Onapsis, in collaboration with The Cloud Security Alliance (CSA), a not-for-profit organization dedicated to raising awareness of best practices to help ensure a secure cloud computing environment, has completed The Critical Controls Implementation for SAP white paper. The Critical Controls Implementation for SAP is the first in a series of implementation documents that focuses on specific ERP technologies and aids organizations in securely migrating to and operating ERP applications in cloud environments. In this document, the working group focuses on providing guidelines on controls implementation as well as a set of checklists for SAP administrators. Download this white paper now for control implementation guidance on a variety of controls.
Download Now

About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
More about this author
Further Reading
Mythos & GPT-5.4-Cyber: The Upcoming AI-Driven “Vulnerability Surge” in SAP
Frontier AI models like Claude Mythos demonstrate an unprecedented capability to autonomously discover zero-day vulnerabilities in critical infrastructure, including flaws that have sat dormant for decades. As former CISA Director Jen Easterly recently emphasized, the response to this shift requires an industry-wide mindset of “preparation, not panic.” This preparation involves confronting foundational security flaws, as…
SAP Security Notes: April 2026 Patch Day
SAP Patch Day for April 2026 addresses critical SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
2,000 Hours Reclaimed: How Global Leaders Transformed SAP ITGC Testing
Automating SAP ITGC testing delivers measurable returns on investment by eliminating the hidden operational costs of manual compliance. In the first post of this series, we examined how manual testing drains up to 2,000 resource hours annually and leaves enterprise organizations vulnerable to human error. The second post detailed the technical solution, explaining how transitioning…
