Bluefin Solutions Ltd

SAP Cloud Platform [SCP]

Providing development services to customers using the SAP Cloud platform to extend existing applications or develop new ones.
SAP Cloud platform is an open platform-as-a-service providing unique in-memory database and business applications. Providing a rich set of application services. Enterprises can quickly build, extend, and integrate modern apps – simply.

Features

  • Database services
  • Analytics services
  • Multi-developer run time environments available
  • Built on Open standards
  • Container services available
  • Mobile
  • Industry standard DevOps tools avialable
  • Security and Identity management built in

Benefits

  • Accelerated application development
  • Developer productivity
  • Low cost PaaS
  • Enterprise grade SLA
  • Simplified IT
  • SAP Supported extension platform

Pricing

£1 per user

  • Free trial available

Service documents

G-Cloud 9

799388227624935

Bluefin Solutions Ltd

Will Howarth

08702330404

William.Howarth@bluefinsolutions.com

Service scope

Service scope
Service constraints Service constraints are defined by SAP and documented in service description document
System requirements Web browser

User support

User support
Email or online ticketing support Email or online ticketing
Support response times For up to date SLA's for response time see T&C document - example SLA
User can manage status and priority of support tickets No
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support Web chat
Web chat support availability 24 hours, 7 days a week
Web chat support accessibility standard WCAG 2.0 AA or EN 301 549 9: Web
Web chat accessibility testing SAP have an internal accessibility compliant plan and an Accessibility Competence Center.
Onsite support Yes, at extra cost
Support levels For up to date SLA's for response time see T&C document - example SLA

P1 Very High: An incident should be
categorized with the priority "very high" if
the problem has very serious consequences
for normal business processes or IT
processes related to core business
processes. Urgent work cannot be
performed.

P2 High: An incident should be categorized
with the priority "high" if normal business
processes are seriously affected. Necessary
tasks cannot be performed. This is caused
by incorrect or inoperable functions in the
SAP service that are required immediately

P3 Medium: An incident should be categorized
with the priority "medium" if normal
business processes are affected. The
problem is caused by incorrect or
inoperable functions in the SAP service

P4 Low: An incident should be categorized
with the priority "low" if the problem has
little or no effect on normal business
processes. The problem is caused by
incorrect or inoperable functions in the SAP
service that are not required daily, or are
rarely used.

The service provides a technical account manager and access to Cloud support engineers
Support available to third parties No

Onboarding and offboarding

Onboarding and offboarding
Getting started The SAP Cloud platform has many resources to assist users - from a comprehensive "Getting started" guide, instructional videos on Youtube as well as community support.
Service documentation Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction Users can export their data using either database tools or the available APIs
End-of-contract process The end of contract process is managed according to the T&Cs from SAP

Using the service

Using the service
Web browser interface Yes
Using the web interface The SAP Cloud platform is fully controllable through the Web interface - from this console all the services are configured, started and stopped.
There is no limitation upon the service available from the web interface, except that which is enforced by security rules.
Web interface accessibility standard WCAG 2.0 AA or EN 301 549
Web interface accessibility testing All accessibility testing is done to meet the standards defined by SAP's accessibility standards which comply with WCAG 2.0 AA
API Yes
What users can and can't do using the API SAP provides both a set of standard and stable APIs but also a marketplace for customers and partners to expose their own APIs to their services. This can be found at https://api.sap.com/#/community
API automation tools Other
API documentation Yes
API documentation formats
  • HTML
  • PDF
Command line interface No

Scaling

Scaling
Scaling available No
Independence of resources SAP does not guarantee the performance of the applications running on it's platform. Only that the resources subscribed to are available for use.
Usage notifications Yes
Usage reporting
  • API
  • Email

Analytics

Analytics
Infrastructure or application metrics Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports

Resellers

Resellers
Supplier type Reseller providing extra features and support
Organisation whose services are being resold SAP

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • EU-US Privacy Shield agreement locations
  • Other locations
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least once a year
Penetration testing approach Another external penetration testing organisation
Protecting data at rest Other
Other data at rest protection approach Other encryption
Secure containers, racks or cages
Physical access control
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach In-house destruction process

Backup and recovery

Backup and recovery
Backup and recovery Yes
What’s backed up
  • Databases
  • Disk Snapshots
Backup controls The users have no control over the backup process, it is automatic and scheduled by the platform.
Datacentre setup Multiple datacentres with disaster recovery
Scheduling backups Supplier controls the whole backup schedule
Backup recovery Users contact the support team

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability SLAs can be found in the T&C documents from SAP.
Commercial refunds are between SAP and customer.
Approach to resilience Available from SAP upon request
Outage reporting Service outage reporting is handled through the following channels
1. Public dashboard - hosted on seperate infrastructure
2. API
3. Social Media
4. E-mail

Identity and authentication

Identity and authentication
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google apps)
  • Username or password
  • Other
Other user authentication SAP Identity management
Access restrictions in management interfaces and support channels Available from SAP upon request
Access restriction testing frequency At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password
Devices users manage the service through Dedicated device on a segregated network (providers own provision)

Audit information for users

Audit information for users
Access to user activity audit information Users contact the support team to get audit information
How long user audit data is stored for At least 12 months
Access to supplier activity audit information Users contact the support team to get audit information
How long supplier audit data is stored for At least 12 months
How long system logs are stored for At least 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 PWC
ISO/IEC 27001 accreditation date 13 Feb 2015
What the ISO/IEC 27001 doesn’t cover Unlisted
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security accreditations No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance accreditation Yes
Security governance standards ISO/IEC 27001
Information security policies and processes Available upon request

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach Yes - Available upon request
Vulnerability management type Undisclosed
Vulnerability management approach Available from SAP upon request
Protective monitoring type Undisclosed
Protective monitoring approach Available from SAP upon request
Incident management type Undisclosed
Incident management approach Available from SAP upon request

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Separation between users

Separation between users
Virtualisation technology used to keep applications and users sharing the same infrastructure apart Yes
Who implements virtualisation Supplier
Virtualisation technologies used Other
Other virtualisation technology used OpenStack
How shared infrastructure is kept separate Available from SAP upon request

Energy efficiency

Energy efficiency
Energy-efficient datacentres Yes

Pricing

Pricing
Price £1 per user
Discount for educational organisations No
Free trial available Yes
Description of free trial Free developer edition is provided by SAP and available at developer.sap.com

Documents

Documents
Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑