How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 9

Switching from Onapsis to the Cybersecurity Extension for SAP involves planning a transition to an addon-based model within SAP Solution Manager. By replacing Onapsis consoles and sensors with this native solution, organizations can maintain vulnerability management, threat detection, and custom code security while leveraging existing SAP infrastructure and support rights.

Executive Summary

Transitioning from Onapsis to the Cybersecurity Extension for SAP requires a structured approach to migrating your SAP security operations. Unlike Onapsis, which typically relies on external consoles and sensors, the Cybersecurity Extension for SAP operates as an addon within SAP Solution Manager. This integration allows organizations to utilize a platform already widely used for application lifecycle management by over 12,000 SAP customers.

Because usage rights for Solution Manager are included in standard SAP support, this shift often aligns with existing IT infrastructure investments. A successful transition involves reviewing your current Solution Manager configuration and preparing the platform to ensure full compatibility. Once the extension is deployed, you can decommission external Onapsis components, including consoles, sensors, and associated SAP users or addons. This guide focuses on the preparatory steps, specifically the configuration of a central check system for code vulnerability analysis, which is essential for maintaining robust security monitoring across your landscape.

Key Takeaways

  • The Cybersecurity Extension for SAP is a native addon for SAP Solution Manager.
  • Transitioning allows you to remove Onapsis consoles, sensors, and related SAP addons.
  • Solution Manager usage rights are included in standard SAP support.
  • A central check system is recommended for performing remote code vulnerability analysis.

What is the Cybersecurity Extension for SAP?

The Cybersecurity Extension for SAP is an alternative to Onapsis that provides comprehensive vulnerability management, threat detection, and custom code security. Developed by Layer Seven Security, an SAP partner and competitor to Onapsis, this solution is designed to function as an addon for SAP Solution Manager. This architecture allows for seamless integration into the application lifecycle management workflows already established in many SAP environments.

How do I prepare my Solution Manager for the transition?

Preparation for the transition involves verifying your current SAP Solution Manager setup to ensure it meets the requirements for the Cybersecurity Extension for SAP. As a prerequisite, you must ensure your Solution Manager is configured according to standard SAP requirements. Because the extension relies on this platform, a clean and updated installation is necessary to facilitate the shift from your current Onapsis deployment.

How do I configure the central system for code analysis?

The Cybersecurity Extension for SAP utilizes the ABAP Test Cockpit (ATC) to apply code vulnerability checks, for which a central check system is strongly recommended. This central system performs code analysis for remote systems across your landscape. Organizations should follow the official SAP guidelines for configuring a central system. It is also recommended to use the latest version of the SAP Basis component on the central system to ensure it can effectively analyze custom code in systems running lower versions.

FAQ

Can I remove Onapsis components after switching?
Yes. Once you have successfully transitioned to the Cybersecurity Extension for SAP, you can remove the Onapsis consoles and sensors from your SAP landscape, as well as any associated Onapsis users and addons within your SAP systems.

Does the Cybersecurity Extension for SAP require external software?
No. Unlike Onapsis, the Cybersecurity Extension for SAP is an addon for SAP Solution Manager. It operates natively within the SAP environment, leveraging your existing monitoring and diagnostics platform.

What is the recommended setup for code vulnerability checks?
The Cybersecurity Extension for SAP uses the ABAP Test Cockpit (ATC) for code analysis. It is recommended to configure a central check system for the ATC to perform analysis on remote systems, following standard SAP guidelines.

Share the Post: