데이터 및 정보 보안 환경은 그 어느 때보다 빠르게 변화하고 있습니다. 새로운 기술의 시장 출시 및 도입 속도와 마찬가지로 해킹에 대한 전문 지식도 날로 증가하고 있습니다. 이는 데이터 소유자를 보호하기 위한 법률의 증가와 함께 주요 비즈니스 과제를 제시합니다.

EPI-USE Labs는 데이터 리스크, 보안, 개인정보 보호 및 규정 준수를 포괄하는 솔루션 제품군을 통해 이 복잡하고 중요한 분야를 탐색하는 데 도움을 드릴 수 있습니다. 또한 고객에게 포괄적인 보호를 제공하기 위해 SAP 고객을 위한 GRC(거버넌스, 리스크 관리 및 규정 준수)를 해결하는 컴플라이언스 소프트웨어를 제공하는 Soterion과 파트너십을 맺었습니다.

Play video
We see every day the news coming out in the press that there are hacking leaks throughout the world. A lot of big suppliers are working for us. They all have access to the test systems. Now when we copy the data, we're bound to protect their personal and sensitive information. For the first time, we now see our real risk exposure, which was even higher than what we anticipated. Compliance was no longer optional. The biggest challenge was that it had gotten really complicated over the years. The complexity of the implementation of GDPR is not only about anonymizing the system, but also archiving a lot of data. We have been doing that quite manually, but at some point, we couldn't make the next step. There's no way we can fix it. We had a very good conversation with EPI-USE Labs, and all the boxes were ticked. Without Soterion, we would have been running blind. And we now have it connected to each of our SAP systems, and we're literally using it on a daily basis. It was really important to have this kind of solution implemented for us. And, of course, it was implemented according to what the regulator was asking us. What we liked is the fact that you could scramble as you extracted the data. Even when we got the extracted files, there is no data in there that someone could have a look at. We work closely with our internal and external auditors, and they're quite happy with what we have done so far. With EPI-USE Labs products, I found it really useful that they're pre-empting my problems. It's really good to work with a supplier that understands the new legislation and is already there with a product.
이 비디오에는 한국어 자막이 있습니다.

SAP 데이터 개인정보 보호 및 보안 과제는?

SAP 데이터 개인정보 보호 규정 준수 강화

SAP에서 데이터 개인정보 보호 규정 준수 강화

모든 개인정보 보호 프로젝트의 목표는 회사의 관할권 내에서 필요한 데이터 개인정보 보호법 준수를 강화하는 것입니다. SAP의 구조상 데이터 개인정보 보호 규정 준수는 특히 까다롭습니다 . 데이터 개인정보 보호 규정 준수의 가장 강력한 이유 중 하나는 새로운 법률에 따라 법 집행 기관이 높은 재정적 제재를 가할 수 있다는 점입니다.

당사는 20년 넘게 전 세계 여러 산업 분야에서 개인정보 보호 프로젝트를 수행해 왔으며, 공통적인 프로젝트 접근 방식에서 필수적인 단계를 확인했습니다:

  • 리스크 식별: 영향 및 리스크 진단
  • PII 찾기 및 매핑
  • 액세스 위험 및 제어 검토
  • 운영 환경에서 백로그 정리
  • 운영 환경 사본에서 PII 관리
  • 데이터 주체 액세스 요청(DSAR) 처리하기
  • 개별 삭제 요청 처리
  • 데이터 주체의 사전 식별
  • 지속적인 감사 및 검토
액세스/제거 권한에 대한 응답

운영 시스템에서 액세스/삭제 권리에 대한 대응

태국의 PDPA, 미국의 주법 중 하나 또는 유럽의 GDPR을 준수하든, 귀하는 환경에서 개인 데이터에 대한 접근 및 삭제 권리에 대한 응답을 제공해야 합니다.

삭제 권한은 세무 감사를 위한 기록 보관과 같은 다른 법적 및 규정 준수 요건을 무효화하지 않습니다. 이제 다른 법적 이유로 데이터가 필요한지 확인하고, 필요하지 않은 경우 시스템에서 민감한 데이터를 제거할 방법을 찾아야 합니다.

SAP는 관계형 데이터베이스로서 민감한 데이터는 본질적으로 비즈니스 트랜잭션과 연결되어 있기 때문에 데이터 제거에 어려움이 있습니다. 따라서 기존의 아카이브 또는 삭제 방식은 트랜잭션과 마스터 데이터를 완전히 제거해야 한다는 것을 의미합니다.

EPI-USE Labs는Data Redact를 통해 레코드에서 PII를 제거하지만 솔루션의 참조 무결성은 그대로 유지하는 대안을 제공합니다. 또한Data Disclose는 PDF 출력에 효과적인 PII 매핑을 제공하여 액세스 권한에 대응할 수 있는 효율적인 프로세스를 제공합니다.

비운영 시스템에서 데이터 스크램블

비운영 시스템의 데이터 스크램블

모든 비즈니스는 연례 급여 과세 업데이트, 서비스 팩 업그레이드 또는 새로운 사용자 지정 등 프로세스를 테스트해야 합니다. 운영 환경에서 새로운 프로세스에 문제가 있다는 사실을 발견하고 싶지 않기 때문에 대부분의 기업은 운영 시스템의 복사본을 가져와 테스트 환경을 만듭니다.

테스트 환경의 수는 비즈니스에 따라 다르지만 일반적인 설정은 다음과 같습니다.

  • 실제 데이터를 제한적으로 또는 전혀 사용하지 않고 개발
  • 운영 환경에서 축소된 데이터 사본으로 품질 테스트
  • 운영 환경 데이터베이스의 전체 사본이 있는 사전 운영 환경.

새로운 개인정보 보호법에 따르면 데이터 주체와 관련된 데이터를 사용하려면 정보에 입각한 명시적인 동의를 받아야 합니다. 경험상 대부분의 비즈니스는 테스트 목적으로 데이터를 사용할 때 이러한 동의를 받지 않습니다. 동의 프로세스가 있더라도 데이터 주체의 비동의 응답에 대해 어떻게 해야 하는지 이해하는 데 추가적인 어려움이 있습니다.

Data Secure을 통해 데이터 익명화를 직접 수행하거나, 데이터 동기화 관리자 제품군의 일부인 Client Sync와 연결하여 종료 시 스크램블하는 기능을 제공하는 데이터 익명화를 권장합니다.

데이터 프라이버시 및 보안 리스크 이해

데이터 개인정보 보호 및 보안 리스크 이해 및 완화하기

문제를 해결하려면 먼저 문제를 이해해야 합니다. 데이터 개인정보 보호와 보안 모두 비즈니스 프로세스와 IT 자산에 어떤 리스크가 있는지 이해해야 합니다.

비즈니스 프로세스와 보안 리스크를 고려하세요. 예를 들어, 프론트 오피스 또는 HR 직원이 통화 중에 메모를 하나요? 그렇다면 이러한 메모에 대한 보안 프로세스는 어떻게 되어 있나요? 비즈니스 전반에 걸쳐 데이터 보안 모범 사례를 따르고 있나요?

IT 자산과 관련하여 세 가지 주요 고려 사항은 다음과 같습니다:

  • 외부 위협: 방화벽이나 VPN 보호와 같은 네트워크 및 인프라 보안
  • 내부 위협: 네트워크/SAP 시스템의 데이터에 대한 액세스 리스크
  • 규정 준수 위험: PII는 어디에 있으며 어떻게 관리되고 있나요?

종합적인 SAP 데이터 개인정보 보호 진단 서비스는(영문) 비즈니스의 내부 및 규정 준수 위험에 대한 투명성을 제공합니다.

SAP 전용 비즈니스 중심의 GRC 추진

SAP를 위한 비즈니스 중심 GRC 추진

거버넌스, 리스크 및 규정 준수(GRC) 솔루션은 액세스 리스크의 여러 측면을 고려합니다. 당사는 Soterion과 파트너십을 맺고 표준으로 제공되는 규칙(rule set)을 통해 빠르고 효율적으로 GRC 리스크를 분석할 수 있도록 지원합니다 :

  • 역할 분리(SoD)
  • 개인정보 보호: 민감한 데이터에 액세스하는 사용자
  • 관할권 간 데이터 액세스
  • 중요한 거래 리스크

이러한 솔루션은 SAP와 클라우드 애플리케이션(예: SAP SuccessFactors)을 통합하여 액세스 리스크에 대한 전체적인 관점을 제공할 수 있습니다.

또한 Soterion은 시스템 라이선스, 파이어파이터 액세스 프로세스 등에 대한 진단(영문 자료)도 제공합니다.

 
 

 

 

SAP 보안 리스크 최소화

SAP 시스템환경의 공격 표면 최소화

민감한 데이터를 보호하려면 공격할 수 있는 시스템 및 데이터의 지형도인 SAP 시스템환경의 '공격 표면'을 줄이는 것을 고려하세요. 데이터 마스킹 또는 난독화를 사용하면 데이터 주체를 식별할 수 있게 하거나 민감한 데이터 필드를 노출하지 않고도 테스트, 교육, 샌드박스 및 개발 시스템 데이터의 참조 무결성과 기능을 유지할 수 있습니다.

EPI-USE Labs의 Data Sync Manager(DSM) Suite의 일부인 Data Secure는 SAP 데이터를 마스킹하여 민감한 정보를 보호하는 완벽한 데이터 보호 솔루션입니다. 수백 개의 사전 제공된 마스킹 규칙을 통해 데이터가 올바르게 작동하도록 합니다. 새로운 규칙을 처음부터 만들거나, 기존 규칙을 확장하거나, 협업 플랫폼인 Client Central에서 다른 커뮤니티 사용자로부터 콘텐츠를 다운로드할 수 있습니다. 그 결과 실시간 데이터 보호가 가능합니다.

많은 기업이 ERP, CRM, SRM 및 외부 환경에 분산된 데이터를 SAP 환경과 통합했습니다. Data Secure는 여러 시스템에서 통합된 데이터 개체를 일관되게 익명화합니다.

SAP 외부에서 데이터를 스크램블링해야 하나요? 당사의 맞춤형 개발팀은 데이터를 스크램블링하는 솔루션을 구축하여 Data Secure를 SAP 이외의 시스템으로 확장할 수 있습니다.

소프트웨어

SAP 솔루션용 Data Privacy Suite

개인정보 보호법 준수

SAP의 혁신적인 개인정보 보호 및 규정 준수 솔루션은 SAP® 시스템을 사용하는 기업이 GDPR(일반 데이터 보호 규정) 및 기타 개인정보 보호법과 같은 법률을 준수할 수 있도록 지원합니다.

Soterion Access Risk Manager

비즈니스 중심의 효과적인 SAP용 GRC 사용

Soterion과 EPI-USE Labs를 사용하면 비용 효율적이고 직관적인 방식으로 역할과 권한을 진단, 업데이트, 유지 관리하고 데이터 개인정보 보호 규정을 준수할 수 있습니다.

Play video
Hi. My name is Dudley Cartwright from Soterion. I'd like to spend a few minutes explaining: what is business-centric GRC and why it's so important for effective access risk management in SAP. Access risk is business risk. What is meant by this is that it is a business decision whether a user in the organisation should have certain access. As an example, if a person in your organisation requires access to both create the purchase order and release the purchase order, which is a typical segregation of duty, it should be your business users who decide if that risk is acceptable to the organisation or not. The challenge facing most organisations is that the business users often have very little visibility as to what access is problematic and is causing a risk violation. And if they do have some form of visibility, you often find that the business users don't understand the access risks being presented to them. SAP authorizations is very technical and complex, and most of the GRC solutions on the market have been developed from a technical audit perspective with very little consideration for its use by the business. These technical and complex GRC solutions are not well adopted by the business users, who generally push this responsibility back onto the IT teams. What ends up happening is that the IT teams run these GRC solutions as back-end solutions with minimal involvement from the business. You often find a high degree of underutilization of the GRC solution because of this. At Soterion, we believe that implementing the correct GRC solution is crucial to enhancing business buy-in and accountability. The GRC solution needs to convert the technical GRC language into a language that the business users can understand. Soterion does this by illustrating all access risks with supporting business process flows. This provides more context to the business users who can then make quicker and more informed decisions. The Soterion solution has been developed to empower the business users with their access risk management activities. Enhancing business accountability of access risk with the use of a business-centric GRC solution will enhance your first line of defence, which in turn will improve the organisation's overall risk awareness and your ability to manage your risk. Should you be interested in seeing a more detailed demo covering other use cases, please don't hesitate to contact us.
이 비디오에는 한국어 자막이 있습니다.

Archive Central

규정 준수를 위해 특정 정보를 링펜싱하세요.

Archive Central™은 역할 기반의 안전한 웹 솔루션으로, 데이터 보호 책임자(DPO) 또는 비즈니스 사용자가 쿼리, 보고 및 비교를 위해 기록 데이터에 액세스할 수 있습니다. 보안 및 규정 준수를 위해 PII와 같은 민감한 정보를 암호화합니다.

Play video
Whether you're divesting your enterprise or planning to migrate to a new platform or SAP S/4HANA, decommissioning your system presents a unique compliance challenge. How do you store your legacy data cost-effectively and securely? Constant system and database updates make running an SAP display-only system too expensive, and the vast sea of interlinked data tables means you can't simply copy and store the relevant Transactional and Master data separately. There's also the issue of access risk. How do you manage who has access? That's where Archive Central comes in. Archive Central is a role-based secure web solution to get business users access to historical data for Queries and Comparisons while simultaneously ensuring compliance requirements are met. Using proprietary software, we can read, select, and automatically load your SAP data into collections that you can access through a modern web application provided as Software-as-a-Service, allowing you to decommission your SAP system safely, and with the ability to import data from any common machine readable formats such as CSV. Archive Central is capable of archiving data from non-SAP systems as well. Archive Central leverages the metadata to present a business entity for the user with all the related data rather than a set of disparate tables. You'll be able to filter through data easily. Our global search allows you to 'one click and type' to find the records you're looking for. It's also easily configurable, giving you the ability to customise the display to suit your needs. You'll also be able to store all common document formats and image files, so no need to worry about those old payslips, invoices, or certificates. They can be stored and linked with the corresponding data for easy access. You'll be able to track who is viewing data records and what a particular user has done. Don't let your legacy data hold you back. Securely store your legacy data for future Queries and Compliance with Archive Central.
이 비디오에는 한국어 자막이 있습니다.

서비스

데이터 프라이버시 컨설팅

Play video

SAP는 세계에서 가장 강력한 시스템 중 하나이지만 가장 복잡한 시스템 중 하나이기도 하며, 그 구조로 인해 개인정보 보호법 준수가 특히 까다롭습니다. 여러 SAP 개체와 시스템의 교차 기능 통합을 매핑하고 이해하려면 상세한 도메인 지식이 필요합니다.

오랜 SAP 파트너인 EPI-USE Labs는 SAP 데이터의 구조에 대해 깊이 있게 이해하고 있습니다. SAP에 대한 심층적인 지식을 쌓아왔으며, 개별 필드 수준과 시스템 간 무결성 매핑을 정의합니다.

운영 시스템에서 복사된 비운영 데이터를 스크램블링하여 고객이 개인정보 보호법을 준수하도록 지원합니다. 또한 Redaction 기술을 통해 운영 데이터의 민감성 제거 문제도 해결합니다. 여러 국가와 산업에 걸친 광범위한 프로젝트 경험과 최첨단 소프트웨어를 결합하여 데이터 프라이버시 문제에 대한 전문적인 지침을 제공할 수 있습니다.

대량 데이터 삭제 서비스

은행 계좌 정보와 같이 더 이상 보관할 법적 근거가 없는 과거 데이터를 간단한 절차로 삭제하세요.

자세히 알아보기

개인정보 보호 및 보안 평가

당사는 귀하의 개인 식별 정보(PII)를 이해 및 식별하고 귀하의 액세스 리스크를 진단하는 데 도움을 드릴 수 있습니다.

자세히 알아보기

액세스 리스크 진단 및 역할 재설계

SAP 시스템의 액세스 리스크에 대한 인사이트를 확보하고 목적에 맞는 새로운 역할 재설계를 통해 리스크를 완화하세요.

SAP 데이터 개인 정보 보호, 보안 및 리스크 관리를 위한 추가 인사이트 얻기

데이터 보안 블로그

블로그 읽기:
데이터 보안에 대해 알아보기

자세히 알아보기

SAP 데이터 개인정보 보호 전문가 가이드

전문적인 가이드 살펴보기
SAP 개인정보 보호 규정 준수를 위한 여정

자세히 보기

데이터 프라이버시 및 보안 웨비나

웨비나 보기:
데이터 프라이버시 및 보안

자세히 보기

개인 정보 보호 및 보안 성공 사례

고객 성공:
데이터 프라이버시 및 보안

자세히 보기

유용한 SAP 다운로드

다운로드: 전자책, 백서 등

자세히 보기

연락하기

SAP 데이터 개인정보 보호, 보안 및 리스크 관리