Threat-First SAP Analytics Architecture (the T in GSTACK)
As of 2026-07-23
What is Threat-First SAP Analytics Architecture (the T in GSTACK)?
The threat tree walks every SAP analytics flow through four steps — asset classification, trust boundaries from ECC to external share, STRIDE-light per boundary, and blast-radius scoring — producing a one-page document per flow.
The 4-step threat tree on SAP analytics flows
Apply to every critical data flow on the engagement. Output is a 1-page-per-flow document.
Step 1 — Asset inventory
What data does this flow carry? Classification levels:
- Public — counts, KPIs at country level, anonymized buyer-persona
- Internal — country-grouped revenue, partner relationships, named-customer logos
- Confidential — per-customer transactional, individual employee, payroll, MNPI
- Restricted — PII identifying natural persons, health data, payment card data
The higher the classification, the smaller the acceptable blast radius.
Step 2 — Trust boundaries
Walk the flow from origin to consumption. At each transition, draw a boundary:
- ECC source → Datasphere replication (boundary: SAP RFC trust)
- Datasphere → BDC Iceberg lakehouse (boundary: lakehouse object-store ACLs)
- BDC → SAC live model (boundary: SAC role + space)
- SAC story → embedded export to Office (boundary: SAC export policy)
- SAC story → shared to external auditor (boundary: SAC public link)
At each boundary, name what the attacker would have to compromise to cross it.
Step 3 — Attack tree (STRIDE-light per boundary)
Why it matters
- Data classification (public, internal, confidential, restricted) sets the acceptable blast radius before any control is designed — the higher the classification, the smaller that radius must be.
- Each trust-boundary transition (ECC to Datasphere, Datasphere to BDC Iceberg, BDC to SAC live model, SAC to external auditor) names exactly what an attacker would need to compromise to cross it.
- STRIDE-light applied per boundary surfaces SAP-specific attack vectors — S-User reuse, RLS bypass via SAC drill-through, a Joule agent inheriting service-account scope.
Key points
- Apply per data flow, not per project — each flow gets a 1-page threat tree.
- 4 steps: asset inventory · trust boundaries · STRIDE-light per boundary · blast-radius scoring.
- SAP analytics-specific boundary list: ECC→Datasphere, Datasphere→BDC, BDC→SAC, SAC→export, SAC→public link.
- Output: a [GSTACK · threat-model · Pn] line per finding, fed into engagement risk register.
- Pairs with ownership-map (C306) — every finding gets a named owner.
- Threat-First SAP Analytics Architecture (the T in GSTACK) is mastered only when it changes a named buyer decision.
- Start with the semantic contract and control model before demonstrating the tool.
- Use current SAP, analyst, study, KG, and news signals as evidence, not decoration.
- Separate verified facts from directional trends and modeled assumptions.
- Define owner, metric, threshold, support path, and rollback before scaling.
Terms used on this page
- Trust boundary
- A point in the architecture where attacker-controlled input meets privileged code or data.
- STRIDE
- Microsoft threat-classification framework: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
- Data classification
- Tagging of data with a sensitivity level (public/internal/confidential/restricted) used to scope acceptable blast radius.
- Asset inventory
- The first step of any threat model — what are we protecting? Skip this and the rest is theatre.
- Decision owner
- The accountable person who accepts the trade-off and funds the next action.
- Semantic contract
- The shared definition of business terms, metrics, entities, and access rules used by tools and teams.
- Control plane
- The layer that applies policy, access, lineage, monitoring, and escalation across the operating model.
- Evidence grade
- A label that separates verified fact, directional signal, modeled assumption, and field observation.
Sources
- Microsoft STRIDE
- OWASP Threat Modeling Cheat Sheet
- SAP Datasphere Security Guide
- SAP Analytics Cloud Security Configuration
- SAP News Center — Accelerate the Autonomous Enterprise with SAP Business Data Cloud
- SAP News Center — SAP Unveils the Autonomous Enterprise
- SAP News Center — The Future of the Enterprise Is Autonomous
- SAP News Center — 2026 SAP Sapphire Keynote: Powering the Autonomous Enterprise
- SAP Datasphere — official product page
- SAP Analytics Cloud — official product page
- SAP BW/4HANA — Help Portal
- SAP S/4HANA — Help Portal
- SAP News Center
- SAP Community
- SAP — industries overview
- EFRAG — CSRD/ESRS standards
- Gartner — research & analyst site
- BARC — BI & Analytics research
- TDWI — data & analytics research
- DSAG — German-speaking SAP user group
- ASUG — Americas' SAP User Group
- Databricks — official site
- Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- The Challenges You Face and How SAP Business Data Cloud Helps — SAP Community (Data Professionals Blog posts)
- Managing Parent-Child Hierarchies in SAC: A Datasphere-Driven Approach — SAP Community (Technology Blog Posts by Members)
- Key figure / column based security in Datasphere — SAP Community (Technology Blog Posts by Members)
- SAP Business Data Cloud and Datasphere News in March — SAP Community (Technology Blog Posts by SAP)
- SAP Analytics Cloud in Business Data Cloud Achieves IBCS Re-Certification until February 2028! — SAP Community (Technology Blog Posts by SAP)
- Beyond Row-Level Security: Implementing Widget-Level Custom Authorization in SAP Analytics Cloud — SAP Community (Technology Blog Posts by Members)
- Currency Conversion in SAP Datasphere: The Next Level — SAP Community (Technology Blog Posts by Members)
- SAP Business Data Cloud for the Business Analyst: turning raw data to trusted and actionable insight — SAP Community (Data Professionals Blog posts)
- SAP Business Data Cloud and Datasphere News in February — SAP Community (Technology Blog Posts by SAP)
- Deep Dive into SAP Datasphere Object Store of BDC: Benefits, Architecture and implementation — SAP Community (Technology Blog Posts by Members)
- SAP Business Data Cloud and Datasphere News in January — SAP Community (Technology Blog Posts by SAP)
- Leveraging SAP Architecture Center for SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- SAP Business Data Cloud - Consolidated Error Messages in SAC Story Designer — SAP Community (Technology Blog Posts by SAP)
- Connecting SAP Analytics Cloud to Databricks model serving endpoint — SAP Community (Technology Blog Posts by SAP)
- Authorization setup for SAC Import Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
- Rewiring of SAP Datasphere to SAP Business Data Cloud — SAP Community (Technology Blog Posts by SAP)
- Data masking, data scrambling and data anonymization in Business Data Cloud with SAP Datasphere — SAP Community (Technology Blog Posts by SAP)
- Datasphere (DSP) and SAC data and metadata versioning / backup and restore — SAP Community (Technology Blog Posts by Members)
- Authorization setup for SAC Live Model from S4 ABAP CDS Views — SAP Community (Tooling (+ SAP Build) Blog Posts)
- SAP Datasphere & Google BigQuery: 3 Integration Strategies Before Zero Copy via BDC Connect Arrives — SAP Community (Technology Blog Posts by SAP)
- Empowering SAP Datasphere users with SAP Business Data Cloud innovations — SAP Community (Technology Blog Posts by SAP)
- SAP PaPM Cloud Universal Model: Pushing and Pulling data to and from SAP Analytics Cloud — SAP Community (Financial Management Blog Posts by SAP)
- Evolution of Data and Analytics with SAP Business Data Cloud — SAP Community (Technology Blog Posts by Members)
- Planning your transition paths to SAP Business Data Cloud (data architecture miniseries) — SAP Community (Technology Blog Posts by SAP)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks.