SAP S/4HANA Cloud (Public Cloud ERP)
SAP ERP Cloud is delivered via public cloud (SaaS), and based on S/4HANA. Deployment takes from 12 weeks, with quarterly innovation updates included. Market leading tech, includes machine Learning, A.I., Predictive Analytics and IoT. The User Experience is next-gen consumer-grade, accessible via mobile, tablet and desktop. GDPR Statement - https://www.sap.com/products/s4hana-erp.html#pdf-asset=e48dd993-df7c-0010-82c7-eda71af511fa&page=1
- 2Tier ERP opportunity to standardize business processes across multiple tiers.
- Procure to Pay, including integration with Ariba Network.
- Plan to Product, including inventory and maintenance management.
- Order to Cash, including contract and receivables processing.
- Project Services and discrete manufacturing, including time and expense management.
- Administrative ERP with Core Finance, including cost management, profitability analysis.
- Integration to SAP (e.g. SAP SuccessFactors) or non-SAP systems.
- Artificial Intelligence with SAP Co-Pilot.
- Extensibility via the HANA Cloud Platform (PaaS).
- Extensible with SAP BusinessObjects Cloud and Digital Boardroom.
- Delivered through a software-as-a-service (SaaS) model.
- Decreased procurement cost and maverick spend.
- Best in Class financial, logistics and staffing services.
- No version lock in, quarterly releases, with access to innovation.
- Reduced days receivables and receivables write-offs.
- Increased user productivity and more efficient user onboarding.
- Organisational agility, based on a simpler IT architecture.
- Short time to value (in as little as 12 weeks).
- TCO reduction (IT administration and development costs).
- More efficient projects and better project controlling.
£44 to £570 per person per month
|Software add-on or extension||No|
|Cloud deployment model||Public cloud|
|Service constraints||Quaterly upgrades, agreed scheduled downtime for updates. Customer are always on the latest version.|
|Email or online ticketing support||Email or online ticketing|
|Support response times||SLAs are agreed with Customers. Weekend SLAs may be different but again will be agreed with Customers|
|User can manage status and priority of support tickets||Yes|
|Online ticketing support accessibility||None or don’t know|
|Phone support availability||9 to 5 (UK time), Monday to Friday|
|Web chat support||No|
|Onsite support||Yes, at extra cost|
|Support levels||Maintenance support and system issues are supported by SAP direct, application support is provided via our partner channel and therefore costs are provided by them direct. Maintenance support is provided as part of the subscription cost and therefore not an extra cost. 24x7 for priority 1 and 2 issues. Non-Business Critical support is 8am to 6pm local time.|
|Support available to third parties||Yes|
Onboarding and offboarding
|Getting started||SAP follows it's ACTIVATE methodology. SAP Activate is the innovation adoption framework that expedites SAP S/4HANA implementations throughout the customer lifecycle. It offers ready-to-run digitized business and technology processes, guided configuration, and next-generation methodology. https://www.sap.com/uk/services/s4hana-deployment.html|
|End-of-contract data extraction||There are data download facilities to extract data if required|
|End-of-contract process||When the contract ends the customer can either renew or revoke their agreement. Once the contract period is over, if a customer chooses not to renew the agreement they can stop subscriptions for the service at no additional cost.|
Using the service
|Web browser interface||Yes|
|Application to install||No|
|Designed for use on mobile devices||Yes|
|Differences between the mobile and desktop service||Certain S/4HANA cloud APPs are available on Mobile and Tablet device.|
|What users can and can't do using the API||SAP's APIs enable the integration of on-premise, cloud-based and third-party solutions with the S/4HANA Cloud solution.|
|API documentation formats||HTML|
|API sandbox or test environment||Yes|
|Description of customisation||Customisation can be done on various levels: Personalise - role driven changes where users can adapt their own screens to meet their needs. Admin. adaptation - field additions and changes can be made to extend the functionality of the system. SAP also provides side-by-side extensibility capabilities with the SAP Cloud platform|
|Independence of resources||S/4HANA Cloud is designed and developed from the outset to be a highly scalable application. Server infrastructure inherited from proven SAP NetWeaver architecture and Cache infrastructure minimises load on central components, especially the database. Application web servers are added automatically if the load becomes compromised. SAP have full security and infrastructure information on this topic.|
|Service usage metrics||Yes|
|Metrics types||Dashboards and reports are available which detail service up-time and planned maintenance periods. You can ensure the availability of the system is in accordance with the service level agreement of your contract. Define, manage, and leverage consistent KPIs across all your business functions, create and manage reports, run analytical queries, and build predictive models.|
|Supplier type||Reseller providing extra support|
|Organisation whose services are being resold||SAP|
|Staff security clearance||Other security clearance|
|Government security clearance||Up to Developed Vetting (DV)|
|Knowledge of data storage and processing locations||Yes|
|Data storage and processing locations||
|User control over data storage and processing locations||Yes|
|Datacentre security standards||Complies with a recognised standard (for example CSA CCM version 3.0)|
|Penetration testing frequency||At least every 6 months|
|Penetration testing approach||In-house|
|Protecting data at rest||Physical access control, complying with SSAE-16 / ISAE 3402|
|Data sanitisation process||Yes|
|Data sanitisation type||Deleted data can’t be directly accessed|
|Equipment disposal approach||In-house destruction process|
Data importing and exporting
|Data export approach||There are a number of methods for data extraction. The most common is excel download of reports or data sources.|
|Data export formats||Other|
|Other data export formats||
|Data import formats||Other|
|Other data import formats||
|Data protection between buyer and supplier networks||TLS (version 1.2 or above)|
|Data protection within supplier network||TLS (version 1.2 or above)|
Availability and resilience
|Guaranteed availability||99.5% System Availability percentage during each month for production systems.|
|Approach to resilience||Comprehensive SAP Data Centre information can be found at http://www.sapdatacenter.com/|
|Outage reporting||SAP data centres maintain multiple connections to several power companies. Even if local power grid were to fail, the data centres supporting your SAP Cloud solution have an uninterruptible power supply for short-term outages and a diesel generator back-up for longer-term outages. Therefore, power interruptions or outages are extremely unlikely to affect customer data or solution access. Any unplanned downtime will be alerted to customer via email.|
Identity and authentication
|User authentication needed||Yes|
|Access restrictions in management interfaces and support channels||
-Network Filtering IntrusionPrevension systems
-Web application firewall 2-factor Authentication
-Network Admission control proxies and content filtering
-Advanced threat management.
|Access restriction testing frequency||At least every 6 months|
|Management access authentication||
Audit information for users
|Access to user activity audit information||Users have access to real-time audit information|
|How long user audit data is stored for||At least 12 months|
|Access to supplier activity audit information||Users contact the support team to get audit information|
|How long supplier audit data is stored for||User-defined|
|How long system logs are stored for||User-defined|
Standards and certifications
|ISO/IEC 27001 certification||Yes|
|Who accredited the ISO/IEC 27001||Price Waterhouse Coopers (PWC)23rd March 2017|
|ISO/IEC 27001 accreditation date||23rd March 2017|
|What the ISO/IEC 27001 doesn’t cover||https://assets.cdn.sap.com/sapcom/docs/2016/01/08b81ca2-597c-0010-82c7-eda71af511fa.pdf|
|ISO 28000:2007 certification||No|
|CSA STAR certification||No|
|Other security certifications||Yes|
|Any other security certifications||
|Named board-level person responsible for service security||Yes|
|Security governance certified||Yes|
|Security governance standards||
|Other security governance standards||SOC1 SSAE 16 SOC2 ISO22301 SOC 3 Reports|
|Information security policies and processes||Assured by independent validation of assertion. Cloud Trust Centre - https://www.sap.com/uk/about/cloud-trust-center.html|
|Configuration and change management standard||Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402|
|Configuration and change management approach||A formal change management process is in place and is regularly reviewed and approved. This process ensures that change requests are planned, tested, approved, recorded, tracked and maintained and an impact analysis of the change is performed prior to implementation.|
|Vulnerability management type||Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402|
|Vulnerability management approach||Vulnerability Management focuses on identifying, assessing and mitigating common vulnerabilities and configuration issues that might represent a potential risk to the integrity and security of systems or services. The following services are part of the Vulnerability Management System: Vulnerability Scanning, External Penetration Testing and Customer Performed Vulnerability Assessment.|
|Protective monitoring type||Supplier-defined controls|
|Protective monitoring approach||In SAP Cloud Business Applications, an automated monitoring system and operations personnel ensure the system availability 24x7. Security relevant events are logged and retained for 180days in a SIEM (Security Information and Event Management) system. CCTV footage is archived for at least 90 days (or maximum allowed by local law). Monitoring rooms are staffed 24x7.|
|Incident management type||Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402|
|Incident management approach||SAP Cloud implements formal event reporting and follows escalation procedures if an information security incident occurs. Documented security incident response plans for the cloud solutions from SAP ensure that the best possible levels of service quality and availability is achieved. Security incidents are monitored and tracked by security specialists in cooperation with defined communication channels relating to customer until resolved.|
|Approach to secure software development best practice||Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)|
Public sector networks
|Connection to public sector networks||No|
|Price||£44 to £570 per person per month|
|Discount for educational organisations||No|
|Free trial available||Yes|
|Description of free trial||Start your SAP S/4HANA experience now with a free, 14-day trial. SAP S/4HANA is the next generation business suite designed to help you run simple in the digital economy|
|Link to free trial||https://www.sap.com/cmp/oth/crm-s4hana/s4hana-cloud.html|