DB-02
Database
Access to Programs and Data
Preventative
Automated
July 29, 2026
Control Description
SAP HANA audit policies are enabled and configured to record sensitive user activities within audit logs. Audit logs are retained per company policy and reviewed by IT management to identify unauthorized activities.
Risk
Inadequate HANA audit logging and review may result in undetected unauthorized database activities, enabling fraud, data manipulation, and circumvention of application controls without forensic evidence.
Implementation Details
Auditing - > Global Settings - > Auditing Status = Enabled
Targeted audit policies are configured to capture high-risk security events, such as user administration (CREATE USER, DROP USER, ALTER USER), privilege and authorization changes (GRANT ANY, REVOKE ANY), and modifications to security configurations.
To prevent performance degradation and log bloat caused by routine business transactions, high-frequency technical application users (e.g., SAPABAP1) are excluded from these policies e.g by specifically excluding those users
Audit trails are directed to secure internal database storage with retention parameters configured to preserve records for at least 180 days (6 months) in alignment with corporate compliance standards.
Test Procedures
Test of Design (ToD):
• Inquire of database administrators and security management to understand the design of SAP HANA audit policies, application user exclusion lists, and log retention rules. Inspect corporate policies to confirm compliance baselines for database monitoring.
Test of Operating Effectiveness (ToE):
• Navigate to Security - > Auditing
• Verify that Auditing Status is set to Enabled
• Verify that audit policies are definedand log retention periods comply with policy