Putting Out Fires: Ensuring Privileged Access Management With SAP Firefighter
Key Takeaways
⇨ Overuse of Firefighter (FF) identities for non-critical transactions is a major issue, increasing log volumes and complicating FF management, which can be mitigated by redesigning roles to include realistic risk thresholds and essential everyday tasks.
⇨ Establishing clear workflows and documentation is essential to maintain process efficiency, reduce false positives/negatives, and provide sufficient context for log approvals, thereby streamlining the emergency access process.
⇨ Automation of low-risk transactions in FF management can help reduce workloads, but must be complemented with regular spot-checks and clear guidelines to ensure high-risk transactions are properly vetted.
Despite Firefighter’s benefits (management of privileged access, streamlined emergency access management, increased audit compliance, etc.), SAP security teams are finding it increasingly difficult to manage the process. The rise in the use of the FF functionality is causing organisations to see a huge spike in their FF log volume, with this resulting in an accumulation of unchecked records that spans weeks, or even months.