The document discusses various guidelines for assessing security in SAP systems. It describes the EAS-SEC standard developed by ERPScan, which includes 33 critical checks across 9 areas. This is proposed as a first step for rapid security assessments. The document also mentions other guidelines from SAP, ISACA, and DSAG that can be used for more comprehensive assessments. It highlights some limitations of existing guidelines and the need to develop standards that cover all applications and aspects of security, including source code reviews. The author proposes expanding the EAS-SEC framework to address these gaps.