Q&A

The ERP Security Challenge

In a rare interview, SAP’s Sachar Paulus talks about how the ERP software giant secures the software that may very well be your business’s backbone.

By Katherine Walsh

January 08, 2008CSO — Until June, Paulus was CSO, responsible for IT, physical and organizational security at the $12 billion German company known for its enterprise resource planning (ERP) software. Now, he’s SVP of product and security governance, and as such is responsible for security strategy for all products. New threats, increasing complexity and emerging regulations have increased the importance of security on all fronts. Despite the high stakes, though, Paulus is not in the spotlight in the United States and does few interviews. CSO’s Katherine Walsh recently talked with him about SAP’s security strategy, global compliance issues, and how he stays on top of it all.

CSO: What is the current state of IT security in businesses and organizations?

Sachar Paulus: The weakest link is still people. As good as IT measures and technologies can be, the biggest problems occur wherever technology comes into contact with people who need to administer, manage or even use IT security functionality. One of the best examples is related to protecting confidential information over the Internet using e-mail encryption. Existing tools are still too cumbersome for people to actually use it the right way. Many people use encryption but then send the password for the encryption in the same e-mail, so what’s the use?

CSO: Can you elaborate on how the security function at SAP has transformed, and how it continues to evolve?

Paulus: From a corporate standpoint there are two things happening at SAP: One is to extend the use of IT security competencies into other areas of the business. IT security is moving away from being mainly driven by the IT organization where the availability of the network and the information were top priorities in terms of security. Now, largely due to compliance requirements like Sarbanes-Oxley, integrity of information and confidentiality is more relevant and important. The CFO is looking into these types of activities, and in most cases he is the one responsible for managing the compliance activities of the organization.

From a product perspective, security is a little more difficult. Years ago at SAP we had ways of managing complex authorizations for complex business systems. That’s something that requires additional expertise beyond the ERP system itself. There were few companies under the IT security label with that kind of expertise, but there was no big demand for it. But now with Sarbanes Oxley, there is more demand to prevent critical combinations of authorization for the same peop

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

The Case for Business Software Assurance ~ Securing Your Applications

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

Digital Identity Protection and Data Security Get Personal

Solving Online Credit Fraud Using Device Reputation

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage