← Back to Controls

APP-03

Layer:
Application
Category:
Change Management
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 29, 2026

Control Description

SAP production clients and core system settings are configured to prohibit direct changes to programs and configurations. Any temporary openings or overrides of production client settings are formally logged, monitored, and approved by management.

Risk

Inadequate restriction or unmonitored administrative overrides of production environment settings may allow unauthorized, untested, or direct changes to code and configurations, leading to system instability, security vulnerabilities, or data corruption

Implementation Details

Enforce a strict change prohibition in SAP production by locking the client-specific layer via SCC4 (Changes and Transport for Client Specific Objects set to No Changes Allowed) and the global repository layer via SE06 (Global Setting set to Not Modifiable).

Table T000 change logging is enabled (monitored via SE16N on DD09L) to ensure any modifications to production client settings are tracked.

For emergency or exceptional scenarios where direct changes are strictly required (e.g., specific number range adjustments), a formal change ticket is initiated and tested in a non-production environment.

The SAP Basis team submits an emergency access request via SAP GRC for a Firefighter ID (FFID), which requires formal approval prior to use.

Authorized Basis personnel use the FFID via SCC4 to temporarily open the production client, perform the approved adjustment, and immediately restore the locked status.

All actions executed under the FFID are captured in system audit logs and subjected to periodic review.

Test Procedures

Test of Design (ToD):

• Inquire of SAP Basis management o understand the design of production client lockdown controls, global system change options, and the workflow for temporarily opening production when necessary.

• Inspect production client settings via SCC4 to verify that client-specific objects are set to No Changes Allowed.

• Inspect system change options via SE06 to confirm that global settings prevent direct changes at the system level.

• Inspect technical settings for table T000 via SE16N (checking DD09L) to verify that change logging is active.

Test of Operating Effectiveness (ToE):

• Obtain the population of production client opening instances from the change logs via SCC4.

• Select a sample of instances where the production client was opened.

• Inspect the associated change ticket to verify that formal business/management approval was documented prior to execution.

• Verify that an approved SAP GRC Firefighter ID (FFID) was utilized to perform the change and that the activity was appropriately logged and reviewed