Blog

  • SAP Change & Transport Management – Efficient and Secure

    Instead of continuously spending large sums fighting fires after deploying changes to the SAP landscape, a tool-supported, automated SAP Change and Transport Management environment with built-in consistency measures can eliminate the root causes of these problems once and for all.

    The necessary measures can be divided into:

    • Organizational measures: clear governance structures, defined responsibilities, and standardized processes for change requests and transport approvals
    • Technical transport validation: automated syntax checks, dependency analysis, and pre-deployment testing before any transport reaches production
    • Consistency assurance: both horizontal (across systems at the same level) and vertical (across system levels, ensuring objects are transported in the right sequence)

    Conclusion: With a certain fatalism, many large SAP organizations still resolve problems arising from change transports reactively. The resulting costs are simply accepted as inherent to the system. Yet with a clean, automated process and embedded consistency measures, many of these efforts can be eliminated once and for all. The investment in proper SAP Change & Transport Management pays for itself rapidly through reduced downtime, fewer emergency fixes, and lower overall operational costs.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Change & Transport Management — Efficient and Secure

    SAP Change & Transport Management — Efficient and Secure. By Dieter Steiger.

    Instead of continuously fighting problems after importing changes into the SAP landscape with expensive firefighting efforts, a tool-supported, automated SAP Change and Transport Management environment with built-in consistency assurance measures can eliminate the root causes of these problems once and for all.

    The measures to be taken can be divided into organizational measures, technical transport validation, and consistency assurance measures with horizontal and vertical effect.

    • Organizational measures: Clear governance structures, defined roles and responsibilities for transport management, mandatory approval workflows
    • Technical transport validation: Automated consistency checks before transport execution, dependency analysis between transport requests
    • Horizontal consistency assurance: Ensuring that transport sequences are maintained across system levels (preventing “overtaker transports”)
    • Vertical consistency assurance: Ensuring completeness and consistency within system tiers (DEV → QA → PRD)

    Conclusion: With a certain fatalism, many large SAP organizations still solve reactively the problems arising from transporting changes. The resulting costs are simply accepted as inherent to the system. However, with a clean, automated process and embedded consistency assurance measures, many of these efforts can be eliminated once and for all.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • Application Security: Money Still Being Squandered on IT

    Security is especially important in online applications, yet far too little attention is paid to it. Perform a quick risk assessment just prior to implementation, jerry-rig a plug for the biggest holes, and you’ll have the software up and running in no time. Then a few days later, the first bytes of customer data are stolen. Does it have to happen this way?

    In an incredibly short time, online security has become an important topic. Data breaches, identity theft, and financial fraud are daily news. Yet despite this, many organizations still treat application security as an afterthought rather than a fundamental requirement.

    The root cause is often economic: security testing and secure development practices cost money upfront, while the costs of security breaches often materialize much later and may fall on customers rather than the organization responsible. This misalignment of incentives leads to systematic under-investment in application security.

    Best practices for application security include: threat modeling during design phase, security requirements alongside functional requirements, security testing integrated into the development process, code reviews with security focus, and penetration testing before production deployment.

    In the SAP context, application security is particularly important because SAP systems contain sensitive business data and are increasingly accessible via web interfaces. Authorization concepts must be carefully designed and tested. Custom developments must be reviewed for common vulnerabilities such as SQL injection and cross-site scripting.

    beteo incorporates application security considerations into all our ALM engagements. We help our clients establish security testing practices that identify and address vulnerabilities before they can be exploited. Investing in security upfront is always cheaper than dealing with a breach after the fact.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Testing with HP Products: A Contradiction?

    It is striking how difficult SAP finds it to position itself as a reseller of HP software components.

    Considering the complexity and heterogeneity of SAP, it would actually seem obvious that the HP software suite is the ideal instrument for managing SAP environments. SAP promotes its own Solution Manager as the central ALM platform, while HP offers a more comprehensive and mature testing toolset. This creates a tension for customers who must choose between tight SAP integration and superior testing capabilities.

    SAP and HP have established a partnership, but the integration between SAP’s own tools and HP’s testing and ALM suite remains fragmented. Customers who invest in HP Quality Center or HP LoadRunner for SAP testing often find that integration points are limited and require significant customization effort.

    Conclusion: SAP and HP should urgently work together to develop a joint strategy for providing a common solution for managing complex IT landscapes. Until then, customers need to carefully evaluate both options and implement integration solutions that bridge the gap between SAP-native tools and the HP software suite.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Testing with HP Products — A Contradiction?

    SAP Testing with HP Products — A Contradiction and HP a Marriage of Convenience?

    It is striking how difficult SAP finds it to position itself as a reseller of HP software components.

    Considering the complexity and heterogeneity of SAP, it would actually seem obvious that the HP software suite is the ideal instrument for managing SAP.

    Conclusion: SAP and HP should absolutely work together to develop a strategy for providing a joint xApp for managing complex IT environments.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • HP Quality Center 10: From a Test Manager’s Perspective

    The new Version 10 of the HP Quality Center (QC) is now available. Yet what are the actual advantages of the new QC compared to its predecessor from a Test Manager’s perspective? Below, I will take a look at some of the new features and changes, and I will answer the question whether one should even make the switch.

    The Most Significant Changes:

    HP Quality Center 10 brings several important new features. The most significant change is the complete redesign of the user interface, which is now based on a web client rather than a dedicated client application. This brings advantages in terms of deployment and maintenance, but requires adaptation from experienced QC users.

    New features include improved dashboard functionality with customizable views and reports, better integration with HP’s ALM tool suite, enhanced defect workflow capabilities, and improved performance with large test repositories.

    From a Test Manager’s perspective, the most valuable improvements are in reporting and dashboard functionality. The new dashboards provide better real-time visibility into test execution status and defect trends. The improved reporting capabilities make it easier to create management-level reports that communicate test progress and quality status effectively.

    The migration from QC 9.x to QC 10 requires careful planning. Data migration needs to be tested thoroughly, and all integrations with other tools must be re-validated. Custom workflows and business rules need to be reviewed and potentially adapted for the new version.

    Recommendation: HP Quality Center 10 offers genuine improvements, particularly in reporting and dashboarding. However, the migration effort should not be underestimated. A phased migration approach with thorough testing is recommended.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Enhancement Packages: Not a Panacea After All

    The new concept of the Enhancement Packages (EhPs) from SAP is ingenious from a technical perspective. It’s actually too bad that SAP, the supplier par excellence for business software, has taken so long to create this software logistics concept. Based on the time and effort they’ve put in, any SAP CIO can tell you what this gap in the framework has cost customers.

    Yet it’s not quite as cut and dried as one might hope. Enhancement Packages promise selective adoption of new functionality without full system upgrades. In theory, customers can implement new features from an EhP without being forced to activate all the changes it contains. This selective activation is the key promise of Enhancement Packages.

    However, the reality is more complex. The dependencies between different functional areas in SAP mean that activating one feature often requires activating others. Testing effort remains significant because even “selective” activation can have unexpected effects on existing customizing and custom code.

    Furthermore, the tooling for impact analysis of Enhancement Package activations is still immature. Customers need to perform comprehensive impact analysis before and after EhP activation to ensure system stability and business continuity.

    beteo’s experience with Enhancement Package projects shows that success requires: thorough pre-activation impact analysis using specialized tools, careful testing strategy that covers both new and existing functionality, experienced project management that accounts for the complexity of dependencies, and a phased approach that manages risk while delivering value.

    Enhancement Packages are a step in the right direction, but they are not a silver bullet. Customers should approach them with realistic expectations and invest in proper analysis and testing.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Enhancement Packages: What They Can and Cannot Do

    Customers frequently ask whether SAP Enhancement Packages (SAP EHP) can simply be deployed. The expectation is very high: SAP Enhancement Packages are supposed to ensure the flexibility customers love during upgrades, while simultaneously reducing effort.

    SAP Enhancement Packages are functionality packages. Their advantages lie primarily in upgrades of delivered functionalities (Business Functions) — with less effort and lower maintenance costs than classic SAP upgrades. However, an SAP Enhancement Package can only deliver these advantages when there are no or few customer developments and modifications.

    What Enhancement Packages explicitly cannot do:

    • Restore clear responsibilities to customer-specific software artifacts (“Separation of Concerns”)
    • Identify, version-manage, and test customer-specific software artifacts that exist in classic SAP source objects

    Conclusion: If we put existing customer implementations in relation to the SAP standard — which customer can seriously do without their own grown SAP Customizing or Enhancements? The technical capabilities of Enhancement Packages set clear limits in terms of flexibility and customer-specific configuration. SAP Enhancement Packages are a real option for SAP customers, but they must be understood for what they are — one upgrade option among many.

  • Is the SAP Enhancement Package Framework the Hoped-for Cure-All?

    The concept of Enhancement Packages (Enhancement Package Framework, abbreviated EhPs) is simply brilliant. However, considering how long SAP — the standard software provider for business software par excellence — took to establish this software logistics discipline, we can no longer speak of brilliance. What the absence of this framework has cost customers up to now is something every customer should calculate for themselves.

    From a software logistics perspective, SAP has finally done its homework — but again only with a focus on standard software. The EhPs unfortunately still do not apply to customer implementations. Impact analyses, such as those provided by Intellicorp and Panaya for the largest investments in an SAP implementation, are nonexistent.

    What does this mean for SAP customers who have already made the move to EhPs (prerequisite: SAP NetWeaver 7.0)? For those not yet on SAP NW 7.0, the conventional SAP upgrade remains a prerequisite.

    Technical basis: The corresponding EhPs can be deployed time-neutrally, meaning the physical effort remains, but the direct temporal dependency on business-technical follow-up work is decoupled.

    Business technical: In a first step (preparation), all additional requirements for new functionality delivered by SAP in the EhP must be collected. Based on these, a competing analysis of the configured baseline (ALM — investment protection) must be carried out, along with an evaluation of new functionality. Only through this analysis can the impact of a business-technical EhP deployment be determined. Activating individual business switches makes the impact analysis even more demanding — it is now necessary to evaluate which transaction areas are actually used in the organization.

    Conclusion: The time-consuming determination, implementation and testing of new business functionality remains the same, if not increased by additional complexity. The temporal decoupling of the technical EhP deployment may save time — but this time savings should at minimum be reinvested in impact analysis to avoid the risk of production outages.

    🇩🇪 Diesen Beitrag auf Deutsch lesen

  • SAP Enhancement Packages: Options and Limits

    Customers often ask whether SAP Enhancement Packages (SAP EHP) can simply be applied. The expectation behind SAP EHP is very high: SAP Enhancement Packages are supposed to ensure the flexibility customers love in the SAP standard during upgrades while simultaneously reducing effort.

    This expectation is reflected in SAP’s marketing message, which positions Enhancement Packages as the solution for all customers who want to avoid SAP upgrades.

    But let the facts speak: What can Enhancement Packages do, and what can they not?

    SAP Enhancement Packages are functionality packages. Their advantages lie primarily in: upgrades of delivered functionalities (Business Functions) — with less effort and lower maintenance costs than classic SAP upgrades.

    However, an SAP Enhancement Package can only deliver these advantages in a limited context: when no or very few customer developments/modifications are present. By customer developments/modifications I mean ABAP changes, modifications to modules/classes, customer-specific transactions/programs, etc. — everything that must accordingly be managed in the CIM model as customer-specific software artifacts.

    What Enhancement Packages explicitly cannot do:

    • Establish clear responsibilities back to customer-specific software artifacts (“separation of concerns”)
    • Identify/version-manage customer-specific software artifacts (customizing and developments) that are in classic source SAP objects, and especially test their correct “impact”

    Conclusion: When we put existing customer implementations in relation to the SAP standard — which customer can seriously do without their customer-specific, grown SAP “customizing” or “enhancements”? In practice, this is truly not easy. It becomes clear: the technical possibilities of Enhancement Packages set clear limits in terms of flexibility and customer-specific adaptation.

    Nevertheless, SAP Enhancement Packages are a real option for SAP customers who want to move forward. But they must be understood for what they are — one upgrade option among many.

    🇩🇪 Diesen Beitrag auf Deutsch lesen