Il panorama della sicurezza dei dati e delle informazioni sta cambiando più rapidamente che mai. Le competenze in materia di hacking sono in aumento, così come la velocità di commercializzazione e l'adozione di nuove tecnologie. Tutto ciò, insieme alla crescente legislazione volta a proteggere i proprietari dei dati, rappresenta un'importante sfida per le aziende.

EPI-USE Labs può aiutarvi a navigare in questo campo complesso e critico con una suite di soluzioni che coprono il rischio, la sicurezza, la privacy e la conformità dei dati. Per fornire ai nostri clienti una protezione completa, abbiamo stretto una partnership con Soterion, il cui software di conformità risolve le problematiche GRC (Governance, Risk management e Compliance) per i clienti SAP.

Play video
We see every day the news coming out in the press that there are hacking leaks throughout the world. A lot of big suppliers are working for us. They all have access to the test systems. Now when we copy the data, we're bound to protect their personal and sensitive information. For the first time, we now see our real risk exposure, which was even higher than what we anticipated. Compliance was no longer optional. The biggest challenge was that it had gotten really complicated over the years. The complexity of the implementation of GDPR is not only about anonymizing the system, but also archiving a lot of data. We have been doing that quite manually, but at some point, we couldn't make the next step. There's no way we can fix it. We had a very good conversation with EPI-USE Labs, and all the boxes were ticked. Without Soterion, we would have been running blind. And we now have it connected to each of our SAP systems, and we're literally using it on a daily basis. It was really important to have this kind of solution implemented for us. And, of course, it was implemented according to what the regulator was asking us. What we liked is the fact that you could scramble as you extracted the data. Even when we got the extracted files, there is no data in there that someone could have a look at. We work closely with our internal and external auditors, and they're quite happy with what we have done so far. With EPI-USE Labs products, I found it really useful that they're pre-empting my problems. It's really good to work with a supplier that understands the new legislation and is already there with a product.

Quali sono le vostre sfide in materia di privacy e sicurezza dei dati SAP?

Migliorare la conformità alla privacy dei dati SAP

Migliorare la conformità alla privacy dei dati SAP 

L'obiettivo di qualsiasi progetto sulla privacy è quello di aumentare la conformità alle leggi sulla privacy dei dati richieste nella giurisdizione dell'azienda. La struttura di SAP rende particolarmente complicato affrontare la conformità alla privacy dei dati. Una delle ragioni più convincenti per la conformità alla privacy è l'applicazione delle multe; le nuove leggi prevedono l'applicazione di sanzioni finanziarie elevate da parte degli organi legali. 

Da oltre 20 anni realizziamo progetti sulla privacy in tutto il mondo, in diversi settori, e abbiamo identificato le fasi essenziali di un approccio comune al progetto:

  • Identificare i rischi: Valutazione dell'impatto e del rischio
  • Individuazione e mappatura delle PII
  • Revisione del rischio di accesso e dei controlli
  • Ripulire l'arretrato in produzione
  • Gestire le PII nelle copie di produzione
  • Gestire le richieste di accesso ai dati (DSAR)
  • Elaborare le richieste di rimozione individuali
  • Identificazione proattiva dei soggetti interessati
  • Audit e revisione continui
Rispondere al diritto di accesso/rimozione

Rispondere al diritto di accesso/rimozione in sistemi di Produzione 

Sia che stiate aderendo al PDPA in Thailandia, a una delle leggi statali negli Stati Uniti o al GDPR in Europa, siete tenuti a fornire una risposta al Diritto di accesso e alla cancellazione dei dati personali dal vostro ambiente.

Il Diritto all'eliminazione non sostituisce nessun altro requisito legale e di conformità, come ad esempio la conservazione dei registri per le verifiche fiscali. Ora è necessario trovare un modo per verificare se i dati sono necessari per altri motivi legali e, in caso contrario, rimuovere i dati sensibili dal sistema.

SAP rappresenta una sfida per la rimozione dei dati: essendo un database relazionale, i dati sensibili sono intrinsecamente legati alle transazioni aziendali. Pertanto, i metodi tradizionali di archiviazione o eliminazione implicano la necessità di rimuovere completamente le transazioni e i dati anagrafici.

EPI-USE Labs offre un'alternativa con Data Redact, che rimuove le PII dai record ma lascia l'integrità referenziale della soluzione. E Data Disclose fornisce un'efficace mappatura delle PII in un output PDF, consentendo un processo efficiente per rispondere al Diritto di Accesso.

Scramble dei dati nei sistemi non di produzione

Scramble dei dati nei sistemi non di produzione

Ogni azienda ha bisogno di testare i propri processi, che si tratti degli aggiornamenti annuali della tassazione sulle retribuzioni, dell'aggiornamento del service pack o di nuove personalizzazioni. Non si vuole scoprire di avere un problema con i nuovi processi in produzione, quindi la maggior parte delle aziende prende una copia dei propri sistemi di produzione e crea ambienti di test.

Il numero di ambienti di test varia a seconda dell'azienda, ma una tipica configurazione prevede

  • Sviluppo con dati reali limitati o inesistenti
  • Qualità: una copia ridotta dei dati della produzione
  • Pre-produzione una copia completa del database di produzione.
Le nuove leggi sulla privacy stabiliscono che è necessario avere un consenso informato ed esplicito per l'utilizzo dei dati relativi agli interessati. Secondo la nostra esperienza, la maggior parte delle aziende non dispone di tale consenso per l'utilizzo dei dati a scopo di test. Anche se si dispone di un processo di consenso, è necessario capire cosa fare in caso di risposta negativa da parte dell'interessato.

Consigliamo l'anonimizzazione dei dati con Data Secure, che fornisce l'anonimizzazione diretta dei dati in loco, o la possibilità di scramble all'uscita quando è collegato con Client Sync, parte della Data Sync Manager Suite.
Comprendere i rischi per la privacy e la sicurezza dei dati

Comprendere i rischi per la privacy e la sicurezza dei dati

Per risolvere un problema, è necessario innanzitutto comprenderlo. Sia per la privacy che per la sicurezza dei dati, è necessario comprendere i rischi legati ai processi aziendali e al patrimonio informatico.

Considerate i vostri processi aziendali e i rischi per la sicurezza. Ad esempio, i colleghi del front office o delle risorse umane prendono appunti durante le chiamate? Se sì, qual è il processo di sicurezza per questi appunti? State seguendo le best practice per la sicurezza dei dati in tutta l'azienda? 

Per quanto riguarda il vostro patrimonio informatico, le considerazioni principali sono tre:

  • Minaccia esterna: Sicurezza della rete e dell'infrastruttura, come firewall o protezione VPN.
  • Minaccia interna: Il rischio di accesso ai dati nella rete o nel sistema SAP.
  • Rischio di conformità: Dove si trovano le vostre PII e come vengono gestite?
Il nostro servizio completo di valutazione della privacy dei dati SAP fornisce trasparenza sui rischi interni e di conformità per la vostra azienda.
Guidare il GRC incentrato sul business per SAP

Guidare il GRC incentrato sul business per SAP

Le soluzioni di Governance, Risk and Compliance (GRC) tengono conto di molti aspetti del rischio di accesso. Siamo partner di Soterion, che offre un'analisi rapida ed efficiente dei vostri rischi GRC con set di regole standard che coprono:

  • Segregazione dei compiti (SoD)
  • Privacy: utenti che accedono a dati sensibili
  • Accesso ai dati in più giurisdizioni
  • Rischio di transazioni critiche.
Queste soluzioni possono integrarsi tra SAP e le applicazioni cloud (come SAP SuccessFactors) per fornire una visione olistica del rischio di accesso.

Soterion offre anche una valutazione delle licenze di sistema, dei processi di accesso dei vigili del fuoco e altro ancora.
Ridurre al minimo la superficie di attacco di SAP

Ridurre al minimo la superficie di attacco di SAP

Per proteggere i dati sensibili, considerate la possibilità di ridurre la "superficie di attacco" nel vostro panorama SAP, ovvero la topografia dei sistemi e dei dati che possono essere attaccati. Il mascheramento o l'offuscamento dei dati possono mantenere l'integrità referenziale e la funzionalità dei dati dei sistemi di test, formazione, sandbox e sviluppo senza rendere identificabili i soggetti dei dati o lasciare esposti campi di dati sensibili.

Data Secure, parte della suite Data Sync Manager (DSM) di EPI-USE Labs, è una soluzione completa di protezione dei dati che maschera i dati SAP per salvaguardare le informazioni sensibili. Consente ai dati di funzionare correttamente grazie a centinaia di regole di mascheramento preconsegnate. È possibile creare nuove regole da zero, estendere quelle esistenti o scaricare contenuti da altri utenti della community sulla nostra piattaforma collaborativa, Client Central. Il risultato è una protezione dei dati in tempo reale.

Molte aziende hanno paesaggi SAP integrati con dati distribuiti tra ERP, CRM, SRM e ambienti esterni. Data Secure anonimizza gli oggetti di dati integrati in modo coerente su sistemi diversi.

Avete bisogno di anonimizzare i dati al di fuori di SAP? Il nostro team di sviluppo personalizzato è in grado di creare una soluzione per la frammentazione dei dati, che estende Data Secure a sistemi non SAP.

SOFTWARE

La Suite di Data Privacy per soluzioni SAP

Conformità alla legislazione sulla privacy dei dati

La nostra innovativa soluzione per la privacy e la conformità dei dati aiuta le aziende con sistemi SAP® a conformarsi a normative come il GDPR (General Data Protection Regulation) e ad altre leggi sulla privacy dei dati.

 

Soterion Access Risk Manager

Ottenere un GRC efficace e incentrato sul business per SAP

Con Soterion ed EPI-USE Labs, potete valutare, aggiornare e mantenere ruoli e autorizzazioni in modo economico e intuitivo, rispettando le normative sulla privacy dei dati.

Play video
Hi. My name is Dudley Cartwright from Soterion. I'd like to spend a few minutes explaining: what is business-centric GRC and why it's so important for effective access risk management in SAP. Access risk is business risk. What is meant by this is that it is a business decision whether a user in the organisation should have certain access. As an example, if a person in your organisation requires access to both create the purchase order and release the purchase order, which is a typical segregation of duty, it should be your business users who decide if that risk is acceptable to the organisation or not. The challenge facing most organisations is that the business users often have very little visibility as to what access is problematic and is causing a risk violation. And if they do have some form of visibility, you often find that the business users don't understand the access risks being presented to them. SAP authorizations is very technical and complex, and most of the GRC solutions on the market have been developed from a technical audit perspective with very little consideration for its use by the business. These technical and complex GRC solutions are not well adopted by the business users, who generally push this responsibility back onto the IT teams. What ends up happening is that the IT teams run these GRC solutions as back-end solutions with minimal involvement from the business. You often find a high degree of underutilization of the GRC solution because of this. At Soterion, we believe that implementing the correct GRC solution is crucial to enhancing business buy-in and accountability. The GRC solution needs to convert the technical GRC language into a language that the business users can understand. Soterion does this by illustrating all access risks with supporting business process flows. This provides more context to the business users who can then make quicker and more informed decisions. The Soterion solution has been developed to empower the business users with their access risk management activities. Enhancing business accountability of access risk with the use of a business-centric GRC solution will enhance your first line of defence, which in turn will improve the organisation's overall risk awareness and your ability to manage your risk. Should you be interested in seeing a more detailed demo covering other use cases, please don't hesitate to contact us.
 

Archive Central

Archiviazione di informazioni specifiche per la conformità alle normative.

Archive Central™ è una soluzione web sicura e basata su ruoli che consente ai responsabili della privacy dei dati (DPO) o agli utenti aziendali di accedere ai dati storici per effettuare interrogazioni, report e confronti. Crittografa le informazioni sensibili come le PII per garantire la sicurezza e la conformità alle normative. 

Play video
Whether you're divesting your enterprise or planning to migrate to a new platform or SAP S/4HANA, decommissioning your system presents a unique compliance challenge. How do you store your legacy data cost-effectively and securely? Constant system and database updates make running an SAP display-only system too expensive, and the vast sea of interlinked data tables means you can't simply copy and store the relevant Transactional and Master data separately. There's also the issue of access risk. How do you manage who has access? That's where Archive Central comes in. Archive Central is a role-based secure web solution to get business users access to historical data for Queries and Comparisons while simultaneously ensuring compliance requirements are met. Using proprietary software, we can read, select, and automatically load your SAP data into collections that you can access through a modern web application provided as Software-as-a-Service, allowing you to decommission your SAP system safely, and with the ability to import data from any common machine readable formats such as CSV. Archive Central is capable of archiving data from non-SAP systems as well. Archive Central leverages the metadata to present a business entity for the user with all the related data rather than a set of disparate tables. You'll be able to filter through data easily. Our global search allows you to 'one click and type' to find the records you're looking for. It's also easily configurable, giving you the ability to customise the display to suit your needs. You'll also be able to store all common document formats and image files, so no need to worry about those old payslips, invoices, or certificates. They can be stored and linked with the corresponding data for easy access. You'll be able to track who is viewing data records and what a particular user has done. Don't let your legacy data hold you back. Securely store your legacy data for future Queries and Compliance with Archive Central.

SERVIZI

Consulenza sulla privacy dei dati

Play video
The first challenge that most businesses face from a privacy point of view is actually understanding how much of the risk they're holding within their data. Most industries have spent, fifteen, twenty years customizing an SAP environment, making it correct for their business process, with no consideration as to how much data they're then proliferating into additional tables. So actually then understanding and mapping that data is quite a large challenge especially because the people that built them have likely retired, moved on, and gone through natural attrition. So it does create quite a large business challenge, and to be able to build your business case for an investment in a privacy solution you first need to know how much risk you are mitigating to be able to follow it through. So to help with that, EPI-USE Labs have utilized our data model mapping that we've been using for the last twenty years to manage SAP data to build a discovery program. Now unlike some of the other competitors on the market, EPI-USE Labs are utilizing SAP domain knowledge that we've built to understand the data dictionary within your system, and we're able to complete a key search of the data elements within that environment based on the list of PII data items that we've already identified. The output list is then validated against whether the data is actually populated because, of course, just because it's in the system doesn't mean you've actually populated it. And we'll then go through a workshop and detailed analysis process with one of our professional services consultants where we will analyze and understand how we can integrate that data back to a data subject for a customer, a vendor or an employee, but also understand what values are maintained and map out that PII challenge for your SAP system. We collect all that information into a single document that has both the business functional requirements from the workshop, as to what retention periods you would like and how data should be affected based on those retention periods - so whether it should be cleared or transformed to a new value, and the same for non-production, for a system copy that you're going to use for testing, you need to have the real data from Production to improve your DevOps process. But you can't have the real data because that is a PII risk, and you would have to have informed and explicit consent from every data subject in your environment to use that data as testing, and no company has entered those clauses into a contract so far to be able to say they're ready. So with that documentation, you have the business requirements of how data should be transformed and then also the technical specification of exactly which tables and fields grouped according to data type to be able to understand where the names, where the telephone numbers, where the bank details exist within the environment. Additionally we now have an enhanced discovery working with one of our strategic partners Soterion. They offer GRC solutions as an alternative to SAP GRC. They have pre-delivered rule sets that are able to analyse your segregation of duties risk. They also have specific rule-sets to review your access to privacy data, to be able to understand who can actually see sensitive data within your SAP system. We also have queries to be able to understand where there's cross legal jurisdictional access. So where somebody from the US is able to access European employee data or vice-versa. Through that analysis, we're able to provide a clear risk assessment of both the access to sensitive data, and where that data is within your environment. Both of these options come as a license free, there is no license cost upfront, there is some professional services cost for around about one and a half to two weeks elapsed time, so in a very short turnaround period we're able to provide you this documentation, which we've seen from some of our clients is being used as audit evidence and passed through to their auditors to be able to help them understand your data model and how you're compliant to the laws. So the data discovery and enhanced data discovery are available from your Account Executives, and we would be happy to discuss them with you. As well as the output of the document, we will also then give you a fixed price, fixed scope implementation cost if you were to choose EPI-USE Labs as your privacy partner to be able to manage that data moving forward.

SAP è uno dei sistemi più robusti al mondo, ma anche uno dei più complessi, e la sua struttura rende particolarmente complicato affrontare la conformità alla legislazione sulla privacy dei dati. È necessaria una conoscenza dettagliata del dominio per mappare e comprendere l'integrazione interfunzionale di più oggetti e sistemi SAP.

In qualità di partner SAP di lunga data, EPI-USE Labs ha una conoscenza approfondita della struttura dei dati SAP. Abbiamo sviluppato una conoscenza approfondita di SAP e la nostra mappatura dell'integrità è definita sia a livello di singolo campo che tra i sistemi.

Aiutiamo i nostri clienti a conformarsi alle leggi sulla privacy dei dati, scramblingando i dati non di produzione copiati dai sistemi di produzione. Ci occupiamo anche della de-sensibilizzazione dei dati in produzione con la nostra tecnologia di redenzione. Il nostro software all'avanguardia, unito alla nostra vasta esperienza di progetti in diversi paesi e settori, ci permette di fornirvi una guida esperta per le vostre sfide in materia di privacy dei dati.

Servizi di rimozione di massa dei dati

Eliminate i dati storici che non avete più motivo di conservare, come ad esempio i dati del conto bancario, con una semplice procedura.

SCOPRI DI PIÙ

Analisi della privacy e della sicurezza

Possiamo aiutarvi a comprendere e identificare le vostre informazioni di identificazione personale (PII) e a valutare i rischi di accesso.

SCOPRI DI PIÙ

Valutazione del rischio di accesso e riprogettazione dei ruoli

Ottenete informazioni sul rischio di accesso nel vostro sistema SAP e mitigatelo con una nuova riprogettazione dei ruoli adatta allo scopo. 

Ottieni ulteriori informazioni per gestire la privacy, la sicurezza e il rischio dei tuoi dati SAP

Data Security Blogs

Leggi gli articoli:
Parliamo di Data Security

Scopri di più

SAP data privacy Ultimate Guide

Esplora la ultimate guide:
Road to SAP data privacy compliance

Scopri di più

Data Privacy and Security webinar

Guarda i webinars:
Data Privacy e Sicurezza

Guarda qui

Privacy and Security success stories

Storie di successo:
Data privacy e sicurezza

Scopri di più

Useful SAP downloads

Download: Ebooks,
white papers ed altro

Scopri di più

Contattaci

Gestisci la privacy, la sicurezza e il rischio dei tuoi dati SAP