Why publishing an SAP Fiori front-end server behind a Web Dispatcher is the wrong external-access design: what the ICF service tree exposes, what ICMAD and CVE-2025-31324 prove about pre-authentication reachability, and the layered architecture that keeps the ICM unreachable.
The SAP DRC authorization footprint for the French e-invoicing mandate: EDO_PROC, EDO_ORG, EDO_BUK, F_SRF_RNTM and the OAuth object S_OA2C_USE, why the org-level conversion is usually unnecessary, and a role model that survives September 2026.
What IT general controls (ITGC) are, the core domains (access, change management, IT operations, development), how they map to SOX, ISAE 3402 and SOC reports, and how to get audit-ready without over-engineering.
A practical guide to SAP platform cybersecurity beyond authorizations: SAP Security Notes and patching, system hardening, gateway and RFC security (UCON), secure communication (SNC), and monitoring with the Security Audit Log.
A consultant's guide to SAP GRC Access Control: the ARA, ARM, BRM and EAM components, how they fit together, common implementation pitfalls, and when a full GRC deployment is justified versus a lighter alternative.
Implementing the SP21 Firefighter session change (SAP Note 3318927) on GRCPINW V1100 plugin systems: prerequisites, the follow-on notes you actually need, and fixes for locking, logon pad and short-dump issues in decentralized EAM.
SAP Firefighter role design guide: scope, ownership, logging, SoD implications and compliance. Best practices for emergency access management in SAP GRC and S/4HANA.
SAP S/4HANA migration guide, Greenfield, Brownfield and Selective compared on cost, timeline and risk. Authorization redesign and the 2027 ECC deadline. Geneva, Switzerland.