Table Of Contents

1 Introduction
2 Hardening
2.1 What Is Hardening?
2.2 Multi-layered Hardening
2.3 Harding Implementation Steps
2.4 Implementation of Hardening
Network Hardening
Server Hardening
Implement Other Hardening
2.5 Other Hardening Information
2.6 Operation Checks
2.7 Final Security Check
2.8 Other Methods for Checking Hardening Implementation
3 Patch Management
3.1 What Is Patch Management?
3.2 Collecting Information
Collecting Information about Security Vulnerability
3.3 Assessing Risks
Assessing the Consequences and Urgency of the Vulnerability
What is a Vulnerability Assessment Matrix?
- Vulnerability Assessment Matrix
Organizing the Information about Security Vulnerability
Step 1: Organizing Information about Security Vulnerability
Assessing the Pros and Cons of the Risk
Determining the Degree of Urgency
Devising a Plan for Responding to the Vulnerability
Step 1: Devising a plan for responding to the vulnerability
3.4 Applying Security Update Program
Points to Consider When Applying Security Patches
Testing the Security Update Program before Application
Note: Before applying the security update program
Testing the Application in a Test Environment
Updating via Management Tools
3.5 Monitoring the Results
Verifying Behavior in the Test Environment
Confirming the Steps for Roll-Back in the Test Environment
Confirming that the Necessary Programs have been Applied
Appendix: Report on Hardening Verification
1.1 Verification Scenarios
Verification Scenarios
1.2 Contents of Verifications
1.3 Verification Results
Contents of Verifications
1.4 Network Hardening Settings
Network Hardening in SAP R/3 Enterprise
Network Hardening in SAP ITS
Network Hardening in SAP Enterprise Portal
1.5 Service and Other Hardening Settings
Service Hardening Using Templates
Reconfigurations Made After the Application of Security Templates
