SlideShare una empresa de Scribd logo
1 de 10
PUBLIC
Andreas Hauke
October,2017
Address Evolving Security Challenges in
Commerce
2PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
“Security is disruptive by definition”
Security as main challenge for the industry
3PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
“New regulations like GDPR or the Chinese
Cyber Security law forces companies all
over the industries to rethink their approach.
Also the technology shifts are influencing
the view on security”
Why security?
4PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
How to tackle security with an overall approach – Secure SDL
5PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
A typical Commerce scenario
Consumer
interacts with the
Storefront
Orders
processed in
Commerce
Data is persisted
in DB
Admin / Product- or
Content Manager
uses Commerce
Backoffice
UI handles the
interaction
{y}
6PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
Features in Commerce to support security
Authentication Authorization Encryption Advanced security settings
§ High security password
storage using PBKF2 (NIST
proofed)
§ SSO with SAML and other
protocols
§ MFA via SAP Cloud Platform
Identity Authentication
§ Business roles in Backoffice
§ OAuth2 for headless
Commerce (protection for
REST service)
§ Permission services
framework
§ TLS everywhere
§ Transparent Attribute
Encryption
§ DBs, e.g. Hana, support
Encryption
§ Advanced Security Filters, e.g.
to protect against clickjacking
§ Output encoding libaries
shipped with platform
§ Advanced security settings in
Tomcat for security headers
7PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
Features in Commerce to support data protection
Consent Loggingof changes Transparency Data portability
§ Consent management in the
storefront for registered and
anonymous users
§ Audit logging of changes to
attributes containing PII
together with advanced
reporting functionality in
Backoffice (Future Release)
§ Data annotation framework
§ Advanced reporting
functionality for PII in
Backoffice (Future Release)
§ Impex
§ OCC - REST APIs
8PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
Where to get help? – help.hybris.com
9PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
“Security must be not a burden in
development and operations. It should be
integrated in the normal software lifecycle
using methodologies and automation”
Blameless security
10PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ
QUESTIONS
COMMENTS
FEEDBACK
It is your turn

Más contenido relacionado

Más de SAP Customer Experience

The Perfect Store Execution (Picture of Success)
The Perfect Store Execution (Picture of Success)The Perfect Store Execution (Picture of Success)
The Perfect Store Execution (Picture of Success)SAP Customer Experience
 
The Consumer-Driven Digital Economy: Creating value in a digital world where ...
The Consumer-Driven Digital Economy: Creating value in a digital world where ...The Consumer-Driven Digital Economy: Creating value in a digital world where ...
The Consumer-Driven Digital Economy: Creating value in a digital world where ...SAP Customer Experience
 
How to create Magic Moments for your customers with Process Mining
How to create Magic Moments for your customers with Process MiningHow to create Magic Moments for your customers with Process Mining
How to create Magic Moments for your customers with Process MiningSAP Customer Experience
 
Empower Store Associates with Mobile Apps to Reinvent the In-Store Experience
Empower Store Associates with Mobile Apps to Reinvent the In-Store ExperienceEmpower Store Associates with Mobile Apps to Reinvent the In-Store Experience
Empower Store Associates with Mobile Apps to Reinvent the In-Store ExperienceSAP Customer Experience
 
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...SAP Customer Experience
 
Data-Driven Desicision-Making with Mindray Medical International Co.
Data-Driven Desicision-Making with Mindray Medical International Co.Data-Driven Desicision-Making with Mindray Medical International Co.
Data-Driven Desicision-Making with Mindray Medical International Co.SAP Customer Experience
 
Protect Sponsorship Business Value by Measuring What You Pay For
Protect Sponsorship Business Value by Measuring What You Pay ForProtect Sponsorship Business Value by Measuring What You Pay For
Protect Sponsorship Business Value by Measuring What You Pay ForSAP Customer Experience
 
Monetizing Microsoft High Volume Revenue using SAP Hybris Billing
Monetizing Microsoft High Volume Revenue using SAP Hybris BillingMonetizing Microsoft High Volume Revenue using SAP Hybris Billing
Monetizing Microsoft High Volume Revenue using SAP Hybris BillingSAP Customer Experience
 
Grupo DIA advancing digital transformation
Grupo DIA advancing digital transformationGrupo DIA advancing digital transformation
Grupo DIA advancing digital transformationSAP Customer Experience
 
Grupo DIA advancing digital transformation
Grupo DIA advancing digital transformationGrupo DIA advancing digital transformation
Grupo DIA advancing digital transformationSAP Customer Experience
 
Fuel Trusted Customer Relationships with Personalization, Preference & Privacy
Fuel Trusted Customer Relationships with Personalization, Preference & PrivacyFuel Trusted Customer Relationships with Personalization, Preference & Privacy
Fuel Trusted Customer Relationships with Personalization, Preference & PrivacySAP Customer Experience
 
Improve Customer Experience in the Cognitive and 5G Era
Improve Customer Experience in the Cognitive and 5G EraImprove Customer Experience in the Cognitive and 5G Era
Improve Customer Experience in the Cognitive and 5G EraSAP Customer Experience
 
Smart Adoption Methodology for SAP Hybris
Smart Adoption Methodology for SAP HybrisSmart Adoption Methodology for SAP Hybris
Smart Adoption Methodology for SAP HybrisSAP Customer Experience
 
Implementation of Hybris Billing at PostNL
Implementation of Hybris Billing at PostNLImplementation of Hybris Billing at PostNL
Implementation of Hybris Billing at PostNLSAP Customer Experience
 
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...SAP Customer Experience
 
Bavaria Becoming the Smartest Beer Company Using Technology
Bavaria Becoming the Smartest Beer Company Using TechnologyBavaria Becoming the Smartest Beer Company Using Technology
Bavaria Becoming the Smartest Beer Company Using TechnologySAP Customer Experience
 
Transforming its Customer Engagement Approach for Global Harmonization
Transforming its Customer Engagement Approach for Global HarmonizationTransforming its Customer Engagement Approach for Global Harmonization
Transforming its Customer Engagement Approach for Global HarmonizationSAP Customer Experience
 
Succeed with Digital Transformation in a Traditional Legacy Business
Succeed with Digital Transformation in a Traditional Legacy BusinessSucceed with Digital Transformation in a Traditional Legacy Business
Succeed with Digital Transformation in a Traditional Legacy BusinessSAP Customer Experience
 
Palladium Hotel Group A Digital Transformation Story
Palladium Hotel Group A Digital Transformation StoryPalladium Hotel Group A Digital Transformation Story
Palladium Hotel Group A Digital Transformation StorySAP Customer Experience
 

Más de SAP Customer Experience (20)

The Perfect Store Execution (Picture of Success)
The Perfect Store Execution (Picture of Success)The Perfect Store Execution (Picture of Success)
The Perfect Store Execution (Picture of Success)
 
The Consumer-Driven Digital Economy: Creating value in a digital world where ...
The Consumer-Driven Digital Economy: Creating value in a digital world where ...The Consumer-Driven Digital Economy: Creating value in a digital world where ...
The Consumer-Driven Digital Economy: Creating value in a digital world where ...
 
How to create Magic Moments for your customers with Process Mining
How to create Magic Moments for your customers with Process MiningHow to create Magic Moments for your customers with Process Mining
How to create Magic Moments for your customers with Process Mining
 
Empower Store Associates with Mobile Apps to Reinvent the In-Store Experience
Empower Store Associates with Mobile Apps to Reinvent the In-Store ExperienceEmpower Store Associates with Mobile Apps to Reinvent the In-Store Experience
Empower Store Associates with Mobile Apps to Reinvent the In-Store Experience
 
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...
Unleash Your B2X Potential with Flieger Plug & Play Based on SAP Hybris Solut...
 
Data-Driven Desicision-Making with Mindray Medical International Co.
Data-Driven Desicision-Making with Mindray Medical International Co.Data-Driven Desicision-Making with Mindray Medical International Co.
Data-Driven Desicision-Making with Mindray Medical International Co.
 
Protect Sponsorship Business Value by Measuring What You Pay For
Protect Sponsorship Business Value by Measuring What You Pay ForProtect Sponsorship Business Value by Measuring What You Pay For
Protect Sponsorship Business Value by Measuring What You Pay For
 
Monetizing Microsoft High Volume Revenue using SAP Hybris Billing
Monetizing Microsoft High Volume Revenue using SAP Hybris BillingMonetizing Microsoft High Volume Revenue using SAP Hybris Billing
Monetizing Microsoft High Volume Revenue using SAP Hybris Billing
 
Grupo DIA advancing digital transformation
Grupo DIA advancing digital transformationGrupo DIA advancing digital transformation
Grupo DIA advancing digital transformation
 
Grupo DIA advancing digital transformation
Grupo DIA advancing digital transformationGrupo DIA advancing digital transformation
Grupo DIA advancing digital transformation
 
Fuel Trusted Customer Relationships with Personalization, Preference & Privacy
Fuel Trusted Customer Relationships with Personalization, Preference & PrivacyFuel Trusted Customer Relationships with Personalization, Preference & Privacy
Fuel Trusted Customer Relationships with Personalization, Preference & Privacy
 
Explore the Impact of AI on E-Commerce
Explore the Impact of AI on E-CommerceExplore the Impact of AI on E-Commerce
Explore the Impact of AI on E-Commerce
 
Improve Customer Experience in the Cognitive and 5G Era
Improve Customer Experience in the Cognitive and 5G EraImprove Customer Experience in the Cognitive and 5G Era
Improve Customer Experience in the Cognitive and 5G Era
 
Smart Adoption Methodology for SAP Hybris
Smart Adoption Methodology for SAP HybrisSmart Adoption Methodology for SAP Hybris
Smart Adoption Methodology for SAP Hybris
 
Implementation of Hybris Billing at PostNL
Implementation of Hybris Billing at PostNLImplementation of Hybris Billing at PostNL
Implementation of Hybris Billing at PostNL
 
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...
Go direct to consumer: How Trek brings bikes and gear directly to its B2C cus...
 
Bavaria Becoming the Smartest Beer Company Using Technology
Bavaria Becoming the Smartest Beer Company Using TechnologyBavaria Becoming the Smartest Beer Company Using Technology
Bavaria Becoming the Smartest Beer Company Using Technology
 
Transforming its Customer Engagement Approach for Global Harmonization
Transforming its Customer Engagement Approach for Global HarmonizationTransforming its Customer Engagement Approach for Global Harmonization
Transforming its Customer Engagement Approach for Global Harmonization
 
Succeed with Digital Transformation in a Traditional Legacy Business
Succeed with Digital Transformation in a Traditional Legacy BusinessSucceed with Digital Transformation in a Traditional Legacy Business
Succeed with Digital Transformation in a Traditional Legacy Business
 
Palladium Hotel Group A Digital Transformation Story
Palladium Hotel Group A Digital Transformation StoryPalladium Hotel Group A Digital Transformation Story
Palladium Hotel Group A Digital Transformation Story
 

Address Evolving Security Challenges in Commerce

  • 1. PUBLIC Andreas Hauke October,2017 Address Evolving Security Challenges in Commerce
  • 2. 2PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ “Security is disruptive by definition” Security as main challenge for the industry
  • 3. 3PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ “New regulations like GDPR or the Chinese Cyber Security law forces companies all over the industries to rethink their approach. Also the technology shifts are influencing the view on security” Why security?
  • 4. 4PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ How to tackle security with an overall approach – Secure SDL
  • 5. 5PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ A typical Commerce scenario Consumer interacts with the Storefront Orders processed in Commerce Data is persisted in DB Admin / Product- or Content Manager uses Commerce Backoffice UI handles the interaction {y}
  • 6. 6PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ Features in Commerce to support security Authentication Authorization Encryption Advanced security settings § High security password storage using PBKF2 (NIST proofed) § SSO with SAML and other protocols § MFA via SAP Cloud Platform Identity Authentication § Business roles in Backoffice § OAuth2 for headless Commerce (protection for REST service) § Permission services framework § TLS everywhere § Transparent Attribute Encryption § DBs, e.g. Hana, support Encryption § Advanced Security Filters, e.g. to protect against clickjacking § Output encoding libaries shipped with platform § Advanced security settings in Tomcat for security headers
  • 7. 7PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ Features in Commerce to support data protection Consent Loggingof changes Transparency Data portability § Consent management in the storefront for registered and anonymous users § Audit logging of changes to attributes containing PII together with advanced reporting functionality in Backoffice (Future Release) § Data annotation framework § Advanced reporting functionality for PII in Backoffice (Future Release) § Impex § OCC - REST APIs
  • 8. 8PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ Where to get help? – help.hybris.com
  • 9. 9PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ “Security must be not a burden in development and operations. It should be integrated in the normal software lifecycle using methodologies and automation” Blameless security
  • 10. 10PUBLIC© 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ QUESTIONS COMMENTS FEEDBACK It is your turn