In an SAP profile parameter review, "not found" means the system never returned the parameter and nothing was measured, "not set" means the system returned it and the answer was empty, and "zero" is a real value that for many settings means the control is switched off. The RedRays Security Platform keeps the three apart.
They are easy to confuse because all three arrive at the reader as an absence of a number. A spreadsheet cell is blank in all three cases, and the person who filled it in has usually forgotten which one it was by the time anybody asks.
| What happened | What can be concluded | What remediation follows |
|---|---|---|
| The parameter was not among those the system returned | Nothing about the setting. No comparison was made | Find out why it did not come back before anything else |
| The system returned the parameter and the value was empty | A measurement. Something that should name a value names nothing | Set the value the parameter is meant to carry |
The system returned 0 |
A measurement. For several settings, zero means never or unlimited | Decide whether never is the intended policy |
| The system returned a value that did not meet the expected condition | A measurement, and an ordinary finding | Change the value |
Not Found means the parameter this entry names was not among the parameters the system returned. That is the whole of the claim.
It is not a statement that the setting is safe. It is not a statement that the setting is unsafe. It is not a statement that the parameter sits at its kernel default, because a parameter that did not come back had neither of its values read. And it is not a statement about the release, because the review does not ask the system which release it is.
Because nothing was measured, no verdict is computed and no remediation is offered. Withholding the remediation is deliberate: an instruction to change a setting nobody could read is advice about a fact not in evidence. The row says, in the product's own words, that the parameter was not returned by the system, that this is not the same as a safe value, and that nothing was measured so nothing was judged.
A parameter that never came back is shown as unmeasured, and no remediation is offered for a setting nobody could read.
The honest limit. Not Found carries two meanings that the review does not separate: this release of SAP does not have the parameter, and the read did not deliver it. Both are worth chasing, and they have different owners. A catalogue entry for a parameter your release genuinely does not have is a catalogue question. A parameter your release does have that did not come back is a question about the read.
It means the system was asked, answered, and the answer contained nothing. That is a measurement with a verdict behind it, and it is usually a finding: a parameter that is supposed to name a library, a file or a list and names nothing is not configured.
The classic case is snc/gssapi_lib. An empty value there means no security library is named in this instance's profile. It does not, by itself, mean nothing is encrypted, because whether the library would be loaded at all is governed by a separate parameter. One row is a fact; the conclusion needs the neighbouring rows.
An empty answer the system really gave is a measurement and a finding, drawn in the colour of a failure rather than the grey of something never read.
Because zero is a value somebody set, and in SAP it frequently means "never". login/password_expiration_time at 0 means no user is ever forced to change a password. login/password_max_idle_initial at 0 means an initial password never expires. rdisp/gui_auto_logout at 0 means an idle session is never closed. Each of these is listed with what it governs in security-relevant SAP profile parameters.
A review prints the value beside the condition for exactly this reason. Read the value, not only the colour of the verdict: a numeric condition can be satisfied by the number that switches a control off, and the only person who can catch that is the reader who looked at both fields. Where a zero represents a deliberate policy, record the decision as a mitigating control rather than leaving the row to be re-argued next quarter.
This is the same rule the rest of the platform is written under, stated in one place: what a finding does and does not claim.
Yes, for the parameters that were returned. It is not usable as a statement that the system passed the ones it could not read, and the report does not present it as one. Treat unmeasured rows as open work, not as clean rows.
Because that would be a number nobody measured, printed as though it had been. Assuming the default would make a report that read almost nothing look nearly as good as one that read everything.
It could, and that is the second of the two meanings above. The first thing to check is whether the parameter exists in your release, which RZ11 will answer in a few seconds for a single name.
Not always, but usually. Some parameters are legitimately empty on a system where the corresponding feature is not in use. The value and the condition are printed together so that case can be recognised and recorded rather than argued from memory.