<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAPLIB</title>
	<atom:link href="http://www.saplib.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.saplib.com</link>
	<description>SAP R/3 Security Resources</description>
	<lastBuildDate>Sat, 18 Sep 2010 10:00:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SAS 70 Environmental Controls Security Examination Audit</title>
		<link>http://www.saplib.com/sas-70-environmental-controls-security-examination-audit/</link>
		<comments>http://www.saplib.com/sas-70-environmental-controls-security-examination-audit/#comments</comments>
		<pubDate>Sat, 18 Sep 2010 10:00:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Audit]]></category>
		<category><![CDATA[Checklist]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.saplib.com/?p=187</guid>
		<description><![CDATA[The environment of the data center will come under scrutiny as well. Not only will the auditors examine the physical access controls to the data center but they will also examine the suitability of the data center to house sensitive information and systems. As such the following items are examined - The structure of the [...]]]></description>
			<content:encoded><![CDATA[<p>The environment of the data center will come under scrutiny as well. Not only will the auditors examine the physical access controls to the data center but they will also examine the suitability of the data center to house sensitive information and systems. As such the following items are examined<br />
- The structure of the walls, ceiling, and floor<br />
- The security of the wiring<br />
- Fire suppression<br />
- Environmental controls<br />
- Power<span id="more-187"></span></p>
<p>The auditors will look for ways of using the lack of controls to either access sensitive areas or information and the ability of the systems to continue to function during adverse conditions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.saplib.com/sas-70-environmental-controls-security-examination-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Logical Access Controls Security Examination Audit</title>
		<link>http://www.saplib.com/sas-70-logical-access-controls-security-examination-audit/</link>
		<comments>http://www.saplib.com/sas-70-logical-access-controls-security-examination-audit/#comments</comments>
		<pubDate>Sat, 18 Sep 2010 10:00:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Audit]]></category>
		<category><![CDATA[Checklist]]></category>
		<category><![CDATA[Implementation]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.saplib.com/?p=185</guid>
		<description><![CDATA[Logical access controls determine which individuals have access to what information. Some of the items examined here are mechanisms in place on computer and network systems and some pertain to the overall architecture of the offerings provided by the organization. Some of the items that will be investigated include - Individuals who have access to [...]]]></description>
			<content:encoded><![CDATA[<p>Logical access controls determine which individuals have access to what information. Some of the items examined here are mechanisms in place on computer and network systems and some pertain to the overall architecture of the offerings provided by the organization. Some of the items that will be investigated include<br />
- Individuals who have access to client information<br />
- Individuals with privileged access to network devices such as firewalls and routers and computer systems<br />
- Appropriateness of individual access to job function<br />
- Appropriateness of user management procedures to identify dormant and unused accounts and to determine individual access<br />
- Restriction of customer access to prevent the sharing of information<br />
- Mechanisms in place to prevent unauthorized access to client information (both with regard to other clients and employees)<!--break--></p>
<p>The information that is necessary to evaluate these issues is not solely related to the controls on the computer systems. The auditors will need to understand the underlying architecture that separates sensitive information and the procedures used by the organization to manage user access effectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.saplib.com/sas-70-logical-access-controls-security-examination-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Clearance Levels in the United States</title>
		<link>http://www.saplib.com/security-clearance-levels-in-the-united-states/</link>
		<comments>http://www.saplib.com/security-clearance-levels-in-the-united-states/#comments</comments>
		<pubDate>Tue, 07 Sep 2010 22:05:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[How to]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.saplib.com/?p=183</guid>
		<description><![CDATA[Secret or Level 2 Clearance A secret clearance (also known as ‘collateral secret’ or ‘ordinary secret’) is broadly similar to the UK SC clearance. There are a number of things that can complicate obtaining secret clearance: - Residences in foreign countries - Relatives outside the United States - Significant ties with non-US citizens - Bankruptcy [...]]]></description>
			<content:encoded><![CDATA[<p><b>Secret or Level 2 Clearance</b><br />
A secret clearance (also known as ‘collateral secret’ or ‘ordinary secret’) is broadly similar to the UK SC clearance. There are a number of things that can complicate obtaining secret clearance:<br />
- Residences in foreign countries<br />
- Relatives outside the United States<br />
- Significant ties with non-US citizens<br />
- Bankruptcy and unpaid bills<br />
- Criminal charges of any kind.</p>
<p>Poor financial history is the number-one cause of rejection and foreign activities and criminal records are also common causes for disqualification. A secret clearance requires an NACLC check. It must also be reinvestigated every 10 years (though, in practice, it tends to happen more often).</p>
<p><b>Top Secret or Level 3 Clearance</b><span id="more-183"></span><br />
As you would expect, ‘Top Secret’ is the most stringent clearance. A top secret (TS) clearance is usually only given following a singlescope background investigation (SSBI). This will include independent investigation into the following:<br />
- Citizenship;<br />
- Education;<br />
- Employment;<br />
- References;<br />
- Neighborhood and friends;<br />
- Credit;<br />
- Local agency checks;<br />
- Public records.</p>
<p>Top secret clearances, in general, afford one access to data that directly affects national security or other highly sensitive data. There are far fewer individuals with TS clearances than secret clearances. A TS clearance can  ake as few as 3-6 months to obtain, but more often it takes between six and 18 months and sometimes even up to three years. The SSBI must be renewed every five years.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.saplib.com/security-clearance-levels-in-the-united-states/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Download Free Onapsis&#8217; SAP Security In-Depth publication</title>
		<link>http://www.saplib.com/download-free-onapsis-sap-security-in-depth-publication/</link>
		<comments>http://www.saplib.com/download-free-onapsis-sap-security-in-depth-publication/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 10:16:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Audit]]></category>
		<category><![CDATA[Checklist]]></category>
		<category><![CDATA[SAP]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.saplib.com/?p=180</guid>
		<description><![CDATA[SAP Security In-Depth is a free technical publication leaded by the Onapsis Research Labs with the purpose of providing specialized information about the current and future risks in the SAP security field, allowing all the different actors (financial managers, information security managers, SAP administrators, auditors, consultants and the general professional community) to better understand the [...]]]></description>
			<content:encoded><![CDATA[<p>SAP Security In-Depth is a free technical publication leaded by the Onapsis Research Labs with the purpose of providing specialized information about the current and future risks in the SAP security field, allowing all the different actors (financial managers, information security managers, SAP administrators, auditors, consultants and the general professional community) to better understand the involved risks and the techniques and tools available to assess and mitigate them.<span id="more-180"></span></p>
<p><a href="http://www.onapsis.com/resources/get.php?resid=ssid01" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.onapsis.com/resources/get.php?resid=ssid01');">Onapsis.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saplib.com/download-free-onapsis-sap-security-in-depth-publication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless LAN Security Policy Checklist</title>
		<link>http://www.saplib.com/wireless-lan-security-policy-checklist/</link>
		<comments>http://www.saplib.com/wireless-lan-security-policy-checklist/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 22:52:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Checklist]]></category>
		<category><![CDATA[Document]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.saplib.com/?p=174</guid>
		<description><![CDATA[Download Free Wireless LAN Security Policy Checklist - Identify who may use WLAN technology in an company - Identify whether Internet access is required - Describe who can install access points and other wireless equipment - Provide limitations on the location of and physical security for access points - Describe the type of information that [...]]]></description>
			<content:encoded><![CDATA[<p>
<IMG SRC="http://www.saplib.com/files/wireless-lan-security-policy-checklist.jpg" alt="Download Free Wireless LAN Security Policy Checklist"><br />
Download Free Wireless LAN Security Policy Checklist<br />
- Identify who may use WLAN technology in an company<br />
- Identify whether Internet access is required<br />
- Describe who can install access points and other wireless equipment<br />
- Provide limitations on the location of and physical security for access points<br />
- Describe the type of information that may be sent over wireless links<br />
- Describe conditions under which wireless devices are allowed<span id="more-174"></span><br />
- Define standard security settings for access points<br />
- Describe limitations on how the wireless device may be used, such as location<br />
- Describe the hardware and software configuration of all wireless devices<br />
- Provide guidelines on reporting losses of wireless devices and security incidents<br />
- Provide guidelines for the protection of wireless clients to minimize/reduce theft<br />
- Provide guidelines on the use of encryption and key management<br />
- Define the frequency and scope of security assessments to include access point discovery.</p>
<p><a href="http://www.saplib.com/files/wireless-lan-security-policy-checklist.xls" onclick="javascript:pageTracker._trackPageview('/downloads/files/wireless-lan-security-policy-checklist.xls');">Download</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.saplib.com/wireless-lan-security-policy-checklist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

