Category: Application Security

SAP and enterprise application security

  • Application Security: Money Still Being Squandered on IT

    Security is especially important in online applications, yet far too little attention is paid to it. Perform a quick risk assessment just prior to implementation, jerry-rig a plug for the biggest holes, and you’ll have the software up and running in no time. Then a few days later, the first bytes of customer data are stolen. Does it have to happen this way?

    In an incredibly short time, online security has become an important topic. Data breaches, identity theft, and financial fraud are daily news. Yet despite this, many organizations still treat application security as an afterthought rather than a fundamental requirement.

    The root cause is often economic: security testing and secure development practices cost money upfront, while the costs of security breaches often materialize much later and may fall on customers rather than the organization responsible. This misalignment of incentives leads to systematic under-investment in application security.

    Best practices for application security include: threat modeling during design phase, security requirements alongside functional requirements, security testing integrated into the development process, code reviews with security focus, and penetration testing before production deployment.

    In the SAP context, application security is particularly important because SAP systems contain sensitive business data and are increasingly accessible via web interfaces. Authorization concepts must be carefully designed and tested. Custom developments must be reviewed for common vulnerabilities such as SQL injection and cross-site scripting.

    beteo incorporates application security considerations into all our ALM engagements. We help our clients establish security testing practices that identify and address vulnerabilities before they can be exploited. Investing in security upfront is always cheaper than dealing with a breach after the fact.

    🇩🇪 Diesen Beitrag auf Deutsch lesen