Security Measures – Overview
(RFC)
To guarantee the security of your RFC connections, include the following points in your setup and take the appropriate measures:
● Restrict authorizations for maintaining RFC destinations (transaction SM59)
● Store user information for system users only (not for dialog users)
● Restrict access to table RFCDES (information on RFC destinations)
● Use authorization checks in (application) function modules if you want to call these modules using RFC.
● Use secure network communications.
● Restrict trace access
● Deactivate remote monitoring of SAP gateways
● Prevent the misuse of RFC Software Development Kit
● Allow RFC connections from known and selected systems only
● Restrict the use of external RFC server programs
●
Restrict access to
RFC server program RFCEXEC or RFCEXEC.EXE (only relevant for
classic RFC
API).

For a more detailed description of these measures, see the appropriate scenario.
● RFC Communication Between SAP Systems
● RFC Communication Between SAP Systems and External (Non-SAP) Systems

Also read the following security information about the SAP Gateway:
Security Settings in
SAP Gateway

You can use the Security Audit Log to monitor RFC calls: