SlideShare a Scribd company logo
1 of 3
Download to read offline
Hovitaga OpenSQL Editor
                                                       Security and Authorization concept

Introduction
  The most frequently asked questions about the purchase of an SAP add-on are
about security. What are the risks of installing the add-on? Does my business-critical
data become available for unauthorized access? What are the chances of downtime of
productive systems due to the malfunctioning of the add-on?

  Based on our experience we have designed the OpenSQL Editor with these
questions in mind. Our products use the standard SAP authorization framework to
protect the system against unauthorized access.

Overview of the OpenSQL Editor
  The OpenSQL Editor is a powerful tool that helps SAP consultants, ABAP developers
and basis administrators to work with the database of an SAP system. It provides an
intuitive way to build ad-hoc reports and statistics with simple OpenSQL commands.
No further ABAP programming is required.

  The OpenSQL Editor uses multiple authority objects provided by SAP and used
by most of the customers worldwide. This means that if those authority objects are
already configured in an SAP system, no additional effort is required. Additionally any
number of authorization objects can be assigned to database tables, so every query
will check if the user has the necessary authorizations to work with the required data.

  All the row and column level authorization checks are integrated to the queries
sent to the database server to avoid retrieving unnecessary data and to minimize
network traffic.
Authorization concept                                                                      salary field in a table, others could not, depending on the authorizations.

Record level authorizations                                                                  There is an authority object that controls what columns may a user access in a
                                                                                           database table. This can be maintained with the standard SAP tools without any special
  While the tools mostly used by consultants and developers (SE16 and SAP Query)           customizing effort.
only use table group level authorizations to filter query results, the OpenSQL Editor
can be controlled in a much more sophisticated way. This means that besides defining       Table group level authorizations
which tables can be read, you can control which records can be read from a table. A
generic standard SAP authority object (S_TABU_LIN) is used to filter the query results       The OpenSQL Editor also uses the SAP standard authority objects S_TABU_DIS to
based on any organizational criteria defined in customizing. For example a scenario        control access to table groups and S_TABU_CLI to control maintenance of client-
can be set up easily where certain users only see data for their company code (or          independent tables.
country or any organizational level).

  This row level authorization concept is part of every SAP system and can be
                                                                                           Requirements and installation
maintained within customizing (SPRO). If it has been already set up, then the OpenSQL
                                                                                             The OpenSQL Editor is entirely written in ABAP, so it is transparent (not a black-box
Editor will filter all queries accordingly.
                                                                                           development) and deeply integrated into the SAP system. No interfaces needed, no
                                                                                           platform-dependency, no separate IT team to maintain. It does not expose the SAP
  Additionally any number of authority objects can be assigned to tables within a
                                                                                           system to any access from outside.
the OpenSQL Editor customizing transaction. A field mapping between the authority
object and the table must be made that the OpenSQL Editor uses when filtering query
                                                                                             Installation is a process of few minutes, since it only consists of importing one
results.
                                                                                           transport with the TMS (Transport Management System). The only additional effort
                                                                                           is to set up the authorizations for the users. Due to the intuitive user interface and
  For example to filter entries in the VBAK table (Order headers) by sales organization
                                                                                           extensive documentation no consulting or implementation project is needed.
simply assign authority object V_VBAK_VK0 to the table. To filter entries by plant in
table MARC (Plant data), assign authority object M_MATE_WRK to table MARC. If these
                                                                                             Hovitaga OpenSQL Editor runs on SAP 4.6C but some features require SAP Netweaver
authority objects were already used in the SAP system, then the roles, profiles etc. do
                                                                                           7.00 (aka. 2004s) or above.
not need to be changed, no other user maintenance effort is required.

Field level authorizations

  Additionally to the record level authorization concept the OpenSQL Editor can be
controlled on field level also. For example, certain users could see the contents of the
Support and maintenance
  We provide two levels of support. Standard support makes our customers eligible
to receive regular support packages that contain all corrections and improvements.
Customers who choose the premium support will receive every enhancement or
correction immediately without having to wait for the new support package to
be released. The OpenSQL Editor can be purchased without any support also, if
required.

 Conclusion
  Time is money. People involved in SAP development and implementation
projects as well as business users spend a lot of time on inefficient and repetitive
tasks that occur daily during their work. The OpenSQL Editor makes many of these
tasks just a matter of minutes opposed to hours, sparing much time for its users. Let
them spend it on your business instead.




                                To learn more about Hovitaga OpenSQL Editor, visit www.hovitaga.com or send a mail to info@hovitaga.com.
                                              Detailed whitepapers and video demonstrations are available on our website.

                                                       © Copyright Hovitaga Kft. 2009. All rights reserved. SAP is a registered trademark of SAP AG.
                                                                  All other trademarks are the property of their respective owners.

More Related Content

What's hot

SNAPS_DataSheet_BIVoyage
SNAPS_DataSheet_BIVoyageSNAPS_DataSheet_BIVoyage
SNAPS_DataSheet_BIVoyage
sidhartha43
 

What's hot (20)

SAP HANA SPS09- Administration Monitoring
SAP HANA SPS09- Administration MonitoringSAP HANA SPS09- Administration Monitoring
SAP HANA SPS09- Administration Monitoring
 
What's New in SAP HANA SPS 11 DB Control Center (Operations)
What's New in SAP HANA SPS 11 DB Control Center (Operations)What's New in SAP HANA SPS 11 DB Control Center (Operations)
What's New in SAP HANA SPS 11 DB Control Center (Operations)
 
SAP HANA SPS09 - SAP HANA Workload Management
SAP HANA SPS09 - SAP HANA Workload ManagementSAP HANA SPS09 - SAP HANA Workload Management
SAP HANA SPS09 - SAP HANA Workload Management
 
What's New in SAP HANA SPS 11 Operations
What's New in SAP HANA SPS 11 OperationsWhat's New in SAP HANA SPS 11 Operations
What's New in SAP HANA SPS 11 Operations
 
What's new in SAP HANA SPS 11 SQL/SQLScript
What's new in SAP HANA SPS 11 SQL/SQLScriptWhat's new in SAP HANA SPS 11 SQL/SQLScript
What's new in SAP HANA SPS 11 SQL/SQLScript
 
What's New in SAP HANA SPS 11 Platform Lifecycle Management (Operations)
What's New in SAP HANA SPS 11 Platform Lifecycle Management (Operations)What's New in SAP HANA SPS 11 Platform Lifecycle Management (Operations)
What's New in SAP HANA SPS 11 Platform Lifecycle Management (Operations)
 
SNAPS_DataSheet_BIVoyage
SNAPS_DataSheet_BIVoyageSNAPS_DataSheet_BIVoyage
SNAPS_DataSheet_BIVoyage
 
Whats New on SAP HANA SPS 11 Core Database Capabilities
Whats New on SAP HANA SPS 11 Core Database CapabilitiesWhats New on SAP HANA SPS 11 Core Database Capabilities
Whats New on SAP HANA SPS 11 Core Database Capabilities
 
SAP HANA SPS08 Administration & Monitoring
SAP HANA SPS08 Administration & MonitoringSAP HANA SPS08 Administration & Monitoring
SAP HANA SPS08 Administration & Monitoring
 
What's New in SAP HANA SPS 11 Predictive
What's New in SAP HANA SPS 11 PredictiveWhat's New in SAP HANA SPS 11 Predictive
What's New in SAP HANA SPS 11 Predictive
 
How Do You Innovate In a Complex Work? Read How SAP and Intel Can Help
How Do You Innovate In a Complex Work? Read How SAP and Intel Can HelpHow Do You Innovate In a Complex Work? Read How SAP and Intel Can Help
How Do You Innovate In a Complex Work? Read How SAP and Intel Can Help
 
Technical Overview of CDS View – SAP HANA Part I
Technical Overview of CDS View – SAP HANA Part ITechnical Overview of CDS View – SAP HANA Part I
Technical Overview of CDS View – SAP HANA Part I
 
Hana e2 e_adminmonitoring_sps08
Hana e2 e_adminmonitoring_sps08Hana e2 e_adminmonitoring_sps08
Hana e2 e_adminmonitoring_sps08
 
SAP HANA SPS10- SAP HANA Remote Data Sync
SAP HANA SPS10- SAP HANA Remote Data SyncSAP HANA SPS10- SAP HANA Remote Data Sync
SAP HANA SPS10- SAP HANA Remote Data Sync
 
SAP HANA SPS10- SAP HANA Dynamic Tiering
SAP HANA SPS10- SAP HANA Dynamic TieringSAP HANA SPS10- SAP HANA Dynamic Tiering
SAP HANA SPS10- SAP HANA Dynamic Tiering
 
SAP HANA for SAP Overview
SAP HANA for SAP OverviewSAP HANA for SAP Overview
SAP HANA for SAP Overview
 
What's new for SAP HANA SPS 11 Dynamic Tiering
What's new for SAP HANA SPS 11 Dynamic TieringWhat's new for SAP HANA SPS 11 Dynamic Tiering
What's new for SAP HANA SPS 11 Dynamic Tiering
 
Taking it all offline with SQL Anywhere
Taking it all offline with SQL AnywhereTaking it all offline with SQL Anywhere
Taking it all offline with SQL Anywhere
 
SAP HANA SPS09 - XS Programming Model
SAP HANA SPS09 - XS Programming ModelSAP HANA SPS09 - XS Programming Model
SAP HANA SPS09 - XS Programming Model
 
Consuming Data With HANA XS
Consuming Data With HANA XSConsuming Data With HANA XS
Consuming Data With HANA XS
 

Viewers also liked (8)

Crear una wiki(paso a paso)
Crear una wiki(paso a paso)Crear una wiki(paso a paso)
Crear una wiki(paso a paso)
 
How to give a powerful presentation
How to give a powerful presentationHow to give a powerful presentation
How to give a powerful presentation
 
Negative list 01 - taxtube.blogspot.in
Negative list 01 - taxtube.blogspot.inNegative list 01 - taxtube.blogspot.in
Negative list 01 - taxtube.blogspot.in
 
Fruits and vegetables
Fruits and vegetablesFruits and vegetables
Fruits and vegetables
 
About me
About meAbout me
About me
 
Hovitaga authorization concept and setup guide
Hovitaga authorization concept and setup guideHovitaga authorization concept and setup guide
Hovitaga authorization concept and setup guide
 
Negative list 02 - taxtube.blogspot.in
Negative list 02 - taxtube.blogspot.inNegative list 02 - taxtube.blogspot.in
Negative list 02 - taxtube.blogspot.in
 
A fábula do holocausto Arthur R. Butz
A fábula do holocausto  Arthur R. ButzA fábula do holocausto  Arthur R. Butz
A fábula do holocausto Arthur R. Butz
 

Similar to Hovitaga OpenSQL Editor - Security and authorization concept

W2 k3 ad_integration-how_to
W2 k3 ad_integration-how_toW2 k3 ad_integration-how_to
W2 k3 ad_integration-how_to
Meka SriHari
 
1 extreme performance - part i
1   extreme performance - part i1   extreme performance - part i
1 extreme performance - part i
sqlserver.co.il
 
Oracle and its related technologies
Oracle and its related technologiesOracle and its related technologies
Oracle and its related technologies
anup4704
 
AnalysisServices
AnalysisServicesAnalysisServices
AnalysisServices
webuploader
 

Similar to Hovitaga OpenSQL Editor - Security and authorization concept (20)

Hovitaga OpenSQL Editor - Product flyer
Hovitaga OpenSQL Editor - Product flyerHovitaga OpenSQL Editor - Product flyer
Hovitaga OpenSQL Editor - Product flyer
 
Hovitaga OpenSQL Editor - Overview
Hovitaga OpenSQL Editor - OverviewHovitaga OpenSQL Editor - Overview
Hovitaga OpenSQL Editor - Overview
 
Hovitaga Data Visualizer - Overview
Hovitaga Data Visualizer - OverviewHovitaga Data Visualizer - Overview
Hovitaga Data Visualizer - Overview
 
Java workflow engines
Java workflow enginesJava workflow engines
Java workflow engines
 
End to-end root cause analysis minimize the time to incident resolution
End to-end root cause analysis minimize the time to incident resolutionEnd to-end root cause analysis minimize the time to incident resolution
End to-end root cause analysis minimize the time to incident resolution
 
W2 k3 ad_integration-how_to
W2 k3 ad_integration-how_toW2 k3 ad_integration-how_to
W2 k3 ad_integration-how_to
 
Pulkit Sachdeva-Resume
Pulkit Sachdeva-ResumePulkit Sachdeva-Resume
Pulkit Sachdeva-Resume
 
1 extreme performance - part i
1   extreme performance - part i1   extreme performance - part i
1 extreme performance - part i
 
Patrick_Rebrook_Resume
Patrick_Rebrook_ResumePatrick_Rebrook_Resume
Patrick_Rebrook_Resume
 
SAP performance testing & engineering courseware v01
SAP performance testing & engineering courseware v01SAP performance testing & engineering courseware v01
SAP performance testing & engineering courseware v01
 
SAP ARCHITECTURE (I).pptx
SAP ARCHITECTURE (I).pptxSAP ARCHITECTURE (I).pptx
SAP ARCHITECTURE (I).pptx
 
Novidades do SQL Server 2016
Novidades do SQL Server 2016Novidades do SQL Server 2016
Novidades do SQL Server 2016
 
Sap Interview Questions - Part 1
Sap Interview Questions - Part 1Sap Interview Questions - Part 1
Sap Interview Questions - Part 1
 
Azure for SharePoint Developers - Workshop - Part 3: Web Services
Azure for SharePoint Developers - Workshop - Part 3: Web ServicesAzure for SharePoint Developers - Workshop - Part 3: Web Services
Azure for SharePoint Developers - Workshop - Part 3: Web Services
 
Business Intelligence for users - Sharperlight
Business Intelligence for users - SharperlightBusiness Intelligence for users - Sharperlight
Business Intelligence for users - Sharperlight
 
Oracle and its related technologies
Oracle and its related technologiesOracle and its related technologies
Oracle and its related technologies
 
Oracle and its related technologies
Oracle and its related technologiesOracle and its related technologies
Oracle and its related technologies
 
Business Intelligence Software Tools
Business Intelligence Software ToolsBusiness Intelligence Software Tools
Business Intelligence Software Tools
 
AnalysisServices
AnalysisServicesAnalysisServices
AnalysisServices
 
Ebook11
Ebook11Ebook11
Ebook11
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Recently uploaded (20)

Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

Hovitaga OpenSQL Editor - Security and authorization concept

  • 1. Hovitaga OpenSQL Editor Security and Authorization concept Introduction The most frequently asked questions about the purchase of an SAP add-on are about security. What are the risks of installing the add-on? Does my business-critical data become available for unauthorized access? What are the chances of downtime of productive systems due to the malfunctioning of the add-on? Based on our experience we have designed the OpenSQL Editor with these questions in mind. Our products use the standard SAP authorization framework to protect the system against unauthorized access. Overview of the OpenSQL Editor The OpenSQL Editor is a powerful tool that helps SAP consultants, ABAP developers and basis administrators to work with the database of an SAP system. It provides an intuitive way to build ad-hoc reports and statistics with simple OpenSQL commands. No further ABAP programming is required. The OpenSQL Editor uses multiple authority objects provided by SAP and used by most of the customers worldwide. This means that if those authority objects are already configured in an SAP system, no additional effort is required. Additionally any number of authorization objects can be assigned to database tables, so every query will check if the user has the necessary authorizations to work with the required data. All the row and column level authorization checks are integrated to the queries sent to the database server to avoid retrieving unnecessary data and to minimize network traffic.
  • 2. Authorization concept salary field in a table, others could not, depending on the authorizations. Record level authorizations There is an authority object that controls what columns may a user access in a database table. This can be maintained with the standard SAP tools without any special While the tools mostly used by consultants and developers (SE16 and SAP Query) customizing effort. only use table group level authorizations to filter query results, the OpenSQL Editor can be controlled in a much more sophisticated way. This means that besides defining Table group level authorizations which tables can be read, you can control which records can be read from a table. A generic standard SAP authority object (S_TABU_LIN) is used to filter the query results The OpenSQL Editor also uses the SAP standard authority objects S_TABU_DIS to based on any organizational criteria defined in customizing. For example a scenario control access to table groups and S_TABU_CLI to control maintenance of client- can be set up easily where certain users only see data for their company code (or independent tables. country or any organizational level). This row level authorization concept is part of every SAP system and can be Requirements and installation maintained within customizing (SPRO). If it has been already set up, then the OpenSQL The OpenSQL Editor is entirely written in ABAP, so it is transparent (not a black-box Editor will filter all queries accordingly. development) and deeply integrated into the SAP system. No interfaces needed, no platform-dependency, no separate IT team to maintain. It does not expose the SAP Additionally any number of authority objects can be assigned to tables within a system to any access from outside. the OpenSQL Editor customizing transaction. A field mapping between the authority object and the table must be made that the OpenSQL Editor uses when filtering query Installation is a process of few minutes, since it only consists of importing one results. transport with the TMS (Transport Management System). The only additional effort is to set up the authorizations for the users. Due to the intuitive user interface and For example to filter entries in the VBAK table (Order headers) by sales organization extensive documentation no consulting or implementation project is needed. simply assign authority object V_VBAK_VK0 to the table. To filter entries by plant in table MARC (Plant data), assign authority object M_MATE_WRK to table MARC. If these Hovitaga OpenSQL Editor runs on SAP 4.6C but some features require SAP Netweaver authority objects were already used in the SAP system, then the roles, profiles etc. do 7.00 (aka. 2004s) or above. not need to be changed, no other user maintenance effort is required. Field level authorizations Additionally to the record level authorization concept the OpenSQL Editor can be controlled on field level also. For example, certain users could see the contents of the
  • 3. Support and maintenance We provide two levels of support. Standard support makes our customers eligible to receive regular support packages that contain all corrections and improvements. Customers who choose the premium support will receive every enhancement or correction immediately without having to wait for the new support package to be released. The OpenSQL Editor can be purchased without any support also, if required. Conclusion Time is money. People involved in SAP development and implementation projects as well as business users spend a lot of time on inefficient and repetitive tasks that occur daily during their work. The OpenSQL Editor makes many of these tasks just a matter of minutes opposed to hours, sparing much time for its users. Let them spend it on your business instead. To learn more about Hovitaga OpenSQL Editor, visit www.hovitaga.com or send a mail to info@hovitaga.com. Detailed whitepapers and video demonstrations are available on our website. © Copyright Hovitaga Kft. 2009. All rights reserved. SAP is a registered trademark of SAP AG. All other trademarks are the property of their respective owners.