SAP Datasphere Security Recommendations

These recommendations help you evaluate the security of the configuration of SAP Datasphere services in your landscape.

See Explanation of Table Headings in the SAP Business Technology Platform (SAP BTP) documentation.
Security Recommendations

Service

Priority

Secure Operations Map

Topic

Default Setting or Behavior

Recommendation

More Information

Last Update

Index

SAP Datasphere

Recommended

Security Monitoring and Forensics

Audit Data

The default and minimum retention time for audit log entries is 7 days, and the maximum retention time is 10 000 days. Furthermore, be aware that when you delete a space, all audit logs entries generated for the space, including audit log entries related to any Open SQL schema or HDI container associated with the space, will be permanently deleted.

Export audit log entries before they are deleted. Likewise, before deleting your space, you may want to export the audit log entries generated for your space.

Logging Read and Change Actions for Audit

2023-07-26

DS-0001

SAP Datasphere

Critical

Audit and Fraud Management

Audit Data

By default, audit logs are not enabled for spaces as they can consume a large amount of storage in your SAP Datasphere tenant.

If users with the DW Space Administrator role have enabled audit logs to be created for their space, read and change actions (policies) are recorded. Users with the DW Administrator role can then get an overview of all audit logs and analyze who did what and when in the database. The default and minimum retention time of audit logs is 7 days and the maximum retention time is 10000 days.

To enable audit logs via the command line: enter the audit logging policy for read and change operations and the number of days that the logs are retained. you can retain logs for any period between 7 and 10000 days. Default values: false, 30, false, 30

If you handle personal data in your tenant, we recommend that you enable audit logs to help comply with General Data Protection Regulation (GDPR).

Users with the DW Space Administrator role can enable audit logs for their space in the space details page. You can also enable audit logs via the command line.

Users with the DW Administrator role can then monitor the read and change actions performed in the database with audit logs, and see who did what and when.

Logging Read and Change Actions for Audit

Monitor Read and Change Actions with Audit Logs

The Space Definition File Format

2023-07-26

DS-0002

SAP Datasphere

Critical

User and Identity Management

Authentication

Password policy can be defined for database users with complexity requirements, expiration periods, and reuse restrictions.

The Number of Days to Expiration and Password Change Required on First Logon settings apply only to database users with the Enable Password Lifetime option selected in their configuration dialog.

By default, the properties of password policy are set as follows:
  • Number of Days to Expiration: 182

  • Number of Last Used Passwords That Cannot Be Reused: 5

  • Password Change Required on First Logon: true

  • Minimum Password Length: 8

  • Minimum Number of Uppercase Letters: 1

  • Minimum Number of Lowercase Letters: 1

  • Minimum Number of Digits: 1

  • Minimum Number of Special Characters: 0

Users with the DW Administrator role should define a password policy to ensure system security.

The following values are recommended for non-administrator users.
  • Number of Days to Expiration: 90

  • Number of Last Used Passwords That Cannot Be Reused: 15

  • Password Change Required on First Logon: true

  • Minimum Password Length: 15

  • Minimum Number of Uppercase Letters: 1

  • Minimum Number of Lowercase Letters: 1

  • Minimum Number of Digits: 1

  • Minimum Number of Special Characters: 0

Set a Password Policy for Database Users

2026-08-11

DS-0003

SAP Datasphere

Recommended

User and Identity Management

Authentication

You can reset a database user password via the command line.

For security reasons, specify to receive the new password in an output file.

Manage Spaces and Space Access via the Command Line

2023-07-26

DS-0004

SAP Datasphere

Critical

Network Security

Encryption

SAP Datasphere supports encrypted communication for network communication channels. To enable a secure SSL/TLS-based connection for a connection type that supports remote tables but doesn't use a Data Provisioning Agent, you need to upload a server certificate to SAP Datasphere.

Use encrypted channels in all cases where your network isn't protected by other security measures against attacks, such as eavesdropping, for example, when your network is accessed from public networks. Upload server certificates to enable secure SSL/TLS-based connections to certain sources.

Cloud Network and Communication Security

Manage Certificates

2023-07-26

DS-0005

SAP Datasphere

Critical

Roles and Authorization

Authorization

For security reasons, all external connections to your SAP Datasphere instance are blocked by default.

Control the range of external public IPv4 addresses that get access to the database of your SAP Datasphere by adding them to an allowlist.

Manage IP Allowlist

2023-07-26

DS-0006

SAP Datasphere

Advanced

Data Privacy and Protection

Data Privacy

By default, SAP Datasphere keeps track of objects you’ve accessed, so that you can quickly locate those objects or files again

Keep the object tracking on. Clicking the Manage Settings button opens the Settings dialog for your account where you can enable or disable tracking and optionally clear previously tracked data. In addition, you can always click your user icon in the shell bar, select Settings, and then select the Privacy setting option to change profile settings.

Changing SAP Datasphere Settings

2023-07-26

DS-0007

SAP Datasphere

Recommended

Security Hardening

Session Management

By default, the session timeout is set to 3600 seconds (1 hour). The minimum value is 300 seconds, and the maximum value is 43200 seconds.

Set the amount of time before a user session expires if the user doesn't interact with the system. The recommended time frame is 3600 seconds (1 hour).

Administration Apps and Tools

2023-07-26

DS-0008

SAP Datasphere

Recommended

Security Monitoring and Forensics

Authorization

You can import analysis authorizations defined in SAP BW and SAP BW∕4HANA systems into SAP Datasphere to provide row-level protection for data imported from these systems.

The report generating the permissions table in SAP BW∕4HANA should run at least once a day and the remote table in SAP Datasphere is kept in remote (federated) access to ensure that it is always up-to-date. If you decide to replicate the permissions table, you should schedule at minimum a daily refresh.

Import SAP BW and SAP BW∕4HANA Analysis Authorizations

2023-07-26

DS-0009

For more information on SAP Datasphere security, see SAP Datasphere Security Guide.