The global and independent platform for the SAP community.

Secure on SAP S/4 With Suse and Edge Integration

Regulations such as NIS 2 increase the requirements for data protection and security. The BSI CC EAL 4+ certified Suse Linux Enterprise Server (SLES) fulfills these requirements.
Friedrich Krey, Suse
December 5, 2024
avatar
This text has been automatically translated from German to English.

For companies that want to future-proof their IT systems, SAP S/4 Hana is often the linchpin and the heart of their corporate IT. The sensitive data and business processes that are processed using it must be comprehensively protected. Security should therefore be a top priority when planning the new infrastructure.

With CC EAL 4+: SLES for NIS 2 compliance

A decisive step for IT security is the choice of a secure infrastructure, which is essential for SAP users. Suse Linux Enterprise Server (SLES) is certified by the German Federal Office for Information Security (BSI) according to Common Criteria EAL 4+ and thus fulfills the highest security requirements. This certification confirms that SLES not only ensures the protection of sensitive data, but also offers the entire supply chain reliable security through independent evaluation. For SAP users, this means that they can prove that their systems meet NIS 2 and EU Cyber Resilience Act requirements without any additional effort.

Edge Integration Cell for sensitive data

Many SAP customers are facing the challenge of migrating to S/4 Hana by 2027 as well as replacing existing middleware solutions such as SAP PO/PI. However, not all customers are ready to switch to a fully cloud-based integration solution and want to retain control over sensitive data and interfaces in-house in the future. Organizations from highly regulated industries may also be obliged to do so by compliance requirements or legal regulations.

SAP has developed the SAP Edge Integration Cell for these customers. The SAP Edge Integration Cell is a hybrid solution for the SAP Integration Suite that enables companies to run APIs and integration services locally in their own data center or in a private cloud environment. Developers design their integration flows with the Integration Designer in the cloud and then make them available in a runtime environment in their own network. This enables companies to prevent sensitive data from leaving their network.

Technologically, the first version of the SAP Edge Integration Cell is based on the Suse solution stack. The containerized application runs in a Kubernetes environment that is managed with Suse Rancher Prime. Suse Linux Enterprise (SLE) Micro is used as the operating system. The SAP Edge Integration Cell also uses other open source components such as MetalLB, Redis, PostgreSQL and the cloud-native distributed storage platform Longhorn.

Protection of the entire software supply chain

Users of the SAP Edge Integration Cell also benefit from all the security advantages of the Suse solution stack and are thus able to prepare the SAP Edge Integration Cell for NIS-2 requirements, for example. SLE Micro meets the security standard of the Common Criteria EAL 4+-certified SLES operating system thanks to its common code base - including the independently validated software supply chain.

Suse Rancher Prime - the container management platform of the SAP Edge Integration Cell - also has a secure software supply chain. The solution was recently certified according to Supply Chain Levels for Software Artifacts (SLSA). This framework, developed by Google, aims to ensure the integrity of software when creating binaries. Measures such as an automated build process and complete documentation of origin (Software Bill of Material = SBOM) protect the software from manipulation and enable secure traceability of the source code.


To the partner entry:

avatar
Friedrich Krey, Suse

Friedrich Krey is Head of SAP Alliances and Partners EMEA Central SUSE Linux GmbH and one of our esteemed E3 SAP Community Magazine columnists.


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the second time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

More information will follow shortly.

Event date

Wednesday, May 21, and
Thursday, May 22, 2025

Early Bird Ticket

Available until Friday, January 24, 2025
EUR 390 excl. VAT

Regular ticket

EUR 590 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, March 5, and
Thursday, March 6, 2025

Tickets

Regular ticket
EUR 590 excl. VAT
Early Bird Ticket

Available until December 24, 2024

EUR 390 excl. VAT
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2025, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.