Transcript
So you do have a role in BTP security. So while it is offered as a service, it's going to platform as a service, that doesn't mean that it's 100% the vendor's responsibility to keep that environment secure. They certainly have an element of responsibility and SAP is very clear in terms of what they've published and what exactly their security role is. They've also published lots of guidance and made clear to their customers that you too have a role in ensuring that your BTP is secure. So one of the clearest one is the BTP security recommendations that's published and maintained by SAP. So as the name suggests, this is explicitly what SAP recognizes as important configurations that have a security kind of consequence for your BTP. And if you want to have a secure BTP, these are the recommendations that they provide to you. So you can see on the left of the screen kind of the types of pieces it is. So it's not really about patching. That is obviously something that's strongly the responsibility of the vendor, but the ways in which you've customized and configured BTP or anything else that you have for that matter has an effect on the security posture of that application. The way you manage identity and access. So being very specific about the types of access people have, ensuring that people or machines who are connecting to BTP very clearly identify who they are and based on that identification have explicit access. That is just what they need to do. Helps reduce that attack purchase surface. And then kind of how are we managing the data? How are we ensuring that it's secure, that it's not compromised in any way? And then how do you analyze and make sure all of this is taking place? So the security recommendations are a great first start in order to understand kind of what is the world of security. It's not the all-encompassing world, but it's a big part of what you should be thinking about as you think about securing BTP. It can give you kind of insights into what are the elements of BTP security that you should be monitoring. And kind of the risks of not doing that, you know, it's kind of somewhat self-evident, but I just want to point out what some of them are. Like, you know, so obviously the risk is lower security, but there's also some other elements to risks associated with kind of moving to more of a BTP model. So one that kind of we encounter sometimes is compliance risk. So there can be a belief, just like some people may believe, well, moving to the cloud like this, I'm automatically secure, so therefore I don't have to do anything to do with security. There can be kind of a mistaken belief that moving to the cloud, I'm automatically compliant, like compliance doesn't count in some way. So it's important to, you know, always recognize and remember that when you go to the cloud, you still have to meet your regulatory requirements in terms of compliance. You still have to adhere to whatever standards are applicable to your business or that business division who's using BTP. Another kind of risk is BTP is new, and that can be something that the attacker groups that JP talked about earlier could try and take advantage of. If people are still kind of getting to grips with understanding what BTP is and how it's used, that could be something an attacker could take advantage of to try and kind of bamboozle their way through support or through some other group in order to gain access that they shouldn't have. To a BTP target. And for me, one of the elements I see that's really the biggest is people kind of misunderstanding what are they responsible for. So that myth I talked about earlier that if it's in the cloud, if it's being hosted like this, that security is taken care of for me. You know, there's an expression I grew up with that ignorance is no defense in the eyes of the law. So just because you didn't know that something was your responsibility doesn't mean you're immune from the consequences of not taking that action. And that's doubly true here that you really need to make sure you look at the information that SAP is providing around what are you responsible for? What are they responsible for? And you understand kind of your responsibilities when it comes to security for BTP and you build in a plan to ensure that BTP is just as secure as it would be if this was something on premise with the same kind of data and the same kind of access. JP, anything you'd add in terms of kind of risks related to kind of moving to a model like BTP? I think you covered the categories quite well. And we can get into examples that I was covering over the questions, great questions, by the way. I can't wait to get into the questions by the end. But yeah, there are many different types of issues. And we have the categories here and we'll get into more of the details, specific details. But yeah, it's important to understand that no, software vulnerabilities are less of a problem in the cloud as it is BTP. And by software vulnerabilities, I mean a vulnerability on a specific BTP service. That will be promptly addressed by SAP and there are SLAs and there are contractual obligations that we have in place when we become SAP customers that forces them to do that. However, BTP is a platform as a service, so it's extremely complex from a deployment and configuration perspective, provisioning, user access perspective, integration perspective, but also we use it to build applications. So software vulnerabilities could be affecting our own applications as well. So there are many different aspects of us as customers using BTP that could introduce security risks. Perfect. Thanks, JP. So I want to spend the next bit of time talking about the services that BTP has that can help you build securely on top of it. So it is a platform as a service, as JP referenced. So you build on top of that and SAP provides a lot of great services to help you ensure you're doing so in a secure way. So I'll spend a little bit of time here talking about each of these services. What I want to do is start off with the authorization and trust management service. So this does exactly what it sounds like it does. You can kind of read there on the screen. So it does user authentication, which, you know, this day and age, that's kind of a no-brainer. Like, make sure the people logging in are who they say they are. How do you prove that? But it's also about application authentication as well. So make sure the applications that are talking to or within BTP, that they are the applications that should be talking here. Kind of make sure they authenticate and kind of prove that they're a trusted application. And then for both the users and the applications, kind of, well, we've proven who they are, who they say they are. What should they be able to do? So kind of what authorizations should they have? Let's make sure if they only need to read a certain amount of data, then that's all that they can do. They can't modify that data or they can't read other data that's adjacent, let's say, but perhaps more kind of more sensitive and something you really want to ensure that is protected and treated in a protected way. It also will integrate with, like, Auth 2.0 and other kind of authentication mechanisms. So enables you to really kind of take advantage of investments you've already made in authorization and IAM type technologies and leverage that for your users coming to BTP versus having to give them a whole nother set of credentials there in BTP. So it's about kind of making sure that access is tightly controlled. People have just what they have to get the functions done, but not no broader than that. So this makes it easier to enable that type of capability just straight in BTP itself. If we look at kind of the audit log, you know, this is a real key capability. So the ability for, you know, have something there that's recording security events. So if events of that nature happened, having somewhere that's recorded that you, the SOC, the audit team can get to later, making sure that user activities are being monitored. You need that audit trail of all the actions that have taken place so you can prove a negative or a positive in terms of kind of what happened, especially when we talk about some kind of compliance reporting. You know, to be able to know that no one did, you know, no one performed this kind of action kind of lets you meet compliance requirements. And it just helps you with any kind of ongoing audit requirement you might have as an enterprise. If you need to have a regular audit done, this security audit log service, you know, really enables that. It has those logs there that are able to come and be retrieved through various applications. And then those audits can be performed and you can ensure that you have the same level of audit and accountability in BTP that you do have on your on-premise systems. If we look at the credential store, you know, this is really critical now. Now that you have kind of services and applications that are talking to each other, we need to ensure that they have the access to get the appropriate credentials, but that those credentials are treated as in the secure way they should be. So it provides encrypted storage, you know, so you can have the keys and passwords being stored in an encrypted way. Allows you to do credential management and ensure that any application running on BTP can kind of securely store and retrieve credentials from the store. So you can have kind of trust and faith in how these credentials are being managed, but also to do cryptographic operations. So signing digital certificates, et cetera, having a one place that's built into the platform to enable you to kind of ensure that these functions are carried out in a secure way is really important. And also kind of if you have requirements around data protection and privacy through how credentials are managed, then this is a way to ensure that you're setting that up in a way that meets your requirements, I should say, so you're not in violation of any kind of local law in terms of how things should be managed. And then for all of these actions, it's auditing those as well. So you can keep track of who's accessing keys, who's accessing credentials. And when I say who, this could be a service, it could be an application, et cetera. But you have that audit trails to understand what was accessed and when. So, again, you have all that monitoring and you have that control over the type of data and actions that are available through here. The next one kind of sounds a little simple, the custom domain service, but this is really quite a critical piece. This is something that's hosted and provided, but really when it comes to your users or your customers, you want them going to a place that they would expect to go in order to interact with you as an enterprise. So you can kind of set up exactly as it kind of says on the screen there, having a custom domain that allows you then to manage your own certificates. You can produce certificates for that domain. So now you have control over those certificates. You can ensure that they're trusted and they're kind of trusted within your enterprise. And it improves kind of the user experience now. They're going to a domain they expect when they interact with your enterprise. They're seeing a certificate that's valid. And I would say kind of to the third bullet there, that helps maybe not reduce phishing attempts, but it helps reduce the likelihood of phishing working. If you've kind of over time kind of taught your user base that actually is interacting with my company's apps, sometimes they have a domain that has nothing really to do with my company. They lose that kind of cross-check, that ability to say, hey, I'm being asked to click on this link and it's going to a domain that has really nothing to do with my company. But they're telling me I need to go there to put in a password or make a change. It can help kind of the customers, or more important, the employees kind of give them that second of pause, which is sometimes all you need before someone's going to click on that phishing link and expose kind of your enterprise to attack. So it's a simple capability, but I think it actually provides a really strong level of security. I'll take a breath there, but we have the SAP Connectivity and Destination Service. So kind of this helps you do a few things. It provides a central configuration of destinations, which are kind of what endpoints, what applications that can be connected to. So instead of every single piece that needs to use a destination having its own copy, and now you have multiple copies, those copies could not be configured well and kind of contain old information. So you run into risk there of some kind of service outage because you haven't updated the copy, let's say, of that destination everywhere. But it also kind of provides a secure storage of credentials. So these destinations then can use those secure credentials versus having to be hard-coded again in each of those copies. And they work with the various authentication strategies or capabilities that are available within BTP. So making sure that it'll work on the level of security that you want versus you having to kind of downgrade your security expectations because it's not supported by kind of the technology you want to use. And it integrates with development tools. So BTP is really a platform for you and your enterprise to build on top of. So the fact that these security tools or this specific security tool is kind of really in there in that development platform means it's something that's not an effort for your developers to take advantage of. We want to shift left always when we're doing security. We want to make it as easy as possible for the people doing that creating to include security by design and as part of that development. This is later on. I have to try and force it in after some kind of security review after the fact is performed. And if we have a look, there's a malware scanning service. So if documents, et cetera, are being passed into or around within BTP, you really want to make sure you're not exposing yourself to attack. In some kind of enterprises and some applications, we need to receive artifacts from other sources. So we need to be able to allow for that transforming. But we need to make sure we have a way to scan that as soon as it comes in, identify kind of threats, viruses, Trojans, et cetera, and then perform an action automatically when that happens. So this is built in, which means as you build on top of BTP, you can just include this in your applications, in your development as needed. So your custom apps can take advantage of this capability there inside of BTP. It also helps with compliance. You're using this built-in service. You can then kind of show that as part of every action where you're receiving these kind of artifacts, you have this malware taking place. You're taking proactive protection as soon as it takes place. I kind of raced through that. I took a little bit of a pause for breath. JP, I know I touched on most things, but anything that you'd like to add kind of based on the different security services that I highlighted there available in BTP? No, no, no. The services section was great. I think it's important to understand that SAP BTP is built on top of many capabilities. And for us that are really now interested on securing these, these security services play an important role. And I see a lot of questions around the services that I'm addressing as we speak. Perfect.