What’s New in SAP Cloud ALM Configuration & Security Analysis: Recent Highlights
Share

SAP Cloud ALM continues to expand its Configuration & Security Analysis capabilities with new features designed to improve compliance monitoring, security transparency, and configuration governance across hybrid SAP landscapes.

This blog provides a technical walkthrough of the latest enhancements, including custom checks, policies, recommended SAP Security Notes integration, new supported content, and additional data stores.

 

Introduction

Configuration & Security Analysis in SAP Cloud ALM helps customers monitor configuration and security compliance across managed systems and services. SAP-delivered checks already cover many common compliance requirements, but customer landscapes often require organisation-specific baselines, additional reporting structures, and broader technical coverage.         

Recent enhancements address these needs by introducing:

  • Custom checks for customer-specific compliance requirements
  • Policies for structured compliance reporting
  • Integration with SAP Cloud ALM Landscapes – Design & Visualisation for recommended ABAP security notes
  • New supported content for SAP BTP, Advanced Workflow, and SuccessFactors HCM
  • New data stores for certificates, files, and HANA-related information

Together, these features provide greater flexibility and better visibility into compliance posture across SAP landscapes.

 

Custom Checks

SAP-delivered checks cover a broad range of standard compliance and security requirements. However, many customers need to enforce company-specific security baselines or parameter settings that are not covered by standard SAP content.

To support this, Configuration & Security Analysis now provides the option of custom checks.

Custom checks allow customers and partners to define their own compliance checks directly in SAP Cloud ALM. These checks can then be monitored consistently across managed systems and included in compliance reporting alongside SAP-delivered checks.

Why Custom Checks Matter

Custom checks help organisations enforce internal standards such as:

  • Company-specific security parameter values
  • Internal audit requirements
  • Regulatory or industry-specific baselines
  • Customer-defined configuration rules
  • Partner-defined compliance templates

This allows SAP Cloud ALM to become not only a tool for SAP-delivered best practices, but also a platform for organisation-specific compliance governance.

Multiple Rules – The ability to define multiple rules is especially important for more complex compliance scenarios where a single compliance requirement may depend on several technical conditions.

How to Create a Custom Check

To create a custom check:

  1. Open SAP Cloud ALM
  2. Navigate to Configuration & Security Analysis – Validation Application
  3. Choose Configuration
  4. Select a Service Type of your choice
  5. Go to the Custom Checks tab
  6. Create a new custom check based on the required service type and store definition
  7. Define one or more rules according to your compliance requirement

RamyaHV_1-1786026979371.png

Once created, the custom check can be used in validation runs and reporting together with SAP-delivered checks.

 

Policies

Another major enhancement in Configuration & Security Analysis is the introduction of policies.

A policy is a logical grouping of checks that collectively enforce a specific compliance objective. Each policy is associated with one or more SAP services type, making it clear which part of the landscape the policy governs.

Instead of evaluating individual checks in isolation, customers can now view validation results at a policy level. This provides a more meaningful and aggregated compliance picture.

SAP-Delivered Policies

SAP provides pre-built policies that group related compliance checks together. These SAP-delivered policies are mapped to the specific services type to which they apply.

Custom Policies

In addition to SAP-delivered policies, customers can now create custom policies.

Custom policies provide flexibility to structure compliance reporting according to internal needs. For example, an organization may want to create policies for:

  • Internal security baselines
  • Audit-specific requirements
  • Regional regulatory requirements
  • Application-specific controls
  • Technical platform hardening

Types of Custom Policies

Two types of custom policies are supported:

 Single Policy – A service-type-dependent policy that applies to one specific service type

Composite Policy – A policy that can include policies from different service types

RamyaHV_2-1786027055193.png

Composite policies are especially useful for hybrid or cross-service compliance scenarios where a single compliance objective spans multiple SAP technologies.

Policy-Level Validation Results

With the introduction of policies, validation result visualisation has also changed. Results now provide an aggregated compliance view at policy level.

RamyaHV_0-1786026824070.png

This helps customers quickly understand:

  • Which compliance objectives are fulfilled
  • Which services are affected
  • Where remediation activities should be prioritised

 

SAP Recommended Security Notes Integration

One of the most important recent enhancements is the integration of recommended SAP recommended ABAP security notes into Configuration & Security Analysis.

SAP Cloud ALM Landscapes – Design & Visualisation, also known as LDV, can now fetch applicable recommended security notes for on-premise and private cloud systems from the Maintenance Planner API. This is done using a configured Technical S-user.

The note information is then pushed into the Configuration & Security Analysis data store: ABAP_RECOMMENDED_NOTES_STATUS

This enables Configuration & Security Analysis to display the actual implementation status of recommended SAP Security Notes based on information from Maintenance Planner.

How It Works

The process works as follows:

  1. SAP Cloud ALM Landscapes – Design & Visualisation (under Implementation work centre) connects to the Maintenance Planner API.
  2. The connection uses a configured Technical S-user.
  3. LDV retrieves recommended security notes for relevant on-premise and private cloud systems.
  4. LDV pushes this information to the Configuration & Security Analysis data store `ABAP_RECOMMENDED_NOTES_STATUS`.
  5. Configuration & Security Analysis displays the current implementation status of the notes.
  6. Notes that are already fully implemented are not displayed in Configuration & Security Analysis.
  7. If customer maintains a custom status “Implemented” in Maintenance Planner you will see that status in Configuration & Security Analysis.

Why This Is Important??

Security note compliance is a critical requirement for SAP customers. Traditionally, many organisations have had to rely on manual tracking or custom processes to determine whether recommended security notes were implemented.

With this integration, SAP Cloud ALM improves transparency and reduces manual effort by providing automated visibility into recommended ABAP security note status.

This enhancement is particularly useful for:

  • Security administrators
  • Basis teams
  • Compliance teams
  • Audit preparation
  • Security patch governance
  • Hybrid landscape monitoring

For more details, refer to the SAP Community blog:

[View Recommended Notes in SAP Cloud ALM Applications]

 

New Supported Content

Configuration & Security Analysis has also been expanded with new supported content across SAP BTP, workflow, and SuccessFactors scenarios.

SAP BTP Cloud Foundry Connectivity Services

New content is now available for connectivity services on SAP BTP Cloud Foundry, including the Cloud Connector.

This helps customers monitor relevant configuration and security aspects of connectivity scenarios in SAP BTP environments.

Advanced Workflow

Support has also been introduced for Advanced Workflow.

This enhancement is especially relevant for SAP SuccessFactors Incentive Management customers who had Advanced Workflow as an optional add-on.

With this content, customers can include additional workflow-related configurations in their compliance monitoring scope.

SuccessFactors HCM

Configuration & Security Analysis now also supports SAP SuccessFactors HCM.

This broadens the coverage of SAP Cloud ALM and helps customers extend compliance visibility into their SuccessFactors environments.

 

New Data Stores

Several new data stores have been introduced to extend the data available for compliance evaluation.

PSE_CERTIFICATES Store

The new `PSE_CERTIFICATES` store enables SAP Cloud ALM to collect certificate information from managed systems and evaluate it against defined compliance criteria.

This is an important enhancement for certificate and cryptography-related monitoring which helps reduce the risk of certificate-related outages and improves visibility into the certificate landscape.

FILECMCUST Store

A new file-based custom store has been introduced – FILECMCUST

This store is available for the data collector identified as S00477.

The `FILECMCUST` store enables file-based customisation data to be made available for compliance evaluation in Configuration & Security Analysis.

This provides additional flexibility for customers who need to include file-based configuration or customisation information in their compliance monitoring scenarios.

HANA Stores

HANA-related stores are also available, subject to certain prerequisites on the managed ABAP system.

To view HANA data stores, the ABAP system must meet the following requirements:

  • The latest SAP Host Agent version must be used, with at least patch level 67. The SAP Host Agent versions on the database and application server must match.
  • ST-PI 740 SP35 or ST-PI 758 SP02 must be installed. The relevant packages must be up to date.
  • You’ve implemented the steps from SAP Note 2023587 Information published on SAP site (Maintaining SAP HANA user store using SetDatabaseProperty for SAP Host Agent).

Customers should refer to the SAP Help Portal for the latest prerequisite and setup information.

 

Release Summary Briefly

Feature

Capability Area

Primary Benefit

Custom Checks

Compliance Configuration

Enforce organisation-specific compliance criteria alongside SAP-delivered content

Policies

Compliance Structure & Reporting

Aggregate check results by policy and provide clear service-to-check mapping

CALM–LDV Integration

Security Note Compliance

Automated implementation status of recommended SAP Security Notes via Maintenance Planner

SAP BTP Cloud Foundry Connectivity

BTP Content Extension

Support for new Cloud Foundry connectivity service configurations

Advanced Workflow

Workflow Content Extension

Support for Advanced Workflow scenarios, including relevant SuccessFactors Incentive Management use cases

SuccessFactors HCM Support

SaaS Content Extension

Extend compliance visibility to SAP SuccessFactors HCM

PSE_CERTIFICATES Store

Certificate & Cryptography

Automated collection and evaluation of PSE certificate data from managed systems

FILECMCUST Store S00477

Data Collection Extension

File-based customisation data available for compliance evaluation

HANA Stores

Database Configuration Visibility

Additional HANA-related configuration data available when prerequisites are met

 

Further Reading and Resources

The features described in this blog are part of a broader set of enhancements delivered across SAP Cloud ALM.

Recommended resources:

[SAP Cloud ALM — What’s New]

[SAP Cloud ALM on SAP Community]

 [View Recommended Notes in SAP Cloud ALM Applications]

Closing Thoughts

The recent enhancements in SAP Cloud ALM Configuration & Security Analysis show a clear direction: broader coverage, greater configurability, and tighter integration with adjacent SAP tools and services.

The integration between SAP Cloud ALM Landscapes – Design & Visualisation and Configuration & Security Analysis closes an important gap in automated security note compliance tracking. Many customers previously had to manage recommended SAP Security Notes through manual processes or custom workarounds. With this enhancement, security note visibility becomes more integrated and automated.

The introduction of custom checks and policies provides the structural foundation for organisations to build a compliance program that reflects their actual security, operational, and regulatory requirements rather than relying only on generic baselines.

For customers expanding their use of SAP Cloud ALM across ABAP systems, SAP BTP, SAP SuccessFactors, or hybrid landscapes, these capabilities provide practical starting points for improving compliance monitoring and security governance.

As always, the SAP Community forums and the SAP Cloud ALM group on SAP Community are great places to share experiences, ask questions, and learn how other organisations are applying these capabilities.

Stay tuned for further updates as the next SAP Cloud ALM release cycle approaches.

 

 SAP Cloud ALM continues to expand its Configuration & Security Analysis capabilities with new features designed to improve compliance monitoring, security transparency, and configuration governance across hybrid SAP landscapes.This blog provides a technical walkthrough of the latest enhancements, including custom checks, policies, recommended SAP Security Notes integration, new supported content, and additional data stores. IntroductionConfiguration & Security Analysis in SAP Cloud ALM helps customers monitor configuration and security compliance across managed systems and services. SAP-delivered checks already cover many common compliance requirements, but customer landscapes often require organisation-specific baselines, additional reporting structures, and broader technical coverage.         Recent enhancements address these needs by introducing:Custom checks for customer-specific compliance requirementsPolicies for structured compliance reportingIntegration with SAP Cloud ALM Landscapes – Design & Visualisation for recommended ABAP security notesNew supported content for SAP BTP, Advanced Workflow, and SuccessFactors HCMNew data stores for certificates, files, and HANA-related informationTogether, these features provide greater flexibility and better visibility into compliance posture across SAP landscapes. Custom ChecksSAP-delivered checks cover a broad range of standard compliance and security requirements. However, many customers need to enforce company-specific security baselines or parameter settings that are not covered by standard SAP content.To support this, Configuration & Security Analysis now provides the option of custom checks.Custom checks allow customers and partners to define their own compliance checks directly in SAP Cloud ALM. These checks can then be monitored consistently across managed systems and included in compliance reporting alongside SAP-delivered checks.Why Custom Checks MatterCustom checks help organisations enforce internal standards such as:Company-specific security parameter valuesInternal audit requirementsRegulatory or industry-specific baselinesCustomer-defined configuration rulesPartner-defined compliance templatesThis allows SAP Cloud ALM to become not only a tool for SAP-delivered best practices, but also a platform for organisation-specific compliance governance.Multiple Rules – The ability to define multiple rules is especially important for more complex compliance scenarios where a single compliance requirement may depend on several technical conditions.How to Create a Custom CheckTo create a custom check:Open SAP Cloud ALMNavigate to Configuration & Security Analysis – Validation ApplicationChoose ConfigurationSelect a Service Type of your choiceGo to the Custom Checks tabCreate a new custom check based on the required service type and store definitionDefine one or more rules according to your compliance requirementOnce created, the custom check can be used in validation runs and reporting together with SAP-delivered checks. PoliciesAnother major enhancement in Configuration & Security Analysis is the introduction of policies.A policy is a logical grouping of checks that collectively enforce a specific compliance objective. Each policy is associated with one or more SAP services type, making it clear which part of the landscape the policy governs.Instead of evaluating individual checks in isolation, customers can now view validation results at a policy level. This provides a more meaningful and aggregated compliance picture.SAP-Delivered PoliciesSAP provides pre-built policies that group related compliance checks together. These SAP-delivered policies are mapped to the specific services type to which they apply.Custom PoliciesIn addition to SAP-delivered policies, customers can now create custom policies.Custom policies provide flexibility to structure compliance reporting according to internal needs. For example, an organization may want to create policies for:Internal security baselinesAudit-specific requirementsRegional regulatory requirementsApplication-specific controlsTechnical platform hardeningTypes of Custom PoliciesTwo types of custom policies are supported: Single Policy – A service-type-dependent policy that applies to one specific service typeComposite Policy – A policy that can include policies from different service typesComposite policies are especially useful for hybrid or cross-service compliance scenarios where a single compliance objective spans multiple SAP technologies.Policy-Level Validation ResultsWith the introduction of policies, validation result visualisation has also changed. Results now provide an aggregated compliance view at policy level.This helps customers quickly understand:Which compliance objectives are fulfilledWhich services are affectedWhere remediation activities should be prioritised SAP Recommended Security Notes IntegrationOne of the most important recent enhancements is the integration of recommended SAP recommended ABAP security notes into Configuration & Security Analysis.SAP Cloud ALM Landscapes – Design & Visualisation, also known as LDV, can now fetch applicable recommended security notes for on-premise and private cloud systems from the Maintenance Planner API. This is done using a configured Technical S-user.The note information is then pushed into the Configuration & Security Analysis data store: ABAP_RECOMMENDED_NOTES_STATUSThis enables Configuration & Security Analysis to display the actual implementation status of recommended SAP Security Notes based on information from Maintenance Planner.How It WorksThe process works as follows:SAP Cloud ALM Landscapes – Design & Visualisation (under Implementation work centre) connects to the Maintenance Planner API.The connection uses a configured Technical S-user.LDV retrieves recommended security notes for relevant on-premise and private cloud systems.LDV pushes this information to the Configuration & Security Analysis data store `ABAP_RECOMMENDED_NOTES_STATUS`.Configuration & Security Analysis displays the current implementation status of the notes.Notes that are already fully implemented are not displayed in Configuration & Security Analysis.If customer maintains a custom status “Implemented” in Maintenance Planner you will see that status in Configuration & Security Analysis.Why This Is Important??Security note compliance is a critical requirement for SAP customers. Traditionally, many organisations have had to rely on manual tracking or custom processes to determine whether recommended security notes were implemented.With this integration, SAP Cloud ALM improves transparency and reduces manual effort by providing automated visibility into recommended ABAP security note status.This enhancement is particularly useful for:Security administratorsBasis teamsCompliance teamsAudit preparationSecurity patch governanceHybrid landscape monitoringFor more details, refer to the SAP Community blog:[View Recommended Notes in SAP Cloud ALM Applications] New Supported ContentConfiguration & Security Analysis has also been expanded with new supported content across SAP BTP, workflow, and SuccessFactors scenarios.SAP BTP Cloud Foundry Connectivity ServicesNew content is now available for connectivity services on SAP BTP Cloud Foundry, including the Cloud Connector.This helps customers monitor relevant configuration and security aspects of connectivity scenarios in SAP BTP environments.Advanced WorkflowSupport has also been introduced for Advanced Workflow.This enhancement is especially relevant for SAP SuccessFactors Incentive Management customers who had Advanced Workflow as an optional add-on.With this content, customers can include additional workflow-related configurations in their compliance monitoring scope.SuccessFactors HCMConfiguration & Security Analysis now also supports SAP SuccessFactors HCM.This broadens the coverage of SAP Cloud ALM and helps customers extend compliance visibility into their SuccessFactors environments. New Data StoresSeveral new data stores have been introduced to extend the data available for compliance evaluation.PSE_CERTIFICATES StoreThe new `PSE_CERTIFICATES` store enables SAP Cloud ALM to collect certificate information from managed systems and evaluate it against defined compliance criteria.This is an important enhancement for certificate and cryptography-related monitoring which helps reduce the risk of certificate-related outages and improves visibility into the certificate landscape.FILECMCUST StoreA new file-based custom store has been introduced – FILECMCUSTThis store is available for the data collector identified as S00477.The `FILECMCUST` store enables file-based customisation data to be made available for compliance evaluation in Configuration & Security Analysis.This provides additional flexibility for customers who need to include file-based configuration or customisation information in their compliance monitoring scenarios.HANA StoresHANA-related stores are also available, subject to certain prerequisites on the managed ABAP system.To view HANA data stores, the ABAP system must meet the following requirements:The latest SAP Host Agent version must be used, with at least patch level 67. The SAP Host Agent versions on the database and application server must match.ST-PI 740 SP35 or ST-PI 758 SP02 must be installed. The relevant packages must be up to date.You’ve implemented the steps from SAP Note 2023587 Information published on SAP site (Maintaining SAP HANA user store using SetDatabaseProperty for SAP Host Agent).Customers should refer to the SAP Help Portal for the latest prerequisite and setup information. Release Summary BrieflyFeatureCapability AreaPrimary BenefitCustom ChecksCompliance ConfigurationEnforce organisation-specific compliance criteria alongside SAP-delivered contentPoliciesCompliance Structure & ReportingAggregate check results by policy and provide clear service-to-check mappingCALM–LDV IntegrationSecurity Note ComplianceAutomated implementation status of recommended SAP Security Notes via Maintenance PlannerSAP BTP Cloud Foundry ConnectivityBTP Content ExtensionSupport for new Cloud Foundry connectivity service configurationsAdvanced WorkflowWorkflow Content ExtensionSupport for Advanced Workflow scenarios, including relevant SuccessFactors Incentive Management use casesSuccessFactors HCM SupportSaaS Content ExtensionExtend compliance visibility to SAP SuccessFactors HCMPSE_CERTIFICATES StoreCertificate & CryptographyAutomated collection and evaluation of PSE certificate data from managed systemsFILECMCUST Store S00477Data Collection ExtensionFile-based customisation data available for compliance evaluationHANA StoresDatabase Configuration VisibilityAdditional HANA-related configuration data available when prerequisites are met Further Reading and ResourcesThe features described in this blog are part of a broader set of enhancements delivered across SAP Cloud ALM.Recommended resources:[SAP Cloud ALM — What’s New][SAP Cloud ALM on SAP Community] [View Recommended Notes in SAP Cloud ALM Applications]Closing ThoughtsThe recent enhancements in SAP Cloud ALM Configuration & Security Analysis show a clear direction: broader coverage, greater configurability, and tighter integration with adjacent SAP tools and services.The integration between SAP Cloud ALM Landscapes – Design & Visualisation and Configuration & Security Analysis closes an important gap in automated security note compliance tracking. Many customers previously had to manage recommended SAP Security Notes through manual processes or custom workarounds. With this enhancement, security note visibility becomes more integrated and automated.The introduction of custom checks and policies provides the structural foundation for organisations to build a compliance program that reflects their actual security, operational, and regulatory requirements rather than relying only on generic baselines.For customers expanding their use of SAP Cloud ALM across ABAP systems, SAP BTP, SAP SuccessFactors, or hybrid landscapes, these capabilities provide practical starting points for improving compliance monitoring and security governance.As always, the SAP Community forums and the SAP Cloud ALM group on SAP Community are great places to share experiences, ask questions, and learn how other organisations are applying these capabilities.Stay tuned for further updates as the next SAP Cloud ALM release cycle approaches. Read More Technology Blog Posts by SAP articles 

#SAPCHANNEL

By ali

Leave a Reply