Gui Masking
Gui Masking
Gui Masking
2018-08-01
01010100101010100
10100101001011000
10010101011011100
Data Protection & 10010101000101110
01101010101001010
10100101010010101
01001010101001010
01010010110001001
the Insider 01010110111001001
01010001011100110
UI Data Security – driving factors
Compliance & financial risk of data security breaches
valuable business
personal information
information
political commercial
motivation: motivation:
protection of protection of the
individuals organization
internal requirements
legal requirements
(decrease of financial
(compliance)
risk)
© 2018 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 3
Public
UI Data Security
Data protection requirements
UI Masking UI Logging
to conceal specific data (values in to keep data accessible, but log & analyze
fields/columns) – unless required for tasks access, to identify adequate path of action
The solution provides a detailed, structured data access
The solution masks sensitive (configured) values per
log and allows for analysis who exactly received which
default; unmasking requires explicit access rights (on
data (output), how (input), and in which context (IP…)?
top of existing role/authorization setup)
make data elements unavailable for data abuse prevent illegitimate data access and theft
(opportunistic and targeted) by inducing compliant behavior
identify & prove irregular data access
• awareness for data security (“human firewall”) protect employees by decreasing inadvertent breaches
• top-of-class protection measures trust (employees, customers, and investors)
© 2018 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 7
Public
High level solution architecture (example: SAP GUI)
• UI Masking and UI Logging can be used individually or jointly, depending on the required functionality
• add-ons to SAP NetWeaver – modification free installation, secure server-based functionality with minimal
performance impact
Response
UI Logging
observed data asynchronous call of
traffic log & filtering service
• Based on SAP NetWeaver (cf. RCS Availability Matrix or contact product management for detailed requirements)
• Available for ECC, HEC, Suite on HANA, S/4HANA, “SAP S/4HANA Cloud, private option”
• Maintenance: integrated into standard maintenance, planned until end 2025
• Enhancements and adaptations can be delivered on request
What is UI Masking?
• Sensitive data are masked on the server side and editing is blocked in SAP user interfaces; resulting in consistent
protection also in table display, value help, export, download, print etc.
• provides unmasked data to specifically authorized users/roles only – on top of existing authorization system (PFCG)
• Small-scale, auditable, archivable “access trace” in case of access to protected data fields
How does it work?
• Extensive configuration options on field level:
• Which fields are masked in which way – including mass configuration report for a quick start.
• Which users/roles are shown clear data
• Which accesses are traced
• Complex business logic (e.g. attribute based masking, based on SAP-internal attributes) can be implemented via BAdI
• Highly performant – minimal system requirements
1. Define fields to be masked, and rules 2. Register authorized users per field
• Define which field are masked. • In transaction PFCG, assign users to the UI Masking
• Configure on field level how a field is displayed. Define authorization a role.
on digit base whether and how data are masked. • Users assigned to these roles will be able to see
unmasked values for the applicable fields
• BAdIs available to introduce customized business logic
determining who has access
2. Automatic
alert
transaction: PA30
“Maintain HR Data”
Infotype 8
“Basic Pay”
No Transfer to ETD
Temp. Log
Ext. Repository
ETD System
T +49 6227-7-74995
E [email protected]
http://www.sap.com/innovbizsolutions
© 2018 SAP SE or an SAP affiliate company. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company.
The information contained herein may be changed without prior notice. Some software products marketed by SAP SE and its distributors contain proprietary software components
of other software vendors. National product specifications may vary.
These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP or its affiliated
companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP or SAP affiliate company products and services are those that are
set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty.
In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this docume nt or any related presentation, or to develop or release
any functionality mentioned therein. This document, or any related presentation, and SAP SE’s or its affiliated companies’ strategy and possible future developments, products,
and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The
information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forward-looking statements are subject to various
risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements,
and they should not be relied upon in making purchasing decisions.
SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trade marks of SAP SE (or an SAP affiliate company)
in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companie s.
See http://global.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices.