2013 SAP AG or an SAP affiliate company. All rights reserved. ENN: SAP Access Control helps ENN to build Regular Role and Authority Risk Management Mechanism
ENN Group Industry Energy Products and Services Energy distribution, intelligent energy, solar energy, energy chemicals Web Site www.enn.cn SAP s SAP Access Control, SAP Max Attention Partner SAP Active Global Support (SAP AGS) With the operational running of ENN s ERP system, ENN saw an opportunity to clarify the existing position roles and permission authorization to mitigate the potential risk of the current system and to build a comprehensive, complete and regular risk control mechanism. ENN chose SAP Access Control as the solution for IT risk control management, which will help ENN to build a safer, more standardized and universally applicable business risk management mechanism. 2 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
ENN aims to build a leading, global clean energy company Founded in 1989, ENN set its mission by driving and utilizing innovative clean energy. ENN s vision is to provide solutions worldwide and become a leading, global clean energy company. ENN adopted the ideas of Low-carbon economy, recycling economy and smart energy as guidelines. ENN focuses on areas of energy conservation and emission reduction based on independent technical innovation. Effective utilization of traditional energy and renewable energy sources, offers integrated clean-energy solutions for ENN s customers. ENN are providing solutions which fulfill customers increasing demands for energy utilization, energy conservation and environmental protection. and business expansion, ENN has expanded its business footprint into energy distribution, intelligent energy, energy chemicals and solar energy. As of mid-2012, the group had in excess of 28,000 employees with total assets exceeding 40 billion RMB. ENN operates more than 100 subsidiaries, distributed over 20 domestic provinces and across Asia, Europe, America, Oceania and beyond. ENN Energy (formerly known as XinAo Gas Holdings Limited ) is under the jurisdiction of ENN, which takes city gas business as the core, providing clean energy products such as natural gas, LNG, etc. Currently, ENN Energy is the largest energy distribution company in China. ENN started its business in the fuel gas industry. Through 20 years continuous strategy upgrading 3 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
Deploy SAP Access Control based on SAP Core Business Applications As a private-owned enterprise, ENN attaches great importance to IT construction: on one hand, increase capital input on related projects; on the other hand, place great expectations on how mission critical applications, including ERP, BW and CRM could better optimize business operations. SAP Access Control project is a risk management and control project. The project is targeted at mission critical business applications and business process implementation. It aims to discover and eliminate the potential risks in the current system, establish a long term risk control management mechanism to include: emergency account management, business role management and authorization risk analysis through IT solutions. The realization of this project will further regulate the internal personnel s role and lay a solid foundation for function based authorization. The implementation of SAP Access Control solution, not only regulates the authorization functions of existing applications, but also makes use of the built-in risk rules of the SAP Access Control solution. Sap Access Control both analyzes and optimizes new definitions of roles and predicts potential business risk that may come along with specific role definitions. The solution will improve the scientific management of position roles and permissions management, as well as the efficiency of daily management. We chose SAP Access Control solutions to find and eliminate potential risk factors in the existing business systems, to keep daily business operations free from inappropriate roles setting and permission setting. Liu Jian, Project Manager of GRC AC, IT Department, ENN Group 4 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
Leverage SAP Access Control Built-in Rule Base As the original supplier, SAP s risk control solution has a great advantage in its integrated capability and functionality offering. SAP Access Control solution has the built-in business applications and functional rules base which offers hundreds of out-of-box rules for the implementation of risk control projects. SAP Access Control solution can greatly shorten the project implementation duration, save investment in workforce, capital, and time. SAP Access Control solution contains many international customer best practices, and hands-on application examples at home, such as Lenovo, representing a reference role for ENN project implementation. The long-run project cooperation between SAP and ENN enables the building of a strategic relationship. The smooth exchange between the two parties is conducive and crucial to the rapid and timely support for ENN s project implementation. For above reasons, ENN finally adopted SAP Access Control solution to implement the risk control project. ENN also decided to finalize the project by leveraging internal resources and SAP Max Attention together with SAP Active Global Support. It will, on one hand, help ENN to accelerate the project implementation and benefit ENN from the core product functionality of SAP Access Control as early as possible. On the other hand, it can foster and train ENN s own project team, fulfill the knowledge transfer and lay a solid foundation for future risk control optimization. 5 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
ENN upgrades Authority Management and Control The built-in Segregation of Duty (SOD) rule base of SAP Access Control helps ENN review the existing business process, role definition and authorizations, clean up the non-standard role definition and authorization, unify the rules and processes for roles creation and definition. This solution ensures the definition and creation of new roles to satisfy the specific requirement of ENN s risk control. The new role management process requires that any role will be approved and executed in the future, only if the sufficient risk analysis is provided and well performed. After the role is created, the relative authorization utilization of a role should be controlled and audited by SAP Access Control so as to form an overarching authority risk management mechanism. The project team re-classified and standardized the use of Emergency Account based on the progress made in risk analysis and role definition. The routing management was achieved, including emergency account application, approval, authorization, utilization and recycle, which set up a regulation and rule for the emergency account utilization and built an integrated post audit and track mechanism. 6 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
SAP Max Attention safeguarding ENN SAP Access Control Project ENN s SAP Access Control project commenced in September 2012 and was implemented and successfully went live on December 7 within little over three months. SAP AGS and ENN made bold strides during the project cooperation. With the empowerment, assistance and guidance of SAP AGS, ENN completed the project with the least amount of resources, cultivated the competence of the ENN project implementation team. Before and after the implementation of the project, SAP organized intensive training for ENN project teams and performed necessary knowledge transfer. During the project implementation period, SAP provided over 20 technical documents. During the peak of the implementation, a maximum 6 local/ foreign experts were on site to provide technical guidance and implementation knowledge. The project was successfully implemented through successful communication model collaboratively agreed between the two parties. SAP mobilized global resources to safeguard ENN s project implementation leveraging the SAP Max Attention Contract from AGS. Various problems encountered in actual implementation were well addressed in time and with a high level of success. The advantages of built-in templates and rule base of SAP Access Control product, together with powerful technological support from SAP Max Attention team, helped ENN s implementation personnel to quickly complete the deployment and implementation of SAP Access Control products and accumulate massive implementation experience. 7 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
Set up a regular role and authority risk management mechanism The implementation of the SAP Access Control project brings ENN s risk control into a higher level. During the project implementation period, ENN reviewed and adjusted the existing role settings for some important positions based on the builtin rule base of SAP Access Control. As a result, some unnecessary authorization settings and related business risks were eliminated. During the implementation of Phase 1, ENN also carefully reviewed the rules for privileged and emergency accounts with a whole set of lifecycle management processes, ranging from emergency accounts application, approval, utilization, recovery and audit. To match this, ENN standardized the use of Emergency Accounts. The role management function provided by SAP Access Control empowered ENN to redefine, standardize and integrate the authorities for different position roles for the future. The project team could define roles and then analyze and evaluate the business risks involved in authority provision, preventing the problems from being taken to the production environment. Approved role authorities can be defined for different versions with reference to the role version control and batch modification function of SAP Access Control, and then deployed to ENN s subsidiaries at all levels flexibly and efficiently. The outcome of Phase 1 is well acknowledged by fulfilling all the expected functional goals. The empowerment, assistance and guidance implementation methodology adopted, works perfectly well with ENN. Liu Jian, Project Manager of GRC AC, IT Department, ENN Group 8 / 9 2013 SAP AG or an SAP affiliate company. All rights reserved.
ENN Lay a solid foundation for the future After the completion of Phase 1, ENN will leverage the established management platform and risk analysis function to manage and control the regular risk with the newly set up risk control team as the core enabler. ENN can identify, analyze, and eliminate the existing authority risks in enterprise applications, continuously adjust and optimize the business process and role authorization, as well as strengthen the rules on risk management and control. ENN will further promote and deepen the deployment and implementation for other risk management and control functions from an enterprise level. Position roles standardization based on the role definition function of SAP Access Control will be rolled out in future. CMPXXXX (13/03) 2013 SAP AG or an SAP affiliate company. All rights reserved. 9 / 9
2013 SAP AG or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP AG and its affiliated companies ( SAP Group ) for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Please see http://www.sap.com/corporate-en/legal/copyright/index.epx#trademark for additional trademark information and notices.