming in and building secure applications, doing secure development on top of BTP is critical."
2:49 "For me, the key is complexity, right? So when these type of technologies come into play, it's important to understand the building blocks. So we understand how do we do to secure this."
7:14 "That's the issue with configurations and settings is that even though we can configure them into a secure state, if we don't properly manage who has access to admin to change settings, those settings could go back to insecure state and expose the entire instance."

FAQ

Where can I find SAP's official security recommendations for BTP?

SAP provides a comprehensive, live document containing over 235 security recommendations that can be accessed through SAP's documentation portal by searching for 'BTP security recommendations.' The document is browsable online and downloadable, with filtering capabilities by category and criticality level.

What are the main categories covered in SAP's BTP security recommendations?

The recommendations cover multiple categories including logging and monitoring, identity and authentication, platform configuration settings, and access management. Each recommendation includes both default values and recommended secure configurations, with criticality ratings to help prioritize implementation.


Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Identity & Access
  • Application Security
  • Best Practices
  • Technical Deep Dive
  • SAP Business Technology Platform Security
  • Cloud Platform Configuration
  • Identity and Access Management
  • Secure Application Development
  • Shared Responsibility Model
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: Best Practices for Securing SAP Business Technology Platform

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version