Every verdict in an SAP profile parameter review comes from a catalogue entry that names one parameter and the value expected of it, and in the RedRays Security Platform that catalogue ships with the product, is readable on screen, and can be extended by the customer.
There is no second route to a finding. If a parameter has no entry, it produces no row. If an entry expects the wrong value for your landscape, it produces the wrong verdict. So the catalogue is worth reading before the report is.
| Part | What it is for |
|---|---|
| Parameter name | The exact SAP parameter to ask about. It is a key, not a description, so it has to match what SAP returns |
| Condition | The value or range expected of that parameter |
| Title | The name a reader sees on the finding |
| Description | What the parameter governs, so a reader who has never met it can decide whether the finding matters |
| Recommended solution | What to change, in the words the person doing the change needs |
An entry carries no severity and no score. A parameter deviation is a difference from a recommended setting, and how much it matters depends on the system it was found on.
An entry is editable in the product, so a house standard or a compensating control replaces the shipped expectation instead of living in a footnote.
Because a verdict whose condition is hidden is one the reader has to take on trust. The finding shows the value the system returned next to the condition it was judged against, which lets three different people do three useful things:
An SAP security review that will not show its own conditions is asking to be believed. This one is asking to be checked.
Yes. Entries can be edited and new ones added, which is how a house standard, a regulator's baseline or a compensating control gets into the review instead of living in a footnote. Two consequences are worth knowing before you do it:
The shipped catalogue is assembled from SAP's own documentation and published hardening guidance for each parameter. It is a starting position, not a standard body's ruling, which is why it is visible and editable rather than compiled in.
The verdicts already recorded stay as they were recorded. Treat a catalogue change the way you would treat a change to any control standard: note the date, and read reports either side of it as covering different lists.
That is a question about how you organise reviews rather than about a single entry, and it is worth raising during a proof of value. The point to hold on to is that a report should name the standard it applied, and this one shows the condition on the finding itself.
Nothing. It is not reported, and it is not counted as unmeasured either, because the review never asked about it. Only parameters in the catalogue that the system did not return are reported as unmeasured. See not found, not set and zero.