HR Data Security

Question: We are trying to determine whether or not to place HR on a separate server. One of the main reasons why we would want HR on a separate server is for security reasons.

However, I do not understand how having HR on a separate server is any more secure than having it on the same server. You would only be adding an application server that the HR users would use for load balancing and they would have their own resources. However, all of the HR data will still physically reside on the database instance with the rest of the SAP data. And you would still need to set security at the authorizations level whether or not HR is on a separate server or not.

Or am I mistaken?

Thanks.

Avi

Answer:
Correct.

You would need to use security irespective of the server. THis is a design error in SAP, to the benefit of a secure and performant feeling, but at the expense of security.

Tarr

Answer:
The major reason for putting HR in a separate server is NOT security but upgrade requirements. THe chages to meet the HR requirments happen faster than normal SAP and upgrades are required more frequently. Many companies choose to put HR on a separate system for this reason. It is no more secure and opens HR to many back doors that are not present in an all in one system.

You can secure HR in any system, combined or separate, and there are advantages to having it all in one system ( like security by position) without the ALE updates having to be configured and run. Two systems do not equate to twice the work but close.

Keep it all in one system, you will be farther ahead and FAR less costly.

Answer:

You would only be adding an application server that the HR users would use for load balancing and they would have their own resources. However, all of the HR data will still physically reside on the database instance with the rest of the SAP data.


No, you don't gain anything with this setup. If you want to improve security you have to install a separate HR system, not just an additional application server. Actually, you have to install a separate HR system landscape including HR development and test systems.

No comments:

topics