As organizations expand beyond SAP into hybrid ecosystems of SaaS and LoB applications, governance becomes fragmented and inconsistent. Traditional access control approaches no longer suffice, requiring a shift toward holistic Business Application Risk Management that leverages integrated technologies, automation, and real-time analytics to ensure consistent policy enforcement and visibility.
Martin Kuppinger, Founder and Distinguished Analyst at KuppingerCole Analysts will explore the evolution from SAP-centric access control to unified governance across heterogeneous environments. He will highlight key findings from Leadership Compass reports, SAP Access Control & Security and Business Application Risk Management, discuss emerging trends, outline essential solution capabilities, and provide practical guidance on selecting technologies for effective risk management.
Who Should Attend:
This webinar is designed for IT security leaders, IAM professionals, and enterprise architects seeking to modernize governance strategies across SAP and non-SAP environments.
Welcome everyone to our KuppingerCole Analysts webinar, Unified Governance Across SAP and Business Applications. In this webinar I'll talk about the markets for managing access governance, mainly access governance, but also to a certain extent security when we look at SAP for both SAP and for other types of business applications. So the focus will be basically really more on the access control side, but as I said it will be a little bit expanded. This is based on work I did for two leadership compass reports we published earlier this year.
The one focusing on access control and security for SAP, the other more broad on application risk management across sort of a more diverse but rather a genius set of line of business applications. So that is what I will do for the next hour and before we go into detail, a little bit of housekeeping here. Audio is controlled centrally, nothing to do from your end. We will run polls, two polls concretely, one at the beginning, one towards the end. There will be a Q&A session so you can ask questions at any time just at the lower right edge of the window is the webinar.
You'll find a questions section and there you can ask questions. The more questions we have, the more interesting the Q&A session will be. Last and least, we are recording the webinar and we'll make the slides as well as the recording available soon after the webinar. With that being said, I'd like to directly come to the first poll. And this is the question of who is responsible for application access control? So who can access SOD controls, all that stuff, risks, critical access from a risk perspective across the line of business applications.
So are these different departments, depending on the application. So someone for SAP, others for let's say Salesforce, Workday or whatever, or is it the SAP department? Is it the IAM department or are it others? The poll will be open for a bit so you can take your time to respond to this poll. And from there we go forward to, I just lost my mouse for whichever reason, we go forward to the agenda.
So here, as I've said, it will be simply two parts because I'm the only speaker today. The one is look at unified governance across all line of business applications and beyond. So not just governance. And then the Q&A part. And this is a slide I brought up a longer while ago, but I think it's still very relevant. What we have as a fundamental shift is that we see to some more vendors and obviously the shift from on-premises to hybrid, maybe to full SaaS. So overall, more and more of the line of business applications are SaaS applications.
We see the push of SAP with RISE and other initiatives to move their customer base into SaaS. Reality, I think, is that it's still a bit more on the hybrid side in many environments with a lot of SAP environments still being really remote or more traditionally on-premises. But tendencies moving it to SaaS in the longer term, we probably will have more SaaS, even while there's also a bit of a tendency we observe in the market that the cloud-first tendency may be not as popular anymore as it has been a couple of years ago. And we also see this shift to more vendors.
So not just SAP for most organizations, but other players coming into the space in the line of business applications area, like I mentioned some of them. And there's a growing number. So there's obviously a bit of a change from what we have seen before. It clearly will remain to be seen. So there was this SaaSocalypse term. I don't think it's a very good one, because it's not a precise and correct term. But clearly, there will be changes also on the way how we deal with applications, how applications are built, how applications are maintained.
Personally, I believe the impact will be more on how do we do UX changes, how do we integrate, et cetera, where AI can help us massively. The idea of, oh, I built my new CRM this weekend with some nice prompts. I think this is a bit naive, because that not even is an MVP, a minimal viable product. It's just a nice try. And from there to a product that you or a solution that you fully can maintain that has all the integrations, all the capabilities, it's a long, long, long way. And I'm not exactly sure whether this is the right way to proceed, but that's a bit of a different topic.
So depending on that strategy for your line of business applications, there are also consequences on how do you manage access control, how do you manage application risks, how do you manage security across these applications? So what we see here is that a lot of organizations have SAP Access Control, or many still call it SAP GRC deployed, so the access control products, where we see this transition to the upcoming cloud version, just SAP Cloud IHE.
There's, in the sense of when you take the traditional access control, there's a bit of a, we could call it an end-of-life challenge. SAP clearly won't call it that way. Depending from a customer perspective, it might be that this is more of a move to a new product than just a simple migration that SAP claims it is. I think at the end, it remains a bit to be seen. But clearly, there's a situation where we have sort of an infrastructure that is changing.
And depending on whether your line of business strategy is very SAP-focused or is very hybrid, you may lean more towards solutions that support a lot of different types of applications so that you can build a central governance layer, or you may lean more towards the SAP-specific solutions from SAP or from other vendors. Also, depending on, is it more fully SaaS right now? Is it more on the hybrid or on the on-prem side?
Also, that has an impact on what you are doing. The main point I'd like to make here is, you need to think about the alternatives you have. There are different options you have. There's another wrong or right in that, but you have various ways you can take in this strategy. And I think this is something you definitely need to be aware.
Obviously, there are things which make it more difficult. So how easily can you, from both the technical and the licensing perspective, potentially move away from an SAP access control? How important is SAP? How is your internal organization? So is there an SAP organizational silo that insists on doing all with what SAP says? Or is it that you have a more open strategy? That also goes back to the poll where I asked about the ownership. The more flexible you are in the ownership, the more centralized you are in ownership.
So not having an SAP silo and SAP kingdom, but having more cross-LB responsibility or something that is close to the business processes. So a responsibility for everything that's related to finance, to HR, or whatever else. Then you're potentially more flexible in that, not needing to fight fights around organizational responsibility, et cetera, here. But basically, there are different ways, different routes you can take. This is something you need to surely carefully and thoroughly analyze. But there are different ways forward you can take.
So your strategy online of business applications, both in the sense of which types of vendors, how heterogeneous you go, and how you deploy it, also impacts your decisions around the applications you use to manage access risk. What I strongly, strongly recommend is always going for centralized governance layers. So the more centralized and more consistent the governance layer is across different types of solutions you have.
And probably also beyond line of business towards at least the standard IAM field, where you look at whatever Azure or Enter ID and other types of services, the better you can handle your risks. When you go into siloed governance, you always have a challenge in understanding the risks across different silos you're governing. On the other hand, obviously, you have some specific requirements regarding the depth of information you need, how deep you need to look into it.
So for the applications that are mostly in scope of the auditors, your focus must be, or your ability to deliver information and to implement the governance must be deeper than for some of the other applications. It becomes a bit more and more similar when you look at the level of generic security risks, because then everything is impacted. So what I definitely recommend is think about it. Not just say, okay, this is the route we always took. We just continue following that route. I think it's more complex and it's a good time right now with all the changes to look at what is the right forward.
I brought up some questions here. As I've said, I think you need to think about what is in place. So is it access control with the change of the version? So going to HANA, it means it's a change of the version. You can argue it's an end of life. At the new version, you can say it's a new tool or not. I think it depends on your perspective. As I've said before, you may have focused on SAP Cloud IAG already. You may have a mix of it. You may have another vendor solution, nothing in place, an IGA tool, whatever. Depending on that, you always need to ask, so what will be your future requirements?
I think this is the main question. Always start these requirements with required capabilities. Never start from the tool perspective, but start from what do you need? Where are you heading? That's what I said before with your different types of tools in this application space. What do you have? Then think about the capabilities that are lacking now, that are maybe lacking in the future. Think about what is the best fit for that to deliver the capabilities you will really need. That might be a single solution. That might be a mix of solutions.
So there's, again, there's not the simple answer on that where you say, okay, this is the best tool for that or that. It depends, again, on your organization. So is there something you do specific for SAP and then the rest of the world? Or is it more integrated? It depends on your state, on your strategy, all these aspects. But it's worth to think about what is the right way forward. And then we clearly have this, we can call it application access governance or application risk management. There are different terms.
The market and none of these terms really has established for these solutions that are focusing on access governance, application risk across the line of business applications. And on the other hand, we have the traditional IGA, so the identity governance and administration tools. And for this IGA part, it is that we have to get a common capability to use lifecycle provision and also access governance across a wide range of applications, including very frequently a certain level of line of business applications.
So there's an obvious overlap with provisioning free refund on both ends, user lifecycle, access reviews, and SOD controls as well, where IGA leans into a broader support for applications beyond just line of business applications, while the application access governance, depending on from which end they come, they may have SAP-specific features. For instance, they may have books of rules, very common. They have capabilities like specific role optimization for line of business application. Something we, by the way, see emerge also on the other end of the spectrum more and more.
So it's nothing that is specifically unique. So the book of rules and the added SAP-specific features, like automated definition of role catalogs and stuff like that, there are certain things and also sometimes leaning into SAP security that are really specific for the application access governance side. And they are the same. It might be sufficient to have IGA probably more than the other side, depending on how strong your IGA solution is and what you need from the application access governance side.
It's less likely that your application access governance, application risk management can serve everything. Meanwhile, we see some of the vendors nowadays leaning more into the IGA space, and we see vendors that obviously can do both. So with that, we also need to look at a bigger story behind it. The bigger story is that it's not just identity and access management and access controls. So this is part of it. But when you look at SAP security, then there are things that go beyond that. We can look in other areas.
And when we go bottom to up, then we have the system security and hardening level, where we obviously have SAP-specific solutions from SAP, from third parties, as well as an operating system level hardening. We have threat intelligence and response from SAP, from third-party SAP-specific solutions. We have the standard SIEM, SOAR, XDR tools in the market. Same for code security. A lot of things going on, obviously, here.
Nowadays, I think that will be one of these fields that are very much under change over the next couple of weeks, months, and maybe years. For configuration transport security, this is clearly very SAP-specific.
While, for instance, user management, authentication, identity access also is very commonly a third-party thing. And then when we look at the highest level, the process security, process controls, that is where we see, again, a spectrum of solutions that are centered around SAP.
But also, we see more and more solutions across the line of business continuous controls monitoring. But also, when we go more into IT security, more the signal sharing about risks, about events, alerts that occur at that level. So aside of the access control piece, there's another area, another angle, which goes really into SAP security.
And that also means that there's a perspective of saying, okay, we have something that manages risk for SAP, RASA, comprehensive from a security perspective, from an identity access perspective, and so the SUT part, et cetera, up to potentially process controls. Or you say, I have different types of solutions in which level of integration ever that I run for different types of sort of security layers or capability areas. So when we then look at GRC and security for SAP and beyond on a broader scale, then we have different ways to tackle that.
And one way we can choose is that we say, okay, we do this by basically RASA isolated. So we have some tools for SAP security, we have some for, we have one for the SAP GRC, let's call it GRC right now, the access control stuff. The same for the non-SAP stuff and for non-SAP security. That is usually a consequence of more a tactical decision for certain tools. So really a tool focus, not a holistic risk management approach. This isolated approach is something I don't honestly like. You can do it a bit more SAP siloed.
So you have something integrated covers SAP access control, covers SAP security while you have the specific tools on the access control side for SAP GRC and your standard security tools around that. So if you have a strong focus on SAP from a regulatory compliance perspective, from an audit perspective, that may be fine because you have this well covered, but it's still not a holistic risk management here. The other option then would be to split more around GRC or to integrate around GRC, but split on security.
So very specific security capabilities for SAP makes sense because there's a lot of specific stuff to solve there and a lot of specific insight needed. And you have your more generic security for sort of the rest of the world. While you go for an integrated approach and access control on GRC, which helps you at least to have a comprehensive perspective on your business risk in this area. Last but not least, you can move forward and say, okay, you already do it more holistically and try to have an integrated approach.
I think this is, to be fair, this is relatively tricky when it comes to the full range of non-SAP security because this is really a huge area when we look at all the cyber security tools. And there are clearly things you potentially can do in an integrated manner. It still doesn't require multiple integrated tools. What you can do mostly is really trying to integrate at the risk level, the risk management level, to have a consistent risk understanding across everything. That already would be a significant step forward, but it's not a single tool you will have.
When we look at SAP security then, and this is probably something which is more valuable to look at when you gain access after the webinar to the slide deck and the recording because I don't want to read out a complex metrics here. But what I basically did here is a maturity level metrics for SAP security following the standard CMMI approach from initial to managed, defined, quantitatively managed, to optimizing, and across the different areas.
I think this is worth to look at and also maybe use it as a bit of a guidance and something to look at when you look at your own organization, where you stand with your technology. How good are you in system security hardening? What about code security? What about the identity access management piece? Do you have real-time analytics here and context aware access, all the other stuff? That is more something I give to you later for looking at it later on.
What we then did, as I've said recently, was we did our leadership compass documents, the one on SAP access control and security, the other one on application access, or application risk management across a more diverse field of line of business applications. We decided to do that split because we see the typically SAP buyer that then tends to lean beyond access control into security. We also see that a lot of these specialized solutions covers access control and security aspect. We see the others that say our focus is more the access control but beyond SAP.
When you remember back the charts, then the one would lean more into... Let me quickly go back one more here. The one looks basically more on the first one, the SAP access control and security on this picture, where there's a SAP siloed but a consistent approach across SAP, while the other looks more at that approach, saying I look at integration at the application layer but don't look that much at the security layer. This is basically where the perspectives, where the split comes from when I look at these leadership compass reports.
With that, what did we look at? This is not a comprehensive list, the list of criteria for a leadership compass is way longer.
Obviously, we look at the deployment models. We look at a very comprehensive support for the SAP environment, including the newer, not really new stuff like BGP and others, but also looking at the SaaS suite, more success factors, Concur, stuff like that and others. We look at the ability to manage entitlements and roles and the handling of these access management, including then moving into more emergency access pieces and other things.
A certain level of lifecycle management, that I already mentioned, firefighter emergency access, S&T controls, surely, and then delivering this all with good reporting and dashboards, as well as supporting access review and certification. These were basically more the main set of capabilities. Then there are quite a number of advanced capabilities, so more advanced hybrid pure SaaS support, role optimization, some support, some level of non-app and SAP Cloud solution support. What can you do there? It's partially touched here, but this is increasingly important.
Also thinking about, do you need solutions that then over time can support other line of business applications? How does this integrate with IGA? They're looking at the security aspects, hardening, threat detection, data management aspects for critical data, and also UX aspects we covered here. These are some of the main criteria, but I think the best way is always to look at the leadership compass, where you go way more into detail on these various aspects.
The same we did for the line of business application risk management, where, again, deployment models are important, where the comprehensive support beyond SAP to non-SAP applications is important, where it's about roles, entitlements, access risk analysis, access review, SODs, and again, reporting and dashboarding.
Again, we then had some advanced capabilities like role optimization, so support, good support for non-IPAP system, IGA integration, potentially also here a certain level of firefighter super user management, and especially looking also at more advanced analytics and machine learning support to analyze entitlements. So, of highest reliance here, this is a bit more redundant.
Obviously, it's a comprehensive system support integration, as well as a role and entitlement management. These are key capabilities, and then the optimization, the analytics of roles, which become more and more important, which also are something which is part of this identity, visibility, and intelligence platform market segment, which looks into supporting and understanding entitlements, finding outliers, optimizing them, et cetera. That basically led then to our analysis in this leadership compass. The one on the left-hand side is really SAP-centric.
The other is the broader cross-line of business application support. We see that both markets are interestingly depicted by having relatively few vendors, these markets.
So, compared to other market segments, it's still a very specialized, very niche market, but quite a number of really specialized players in both areas available. It's interesting to see that aside of specialists like SAP and Passlock, we see some of the IGA vendors entering this field as well, some of them also having made acquisitions in that space, like Delinia, like SailPoint, others having had a focus on that from the very beginning, like Savion. We also see specialized vendors from the iWeb space, like Nexus, emerging.
So, we see quite some interest because of non-specialists, but more generic players that come up with strong capabilities in these market segments. As usual, and I think this is really important for, and I would dare to say this is something to keep in mind for every analyst firm's market analysis. This helps you in gaining an understanding and a quick perspective on who are the players in the market, but don't just lean towards the ones in the upper right.
So, when you do a product selection, the starting point again is capabilities. What do you need? What do you have? Where are your gaps? This is something which can be analyzed very methodologically, and this is your starting point that helps you understand what you really need. And then go into the details of these reports.
So, our reports are rather long, providing insights per vendor, looking at different types of dimensions. So, also within the capability areas, where does the vendor axle?
So, which means some of the vendors which are more to the left-hand side might be extremely complementary to other players. So, if you take a security bridge or a web IT with specific angles on SAP security, they might be really complementary to others.
So, go deeper into it and understand and think about, can I work with one? Do I need more than one? What is the right mix of it? Look at alternative sort of ways to solve the entire challenge, like whatever Nexus provides, like to an extent PointShare provides, like SAP has reliable R&D. Look at the ones that have a very strong consultancy behind, like a compliance now.
So, really take a broader perspective on that, because that helps you really to make up your mind to figure out the right type of solutions. So, this is basically what I wanted to share with you today, and it brings us to the second poll, which we'll leave open for a bit.
As I see, we don't have questions yet. So, use the opportunity to ask me questions, so that we can look at these questions.
As I said, we'll leave this open, and in parallel, I basically will be, so to speak, open for the Q&A session, hoping that there will be a few questions coming in. So, if there's anything you're specifically interested, go to the questions area on the lower right edge, respond to these questions. But I'm looking forward to at least having some questions there I can respond to.
Otherwise, knowing at least in Germany, we are ahead of a long weekend with a public holiday tomorrow. Some of you may want to head out. There's a lot of research we provide on this.
So, we have the leadership components. We have a lot of leadership components.
So, we have really a lot of different types of research here, all the buyer's components covering products. Don't miss looking at our different types of services, which immediately brings us to the membership.
So, we have our advisor, by the way, also helping you in the tools choice with our knowledge about the market, about a structured approach on it. Other events coming up in the September to February timeframe, we have a couple of one-day events, like the Identity Fabric Impact Day.
And yeah, that's it. I don't see that any questions come in.
So, no questions asked, no questions answered in that sense. You still can reach me.
So, at any time, reach out to me via LinkedIn, via mail. So, in that sense, thank you very much for your time and hope to have you soon back on one of our other webinars.
See All Locations
See All Locations