Hier mal die settings aus dem neuesten Sec Baseline Template 2.2
a) System Change Option “Global Settings” should be set to “Not modifiable” (Transaction SE06). You can check the setting in transaction SE16 for table TADIR, too: Select the entry for PGMID = HEAD and OBJ = SYST and check whether EDTFLAG = N or P. [Critical]
b) Client Change Option: Use transaction SCC4 to define following settings for all production clients:
- “Client role” = “Live”
- “Changes and Transports for Client-Specific Objects” = “No changes allowed”
- “Cross-Client Object Changes” = “No Changes to Repository and Cross-Client Customizing Objects”
- “Client Copy and Comparison Tool Protection” is set either to “Protection level1: No overwriting” or to “Protection level2: No overwriting, no external availability”.
You can check the settings in transaction SE16 for table T000 for all clients, whether CCCORACTIV = 2 and CCNOCLIIND = 3 and CCCOPYLOCK = X or L. CCCATEGORY = P means production client. [Critical]
c) Activate profile parameter to create customizing table logs
Profile parameter rec/client <> OFF [Standard]
d) Activate transport parameter to create customizing table logs as part of transports
Transport parameter RECCLIENT is defined and not set to OFF [Extended]
e) Activate transport parameters to create versions of repository objects as part of transports
Transport parameter VERS_AT_EXP. Use NO_T respective TRUE, YES, ON, or 1 for development systems (see note 2296271).
Transport parameter VERS_AT_IMP. Decide if value ALWAYS should be used for production systems (see note 1784800). [Extended]
f) Activate transport parameter to validate the content of transport files
Transport parameter TLOGOCHECK = TRUE