← Back to Controls

DB-02

Layer:
Database
Category:
Access to Programs and Data
Control Type:
Preventative
Execution Type:
Automated
Effective Date:
July 29, 2026

Control Description

SAP HANA audit policies are enabled and configured to record sensitive user activities within audit logs. Audit logs are retained per company policy and reviewed by IT management to identify unauthorized activities.

Risk

Inadequate HANA audit logging and review may result in undetected unauthorized database activities, enabling fraud, data manipulation, and circumvention of application controls without forensic evidence.

Implementation Details

Auditing - > Global Settings - > Auditing Status = Enabled

Targeted audit policies are configured to capture high-risk security events, such as user administration (CREATE USER, DROP USER, ALTER USER), privilege and authorization changes (GRANT ANY, REVOKE ANY), and modifications to security configurations.

To prevent performance degradation and log bloat caused by routine business transactions, high-frequency technical application users (e.g., SAPABAP1) are excluded from these policies e.g by specifically excluding those users

Audit trails are directed to secure internal database storage with retention parameters configured to preserve records for at least 180 days (6 months) in alignment with corporate compliance standards.

Test Procedures

Test of Design (ToD):
• Inquire of database administrators and security management to understand the design of SAP HANA audit policies, application user exclusion lists, and log retention rules. Inspect corporate policies to confirm compliance baselines for database monitoring.

Test of Operating Effectiveness (ToE):
• Navigate to Security - > Auditing
• Verify that Auditing Status is set to Enabled
• Verify that audit policies are definedand log retention periods comply with policy