El panorama de la seguridad de los datos y la información está cambiando más rápidamente que nunca. Los conocimientos sobre piratería informática están aumentando, al igual que la velocidad de comercialización y adopción de nuevas tecnologías. Esto, junto con el aumento de las leyes destinadas a proteger a los propietarios de datos, supone un gran reto para las empresas.

EPI-USE Labs puede ayudarle a navegar por este complejo  campo con una suite de soluciones que abarcan el riesgo, la seguridad, la privacidad y la conformidad de los datos. Para ofrecer a nuestros clientes la máxima protección, nos hemos asociado con Soterion, cuyo software de cumplimiento de normativas resuelve los problemas de GRC (Governance, Risk management y Compliance) para clientes SAP.

Play video
We see every day the news coming out in the press that there are hacking leaks throughout the world. A lot of big suppliers are working for us. They all have access to the test systems. Now when we copy the data, we're bound to protect their personal and sensitive information. For the first time, we now see our real risk exposure, which was even higher than what we anticipated. Compliance was no longer optional. The biggest challenge was that it had gotten really complicated over the years. The complexity of the implementation of GDPR is not only about anonymizing the system, but also archiving a lot of data. We have been doing that quite manually, but at some point, we couldn't make the next step. There's no way we can fix it. We had a very good conversation with EPI-USE Labs, and all the boxes were ticked. Without Soterion, we would have been running blind. And we now have it connected to each of our SAP systems, and we're literally using it on a daily basis. It was really important to have this kind of solution implemented for us. And, of course, it was implemented according to what the regulator was asking us. What we liked is the fact that you could scramble as you extracted the data. Even when we got the extracted files, there is no data in there that someone could have a look at. We work closely with our internal and external auditors, and they're quite happy with what we have done so far. With EPI-USE Labs products, I found it really useful that they're pre-empting my problems. It's really good to work with a supplier that understands the new legislation and is already there with a product.

 ¿Cuáles son sus desafíos en cuanto a la privacidad y seguridad de su datos SAP?

Mejorar el cumplimiento de la privacidad de los datos SAP

Mejorar el cumplimiento de la privacidad de los datos SAP

El objetivo de cualquier proyecto de privacidad es aumentar el cumplimiento de las leyes de privacidad de datos exigidas dentro de la jurisdicción de la empresa. La estructura de SAP hace que abordar dicho cumplimiento sea especialmente complicado. Una de las razones más convincentes para la conformidad en cuanto a la privacidad de los datos son las multas coercitivas; las nuevas leyes prevén la aplicación de elevadas sanciones económicas por parte de los organismos legales.

Llevamos más de 20 años realizando proyectos de privacidad en todo el mundo, en distintos sectores, y hemos identificado los pasos esenciales en el planteamiento de un proyecto común:

  • Identifique sus riesgos: Evaluación de impacto y riesgo
  • Encuentre y localice su PII
  • Revisión de los riesgos y controles de acceso
  • Limpiar el retraso en producción
  • Gestión de la PII en copias de producción
  • Gestión de las solicitudes de acceso del sujeto a los datos (DSAR)
  • Tramitar las solicitudes individuales de supresión
  • Identificación proactiva delas partes interesadas
  • Auditoría y revisión continuas
Responder al Derecho de Acceso/Supresión

Responder al Derecho de Acceso/Supresión en sistemas de Producción

Tanto si se adhiere a la PDPA en Tailandia, a una de las leyes estatales en Estados Unidos o al RGPD en Europa, está obligado a responder al Derecho de Acceso y Supresión de datos personales en su entorno.


El derecho a la supresión no anula ninguno de sus otros requisitos legales y de cumplimiento, como la conservación de registros para auditorías fiscales. Ahora se debe encontrar la manera de validar si los datos son necesarios por cualquier otra razón legal y, si no es así, eliminar los datos confidenciales de su sistema.


SAP plantea un reto para la eliminación de datos: al tratarse de una base de datos relacional, los datos sensibles están intrínsecamente ligados a las transacciones comerciales. Por tanto, los métodos tradicionales de archivo o eliminación implican la necesidad de eliminar por completo las transacciones y los datos maestros.


EPI-USE Labs ofrece una alternativa con Data Redact,  que elimina la PII de los registros pero mantiene la integridad referencial de la solución. Y Data Disclose proporciona una asignación eficaz de la IIP en un archivo PDF, lo que permite un proceso eficiente para responder al Derecho de Acceso

Codificar datos en sistemas de no producción

Codificar datos en sistemas de no producción

Todas las empresas necesitan probar sus procesos, ya se trate de las actualizaciones anuales de la fiscalidad de las nóminas, de la actualización de paquetes de servicios o de nuevas personalizaciones. Nadie descubrir que tiene un problema con los nuevos procesos en Producción, por lo que la mayoría de las empresas tomarán una copia de sus sistemas de producción y crearán entornos de prueba.

El número de entornos de prueba varía en función de la empresa, pero una configuración típica constaría de:

  • Desarrollo con datos reales limitados o inexistentes
  • Calidad: una copia reducida de Producción
  • Preproducción: una copia completa de la base de datos de producción

Las nuevas leyes de privacidad establecen que se debe contar con consentimiento informado y explícito para el uso de los datos relativos a los interesados. Según nuestra experiencia, la mayoría de las empresas no cuentan con el consentimiento para utilizar datos con fines de prueba. Incluso si se dispusiera de un proceso de consentimiento, existe el reto adicional de saber qué hacer en caso de que el interesado no dé su autorización.

Nosotros recomendamos la anonimización de datos con Data Secure, que proporciona anonimización de datos in situ y directa, o la posibilidad de codificar a la salida al vincularse con Client Sync, parte de la suite Data Sync Manager.

Comprender los riesgos de privacidad y seguridad de los datos

Comprender y mitigar sus riesgos de privacidad y seguridad de los datos

Para resolver un problema, primero hay que entenderlo. Tanto en el caso de la privacidad como en el de la seguridad de los datos, hay que comprender los riesgos que entrañan los procesos empresariales y su entorno informático.

Piense en sus procesos empresariales y en los riesgos de seguridad. Por ejemplo, ¿toman notas sus compañeros de secretaría o de RR.HH. durante las llamadas? Si es así, ¿cuál es el proceso de seguridad de esas notas? ¿Se siguen las mejores prácticas de seguridad de datos en toda la empresa?

En cuanto a su entorno informático, las tres principales consideraciones son:

  • Amenaza externa: Seguridad de redes e infraestructuras, como cortafuegos o protección VPN.
  • Amenaza interna: El riesgo de acceso de los datos en la red/ sistema SAP.
  • Riesgo de cumplimiento: ¿Dónde está su IIP y cómo se gestiona?

Nuestro servicio de evaluación de la privacidad de datos SAP proporciona transparencia sobre los riesgos internos y de cumplimiento para su empresa.

 

Impulsar una GRC centrada en la empresa para SAP

Impulsar una GRC centrada en la empresa para SAP

Las soluciones de Gobernanza, Riesgo y Cumplimiento (GRC) tienen en cuenta muchos aspectos del riesgo de acceso. Estamos asociados con Soterion, el cual ofrece un análisis rápido y eficaz de sus riesgos de GRC con un conjunto de reglas estándar para cubrir:

  • Segregación de Funciones (SoD)
  • Privacidad: usuarios accediendo a datos sensibles 
  • Acceso a datos entre jurisdicciones
  • Riesgo crítico de transacción.

Estas soluciones pueden integrarse entre SAP y las aplicaciones en la nube (como SAP SuccessFactors) para proporcionar una visión holística de su riesgo de acceso.

Además, Soterion también le ofrece una evaluación de las licencias de su sistema, los procesos de acceso de emergencia ('firefighter access') y más.

Reducir la "superficie de ataque"

Reducir la "superficie de ataque" de su infraestructura SAP

Para proteger datos confidenciales, considere la posibilidad de reducir «la superficie de ataque» en su entorno SAP, es decir, la topografía de los sistemas y datos que pueden ser atacados. El enmascaramiento u ofuscación de datos puede mantener la integridad referencial y la funcionalidad de los datos de sus sistemas de prueba, formación, sandbox y desarrollo sin hacer identificables a los sujetos de los datos ni dejar expuestos los campos de datos sensibles.

Data Secure, parte de la suite Data Sync Manager (DSM) de EPI-USE Labs, es una solución completa de protección de datos que enmascara los datos SAP para salvaguardar la información confidencial. Permite que los datos funcionen correctamente con cientos de reglas de enmascaramiento prediseñadas. Se pueden crear nuevas reglas desde cero, ampliar las existentes o descargar contenidos de otros usuarios de la comunidad en nuestra plataforma de colaboración, Client Central. El resultado es protección de datos en tiempo real.

Muchas empresas han integrado entornos SAP con datos distribuidos entre ERP, CRM, SRM y entornos externos. Data Secure anonimiza de manera consistente los objetos de datos integrados en diferentes sistemas.

¿Necesitas codificar datos fuera de SAP? Nuestro equipo de desarrollo personalizado puede crear una solución que codifique datos, extendiendo Data Secure a sistemas que no son SAP.

SOFTWARE

Data Privacy Suite para soluciones SAP 

Cumpla con la legislación de privacidad de datos

Nuestra innovadora solución de cumplimiento y privacidad de datos ayuda a las empresas con sistemas SAP® a acatar legislaciones como el RGPD (el Reglamento General de Protección de Datos) y otras normativas sobre confidencialidad de datos.

 

Soterion Access Risk Manager

Obtén una GRC efectiva y centrada en el negocio para SAP.

Con Soterion y EPI-USE Labs, puedes evaluar, actualizar y mantener roles y autorizaciones de manera rentable e intuitiva, cumpliendo con las regulaciones de privacidad de datos.

Play video
Hi. My name is Dudley Cartwright from Soterion. I'd like to spend a few minutes explaining: what is business-centric GRC and why it's so important for effective access risk management in SAP. Access risk is business risk. What is meant by this is that it is a business decision whether a user in the organisation should have certain access. As an example, if a person in your organisation requires access to both create the purchase order and release the purchase order, which is a typical segregation of duty, it should be your business users who decide if that risk is acceptable to the organisation or not. The challenge facing most organisations is that the business users often have very little visibility as to what access is problematic and is causing a risk violation. And if they do have some form of visibility, you often find that the business users don't understand the access risks being presented to them. SAP authorizations is very technical and complex, and most of the GRC solutions on the market have been developed from a technical audit perspective with very little consideration for its use by the business. These technical and complex GRC solutions are not well adopted by the business users, who generally push this responsibility back onto the IT teams. What ends up happening is that the IT teams run these GRC solutions as back-end solutions with minimal involvement from the business. You often find a high degree of underutilization of the GRC solution because of this. At Soterion, we believe that implementing the correct GRC solution is crucial to enhancing business buy-in and accountability. The GRC solution needs to convert the technical GRC language into a language that the business users can understand. Soterion does this by illustrating all access risks with supporting business process flows. This provides more context to the business users who can then make quicker and more informed decisions. The Soterion solution has been developed to empower the business users with their access risk management activities. Enhancing business accountability of access risk with the use of a business-centric GRC solution will enhance your first line of defence, which in turn will improve the organisation's overall risk awareness and your ability to manage your risk. Should you be interested in seeing a more detailed demo covering other use cases, please don't hesitate to contact us.
 

Archive Central

 Restringiendo información específica para el cumplimiento normativo

Archive Central™  es una solución web segura basada en roles que permite a los Oficiales de Privacidad de Datos (DPOs) o usuarios de negocio acceder a datos históricos para consultas, informes y comparaciones. Cifra información sensible, como los datos personales (PII), para garantizar la seguridad y el cumplimiento normativo.

Play video
Whether you're divesting your enterprise or planning to migrate to a new platform or SAP S/4HANA, decommissioning your system presents a unique compliance challenge. How do you store your legacy data cost-effectively and securely? Constant system and database updates make running an SAP display-only system too expensive, and the vast sea of interlinked data tables means you can't simply copy and store the relevant Transactional and Master data separately. There's also the issue of access risk. How do you manage who has access? That's where Archive Central comes in. Archive Central is a role-based secure web solution to get business users access to historical data for Queries and Comparisons while simultaneously ensuring compliance requirements are met. Using proprietary software, we can read, select, and automatically load your SAP data into collections that you can access through a modern web application provided as Software-as-a-Service, allowing you to decommission your SAP system safely, and with the ability to import data from any common machine readable formats such as CSV. Archive Central is capable of archiving data from non-SAP systems as well. Archive Central leverages the metadata to present a business entity for the user with all the related data rather than a set of disparate tables. You'll be able to filter through data easily. Our global search allows you to 'one click and type' to find the records you're looking for. It's also easily configurable, giving you the ability to customise the display to suit your needs. You'll also be able to store all common document formats and image files, so no need to worry about those old payslips, invoices, or certificates. They can be stored and linked with the corresponding data for easy access. You'll be able to track who is viewing data records and what a particular user has done. Don't let your legacy data hold you back. Securely store your legacy data for future Queries and Compliance with Archive Central.

SERVICIOS

 Asesoramiento sobre privacidad de datos

Play video
The first challenge that most businesses face from a privacy point of view is actually understanding how much of the risk they're holding within their data. Most industries have spent, fifteen, twenty years customizing an SAP environment, making it correct for their business process, with no consideration as to how much data they're then proliferating into additional tables. So actually then understanding and mapping that data is quite a large challenge especially because the people that built them have likely retired, moved on, and gone through natural attrition. So it does create quite a large business challenge, and to be able to build your business case for an investment in a privacy solution you first need to know how much risk you are mitigating to be able to follow it through. So to help with that, EPI-USE Labs have utilized our data model mapping that we've been using for the last twenty years to manage SAP data to build a discovery program. Now unlike some of the other competitors on the market, EPI-USE Labs are utilizing SAP domain knowledge that we've built to understand the data dictionary within your system, and we're able to complete a key search of the data elements within that environment based on the list of PII data items that we've already identified. The output list is then validated against whether the data is actually populated because, of course, just because it's in the system doesn't mean you've actually populated it. And we'll then go through a workshop and detailed analysis process with one of our professional services consultants where we will analyze and understand how we can integrate that data back to a data subject for a customer, a vendor or an employee, but also understand what values are maintained and map out that PII challenge for your SAP system. We collect all that information into a single document that has both the business functional requirements from the workshop, as to what retention periods you would like and how data should be affected based on those retention periods - so whether it should be cleared or transformed to a new value, and the same for non-production, for a system copy that you're going to use for testing, you need to have the real data from Production to improve your DevOps process. But you can't have the real data because that is a PII risk, and you would have to have informed and explicit consent from every data subject in your environment to use that data as testing, and no company has entered those clauses into a contract so far to be able to say they're ready. So with that documentation, you have the business requirements of how data should be transformed and then also the technical specification of exactly which tables and fields grouped according to data type to be able to understand where the names, where the telephone numbers, where the bank details exist within the environment. Additionally we now have an enhanced discovery working with one of our strategic partners Soterion. They offer GRC solutions as an alternative to SAP GRC. They have pre-delivered rule sets that are able to analyse your segregation of duties risk. They also have specific rule-sets to review your access to privacy data, to be able to understand who can actually see sensitive data within your SAP system. We also have queries to be able to understand where there's cross legal jurisdictional access. So where somebody from the US is able to access European employee data or vice-versa. Through that analysis, we're able to provide a clear risk assessment of both the access to sensitive data, and where that data is within your environment. Both of these options come as a license free, there is no license cost upfront, there is some professional services cost for around about one and a half to two weeks elapsed time, so in a very short turnaround period we're able to provide you this documentation, which we've seen from some of our clients is being used as audit evidence and passed through to their auditors to be able to help them understand your data model and how you're compliant to the laws. So the data discovery and enhanced data discovery are available from your Account Executives, and we would be happy to discuss them with you. As well as the output of the document, we will also then give you a fixed price, fixed scope implementation cost if you were to choose EPI-USE Labs as your privacy partner to be able to manage that data moving forward.

SAP es uno de los sistemas más robustos del mundo, pero también uno de los más complejos, y su estructura hace que abordar el cumplimiento de la legislación sobre privacidad de datos resulte especialmente complicado. Se requiere un conocimiento detallado del dominio para mapear y comprender la integración interfuncional de múltiples objetos y sistemas SAP.

Como socio de SAP desde hace muchos años, EPI-USE Labs conoce en profundidad cómo se estructuran los datos de SAP. Hemos desarrollado un profundo conocimiento de SAP, y nuestro mapeo de integridad está definido tanto a nivel de campo individual como entre sistemas.

 Ayudamos a nuestros clientes a cumplir la normativa sobre protección de datos codificando los datos que no se copian en los sistemas de producción. También abordamos la desensibilización de datos en Producción con nuestra tecnología de redacción. Nuestro software de vanguardia, combinado con nuestra amplia experiencia en proyectos en múltiples países y sectores, nos permite ofrecerle una orientación experta sobre sus retos en materia de privacidad de datos.

Servicios de eliminación masiva de datos

Elimine datos históricos para los cuales ya no tiene bases legales para almacenar, como detalles de cuentas bancarias, mediante un proceso sencillo.

Más información

Evaluaciones de privacidad y seguridad

Podemos ayudarle a identificar y comprender su Información de Identificación Personal (PII) y a evaluar sus riesgos de acceso.

Más información

Evaluaciones de riesgos de acceso y rediseño de roles

Obtenga información sobre los riesgos de acceso en su sistema SAP y mitíguelo con un rediseño de roles que se ajuste a sus necesidades. 

Obtenga más información sobre cómo gestionar la privacidad, seguridad y riesgos de sus datos SAP

Data Security Blogs

Blogs:
Hablemos de Data Security

Más información

SAP data privacy Ultimate Guide

Explore la guía definitiva:
Camino hacia el cumplimiento de la privacidad de datos

Más información

Data Privacy and Security webinar

Webinars:
Privacidad y seguridad de datos

Más información

Privacy and Security success stories

Casos de Éxito:
Privacidad y seguridad de datos

Más información

Useful SAP downloads

Descargar: ebooks,
white papers y más

Descargar

Contáctenos

Gestione la privacidad, la seguridad y los riesgos de sus datos SAP