{"id":9065,"date":"2020-03-23T23:27:58","date_gmt":"2020-03-23T22:27:58","guid":{"rendered":"https:\/\/139-162-136-174.ip.linodeusercontent.com\/?page_id=9065"},"modified":"2020-04-21T17:09:39","modified_gmt":"2020-04-21T15:09:39","slug":"sap-cybersecurity-self-assessment-tool-level-4-results","status":"publish","type":"page","link":"https:\/\/www.bowbridge.net\/en\/sap-cybersecurity-self-assessment-tool-level-4-results\/","title":{"rendered":"Level 4: For Gurus Only"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text]<\/p>\n<h3 class=\"question-text\">1. How long do most companies take to detect a data breach, even a major one?<\/h3>\n<h4>Best Answer: d.<\/h4>\n<h4 class=\"answer-text\">6 months<\/h4>\n<p>Equifax, Capital One and Facebook are just a few of the companies who were hacked in recent years and didn\u2019t discover the intrusion for at least six months. According to the Ponemon\u00a0<a href=\"https:\/\/www.ibm.com\/security\/data-breach\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">2017 Cost of a Data Breach Study<\/a>, <strong>US companies take an average of 206 days to detect a data breach<\/strong>.[\/vc_column_text]<div class=\"qodef-separator-holder clearfix  qodef-separator-center\">\r\n\t<div class=\"qodef-separator\" style=\"border-color: #cccccc;border-width: 1pxpx;margin-bottom: 50px\"><\/div>\r\n<\/div>\r\n[\/vc_column][\/vc_row][vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text]<\/p>\n<h3 class=\"question-text\">2. Who can access the configuration port of the SAP Message Server and potentially register a rogue application server and bypass SAP Gateway Access Control Lists?<\/h3>\n<h4>Best Answer: b.<\/h4>\n<h4 class=\"answer-text\">Everybody, ms\/acl_file_admin does not exist by default.<\/h4>\n<p>By default, the profile parameters ms\/acl_file_admin, ms\/acl_file_ext, ms\/acl_file_int are not specified. Following a secure white list approach, this would mean nobody is allowed access.<\/p>\n<p>However, in absence of these files, ANYBODY can access the relevant ports of a SAP message server. Attackers can register a rogue application server. Because that server will be considered \u201ctrusted,\u201d the attacker may bypass any Access Control implemented in the SAPGW.[\/vc_column_text]<div class=\"qodef-separator-holder clearfix  qodef-separator-center\">\r\n\t<div class=\"qodef-separator\" style=\"border-color: #cccccc;border-width: 1pxpx;margin-bottom: 50px\"><\/div>\r\n<\/div>\r\n[\/vc_column][\/vc_row][vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text]<\/p>\n<h3 class=\"question-text\">3. What should be considered the single most critical component of an SAP installation?<\/h3>\n<h4>Best Answer: c.<\/h4>\n<h4 class=\"answer-text\">The Solution Manager<\/h4>\n<p>It has a trust relationship with ALL connected systems. Hence, if the SAP Solution Manager is compromised, ALL connected systems can be accessed by an attacker.[\/vc_column_text][vc_empty_space height=&#8221;40px&#8221;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text]<\/p>\n<h3 class=\"question-text\">4. True or False: SAP passwords are not stored in the database. Instead, only hashes are stored in the USR02, USH02 and USRPWDHISTORY tables. This means they are safe.<\/h3>\n<h4>Best Answer: b.<\/h4>\n<h4 class=\"answer-text\">False<\/h4>\n<p>Common hacking tools like JTR\u2019s Hashcat have been supporting SAP Hashes for some time now. Although time-consuming, passwords can be cracked using either a dictionary or brute force.<\/p>\n<p>Companies should enforce strong-password policies and disallow the use of common passwords in table USR04.[\/vc_column_text][vc_empty_space height=&#8221;40px&#8221;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text]<\/p>\n<h2>How Did You Do?<\/h2>\n<p>After performing the self-assessment, do you feel confident about your organization\u2019s ability to keep your SAP systems secure from cyberattack? Or did you uncover some areas in which you could be doing better?<\/p>\n<p>Download our helpful SAP cybersecurity checklist, which will help you clearly assess your SAP system and your cybersecurity processes, putting you on the road to stronger SAP cybersecurity.[\/vc_column_text][vc_empty_space height=&#8221;30px&#8221;][\/vc_column][\/vc_row][vc_row content_aligment=&#8221;center&#8221; css=&#8221;.vc_custom_1585229913601{margin-top: 30px !important;}&#8221;][vc_column width=&#8221;1\/4&#8243; css=&#8221;.vc_custom_1585230054135{padding-top: 0px !important;padding-right: 30px !important;padding-bottom: 30px !important;padding-left: 30px !important;}&#8221;][vc_single_image image=&#8221;9094&#8243; img_size=&#8221;&#8221; add_caption=&#8221;yes&#8221; alignment=&#8221;center&#8221; style=&#8221;vc_box_shadow&#8221;][\/vc_column][vc_column width=&#8221;1\/2&#8243; css=&#8221;.vc_custom_1585229937976{padding-top: 30px !important;padding-right: 30px !important;padding-bottom: 30px !important;padding-left: 30px !important;background-color: #f4f4f4 !important;}&#8221;][vc_raw_html]JTNDJTIxLS0lNUJpZiUyMGx0ZSUyMElFJTIwOCU1RCUzRSUwQSUzQ3NjcmlwdCUyMGNoYXJzZXQlM0QlMjJ1dGYtOCUyMiUyMHR5cGUlM0QlMjJ0ZXh0JTJGamF2YXNjcmlwdCUyMiUyMHNyYyUzRCUyMiUyRiUyRmpzLmhzZm9ybXMubmV0JTJGZm9ybXMlMkZ2Mi1sZWdhY3kuanMlMjIlM0UlM0MlMkZzY3JpcHQlM0UlMEElM0MlMjElNUJlbmRpZiU1RC0tJTNFJTBBJTNDc2NyaXB0JTIwY2hhcnNldCUzRCUyMnV0Zi04JTIyJTIwdHlwZSUzRCUyMnRleHQlMkZqYXZhc2NyaXB0JTIyJTIwc3JjJTNEJTIyJTJGJTJGanMuaHNmb3Jtcy5uZXQlMkZmb3JtcyUyRnYyLmpzJTIyJTNFJTNDJTJGc2NyaXB0JTNFJTBBJTNDc2NyaXB0JTNFJTBBJTIwJTIwaGJzcHQuZm9ybXMuY3JlYXRlJTI4JTdCJTBBJTA5cG9ydGFsSWQlM0ElMjAlMjIyNzczMzM5JTIyJTJDJTBBJTA5Zm9ybUlkJTNBJTIwJTIyMTZhM2U3ZjktZjY5OC00ZGQwLTkwNzUtMzhmM2Y1NzVhMGUyJTIyJTBBJTdEJTI5JTNCJTBBJTNDJTJGc2NyaXB0JTNF[\/vc_raw_html][\/vc_column][vc_column width=&#8221;1\/4&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_empty_space height=&#8221;40px&#8221;][vc_column_text]At bowbridge, we\u2019re here to help. We\u2019ve helped organizations worldwide (like Honda, IBM, KPMG, the Australian Government, LEGO, and so many more) secure their SAP system from today\u2019s \u2014 and tomorrow\u2019s \u2014 sophisticated cyberattacks.<\/p>\n<p><a href=\"https:\/\/139-162-136-174.ip.linodeusercontent.com\/en\/contact-bowbridge\/\">Contact us today<\/a> for a free consultation, and ensure your SAP system is safe, secure, and out of the reach of cyberattackers.[\/vc_column_text][vc_empty_space height=&#8221;100px&#8221;][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row css_animation=&#8221;qodef-element-from-fade&#8221;][vc_column][vc_column_text] 1. How long do most companies take to detect a data breach, even a major one? Best Answer: d&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"content-type":"","footnotes":""},"class_list":["post-9065","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/pages\/9065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/comments?post=9065"}],"version-history":[{"count":17,"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/pages\/9065\/revisions"}],"predecessor-version":[{"id":9244,"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/pages\/9065\/revisions\/9244"}],"wp:attachment":[{"href":"https:\/\/www.bowbridge.net\/en\/wp-json\/wp\/v2\/media?parent=9065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}