Analytics Legends The knowledge platform for SAP Analytics
Concept card

Threat-First SAP Analytics Architecture (the T in GSTACK)

Threat-First SAP Analytics Architecture (the T in GSTACK) — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-07-23

What is Threat-First SAP Analytics Architecture (the T in GSTACK)?

The threat tree walks every SAP analytics flow through four steps — asset classification, trust boundaries from ECC to external share, STRIDE-light per boundary, and blast-radius scoring — producing a one-page document per flow.

The 4-step threat tree on SAP analytics flows

Apply to every critical data flow on the engagement. Output is a 1-page-per-flow document.

Step 1 — Asset inventory

What data does this flow carry? Classification levels:

  • Public — counts, KPIs at country level, anonymized buyer-persona
  • Internal — country-grouped revenue, partner relationships, named-customer logos
  • Confidential — per-customer transactional, individual employee, payroll, MNPI
  • Restricted — PII identifying natural persons, health data, payment card data

The higher the classification, the smaller the acceptable blast radius.

Step 2 — Trust boundaries

Walk the flow from origin to consumption. At each transition, draw a boundary:

  • ECC source → Datasphere replication (boundary: SAP RFC trust)
  • Datasphere → BDC Iceberg lakehouse (boundary: lakehouse object-store ACLs)
  • BDC → SAC live model (boundary: SAC role + space)
  • SAC story → embedded export to Office (boundary: SAC export policy)
  • SAC story → shared to external auditor (boundary: SAC public link)

At each boundary, name what the attacker would have to compromise to cross it.

Step 3 — Attack tree (STRIDE-light per boundary)

Why it matters

  • Data classification (public, internal, confidential, restricted) sets the acceptable blast radius before any control is designed — the higher the classification, the smaller that radius must be.
  • Each trust-boundary transition (ECC to Datasphere, Datasphere to BDC Iceberg, BDC to SAC live model, SAC to external auditor) names exactly what an attacker would need to compromise to cross it.
  • STRIDE-light applied per boundary surfaces SAP-specific attack vectors — S-User reuse, RLS bypass via SAC drill-through, a Joule agent inheriting service-account scope.

Key points

  • Apply per data flow, not per project — each flow gets a 1-page threat tree.
  • 4 steps: asset inventory · trust boundaries · STRIDE-light per boundary · blast-radius scoring.
  • SAP analytics-specific boundary list: ECC→Datasphere, Datasphere→BDC, BDC→SAC, SAC→export, SAC→public link.
  • Output: a [GSTACK · threat-model · Pn] line per finding, fed into engagement risk register.
  • Pairs with ownership-map (C306) — every finding gets a named owner.
  • Threat-First SAP Analytics Architecture (the T in GSTACK) is mastered only when it changes a named buyer decision.
  • Start with the semantic contract and control model before demonstrating the tool.
  • Use current SAP, analyst, study, KG, and news signals as evidence, not decoration.
  • Separate verified facts from directional trends and modeled assumptions.
  • Define owner, metric, threshold, support path, and rollback before scaling.

Terms used on this page

Trust boundary
A point in the architecture where attacker-controlled input meets privileged code or data.
STRIDE
Microsoft threat-classification framework: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
Data classification
Tagging of data with a sensitivity level (public/internal/confidential/restricted) used to scope acceptable blast radius.
Asset inventory
The first step of any threat model — what are we protecting? Skip this and the rest is theatre.
Decision owner
The accountable person who accepts the trade-off and funds the next action.
Semantic contract
The shared definition of business terms, metrics, entities, and access rules used by tools and teams.
Control plane
The layer that applies policy, access, lineage, monitoring, and escalation across the operating model.
Evidence grade
A label that separates verified fact, directional signal, modeled assumption, and field observation.

Sources

  1. Microsoft STRIDE
  2. OWASP Threat Modeling Cheat Sheet
  3. SAP Datasphere Security Guide
  4. SAP Analytics Cloud Security Configuration
  5. SAP News Center — Accelerate the Autonomous Enterprise with SAP Business Data Cloud
  6. SAP News Center — SAP Unveils the Autonomous Enterprise
  7. SAP News Center — The Future of the Enterprise Is Autonomous
  8. SAP News Center — 2026 SAP Sapphire Keynote: Powering the Autonomous Enterprise
  9. SAP Datasphere — official product page
  10. SAP Analytics Cloud — official product page
  11. SAP BW/4HANA — Help Portal
  12. SAP S/4HANA — Help Portal
  13. SAP News Center
  14. SAP Community
  15. SAP — industries overview
  16. EFRAG — CSRD/ESRS standards
  17. Gartner — research & analyst site
  18. BARC — BI & Analytics research
  19. TDWI — data & analytics research
  20. DSAG — German-speaking SAP user group
  21. ASUG — Americas' SAP User Group
  22. Databricks — official site
  23. Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  24. The Challenges You Face and How SAP Business Data Cloud Helps — SAP Community (Data Professionals Blog posts)
  25. Managing Parent-Child Hierarchies in SAC: A Datasphere-Driven Approach — SAP Community (Technology Blog Posts by Members)
  26. Key figure / column based security in Datasphere — SAP Community (Technology Blog Posts by Members)
  27. SAP Business Data Cloud and Datasphere News in March — SAP Community (Technology Blog Posts by SAP)
  28. SAP Analytics Cloud in Business Data Cloud Achieves IBCS Re-Certification until February 2028! — SAP Community (Technology Blog Posts by SAP)
  29. Beyond Row-Level Security: Implementing Widget-Level Custom Authorization in SAP Analytics Cloud — SAP Community (Technology Blog Posts by Members)
  30. Currency Conversion in SAP Datasphere: The Next Level — SAP Community (Technology Blog Posts by Members)
  31. SAP Business Data Cloud for the Business Analyst: turning raw data to trusted and actionable insight — SAP Community (Data Professionals Blog posts)
  32. SAP Business Data Cloud and Datasphere News in February — SAP Community (Technology Blog Posts by SAP)
  33. Deep Dive into SAP Datasphere Object Store of BDC: Benefits, Architecture and implementation — SAP Community (Technology Blog Posts by Members)
  34. SAP Business Data Cloud and Datasphere News in January — SAP Community (Technology Blog Posts by SAP)
  35. Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  36. SAP Business Data Cloud - Consolidated Error Messages in SAC Story Designer — SAP Community (Technology Blog Posts by SAP)
  37. Connecting SAP Analytics Cloud to Databricks model serving endpoint — SAP Community (Technology Blog Posts by SAP)
  38. Authorization setup for SAC Import Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
  39. Rewiring of SAP Datasphere to SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
  40. Data masking, data scrambling and data anonymization in Business Data Cloud with SAP Datasphere — SAP Community (Technology Blog Posts by SAP)
  41. Datasphere (DSP) and SAC data and metadata versioning / backup and restore — SAP Community (Technology Blog Posts by Members)
  42. Authorization setup for SAC Live Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
  43. SAP Datasphere & Google BigQuery: 3 Integration Strategies Before Zero Copy via BDC Connect Arrives — SAP Community (Technology Blog Posts by SAP)
  44. Empowering SAP Datasphere users with SAP Business Data Cloud innovations — SAP Community (Technology Blog Posts by SAP)
  45. SAP PaPM Cloud Universal Model: Pushing and Pulling data to and from SAP Analytics Cloud — SAP Community (Financial Management Blog Posts by SAP)
  46. Evolution of Data and Analytics with SAP Business Data Cloud — SAP Community (Technology Blog Posts by Members)
  47. Planning your transition paths to SAP Business Data Cloud (data architecture miniseries) — SAP Community (Technology Blog Posts by SAP)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks.

Open in the app →