Applications vs. Administration: Misplaced Fault
摘要
When an SAP security incident surfaces, whether it is an unauthorized payment, a flawed master-data change, or a workflow bypass, the organizational reflex is almost always the same—find the person who “let it happen.” In most enterprises, the search quickly lands on the SAP security team or the system administrators who executed the provisioning. Their work is the most visible part of the access lifecycle, and visibility often becomes synonymous with blame.