Vendors access to production data

Vendors access to production data

Do you have any guidelines for allowing suppliers/vendors access to production data? What type of security should be in place? Do you know anyone who has done this and been successful?

    Requires Free Membership to View

    When you register, you will start receiving targeted emails from my award-winning team of editorial writers. Our goal is to keep you informed on the hottest topics and biggest challenges faced by SAP professionals today.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSAP.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSAP.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

We are playing with this idea as well. Obviously, access for suppliers/vendors should be limited to precisely the data and functionality they need to know. This is an area that we will continue to see recommendations in the next few years due to many companies' emphasis on Supply Chain projects.

The biggest hurdles I have uncovered are managing the user accounts from a distance: how do we track users, turnover, and password management? I have noted that many companies are turning to off-the-shelf provisioning products that manage many of these 'opportunities' and allow for distributed administation by a vendor delegate. My personal opinion is that vendor access should be limited to functionality and data specific to that vendor's business relationship. Furthermore, user accounts should be "silo'd" in an associated user group and reviewed on a periodic basis (hopefully automatically) for usage and access. Obviously, I suspect that any organization allowing vendors access will have supporting legal and contractual language that governs both use and the expectation of confidentiality.

This was first published in November 2003