Mulltiple Rule Sets in GRC 10.0 for one System

Hi All,
We do have 2 different companies working on one system and by that 2 different rule sets that are applicable.
Due to that we are facing different problems we don't know how to solve yet but lets start with the first one dealing with the rule set that should be used in the access request.
We want to determin which rule set should be used over the requested role (e.g. if role name contains 0001 use rule set 0001, if role name contains 0002 use rule set 0002).
We have alerady tried several different senarios in BRF+ without success.
Does anybody have a solution or at least an idea for this topic?
Thank you all very much in advance!
Eva

Hi Ashish ,
Thanks for your time . Let me explain you my requirement and would really appreciate if you would have some inputs here which would help me to design this .
The actual client requirement is to design a CUP Workflow and If there are SOD issues identified, the workflow will need to go to a central team for them to address each issue. If this group decides to apply mitigating controls to the issues, the workflow must then go to the compliance group for them to review for appropriateness. Requirement is do a SoD analysis for every role change/add request , so that this group takes the appropriate action based on the SoD Analysis . For all my CUP request raised , i want system to do a SoD analysis and let this group know whenever there is a SoD found or just end the workflow if there is no risk.
I am aware of the Risk analysis process for GRC 10.0 , however i want it to happen as a part of this work flow requirement.
The requirement is to configure the access request work flow so that the end goal of work flow is just facilitation of an SOD review.  I hope i was able to explain my requirement . Thanks again for your help.
Your valuable guidance would be really appreciated.
Vikas

Similar Messages

  • I set a Special Ring Tone for One of my contacts and now I want to set the standard tone again. How can I adjust the iPhone to always use the standard tone?

    I set a Special Ring Tone for One of my contacts and now I want to set the standard tone again. How can I adjust the iPhone to always use the standard tone?

    Yeah, I did. But if I go to settings and change the standard ring tone again, the ring tone for that special contact is still the old standard tone. But I want to 'tell' my iPhone/iPad that this contact should always have the standard ringtone from settings.

  • HT204053 Is there a way to set up subsidiary email addresses for one appleID?

    My children now each have an iPod touch and I'd like to set them up with, for example, the ability to facetime my wife or me without having to set up a new AppleID for each of them. All our music is consolidated on my AppleID and I don't want to change that!

    You can create up to three email 'aliases' on your account - these are additional addresses (not accounts) which deliver into your inbox.
    BUT
    You will get all their mail and they will get all of yours: and once created you can never move that address away from your account to become a separate account, so that when your kids grow up and don't want you reading their email they won't be able to keep the same address.
    So I would strongly advise you not to do that, but to create a new and separate iCloud account for each of them. You will find that much more practical and convenient.
    There is no problem about iTunes: just go on using the same login for iTunes - it's perfectly possible to be using one ID for iCloud and another for iTunes, iTunes Match and iTunes in the Cloud.

  • SMSY//Logical component definition - multiple roles for one system?

    Dear all,
    as our client has a divided system landscape (three-tier operational line as well as two-tier development line) some systems have more than one role to fill. The development system on development line is source system for all developments, as well as post-processing system for retrofit purpose from operational line. The maintenance system on operational line is target system for developments from development line, as well as source system for maintenance activities on operational line.
    --> What are the consequences of assigning multiple roles to one system?
    --> Is there anonther option than assigning multiple roles?
    Best regards
    Nick

    We have Event Manger 7.0 installed into a stand-alone SCM 7.0 system. When trying to set this up in SMSY, the only options given for setting up the Logical System is to associate with with EHP3 or EHP4 for in ECC 6.0.
    Obviously we have not installed EM into ECC. So where are the other appropriate entries in SMSY for recognizing that EM is installed in SCM?
    1) This system must be maintained as SCM 7.0 in SMSY and not as SAP ERP 6.0 or EHPX for SAP ERP 6.0, this is the reason as you can see this system SCM 7.0 can be assigned just to SAP ERP 6.0 or EHPX for SAP ERP 6.0.
    2) There's no Main Instance available to be selected when you have a SAP SCM 7.0. You must select one or more of the following main instances below.
    BI Content
    SCM Server
    cFolders on SCM Server
    GEOCODING
    Portal Content
    SAP LiveCache
    SAP NW - Adobe Docu. Service
    SCM Optimizer
    SCM WCL
    XI Content
    These are the main instances available to SCM 7.0

  • Installation Wizard for one system

    Hi,
    We have only one system which will act as SCL and backend server. Can we try to deploy using Installation wizard? If yes what should be the number i mention to "Connect to SAP systems". Also what are the other requirements which I should care in this case? I mean the trust, rfc destinations, users etc.
    Please let me know.
    Thanks,
    Rahul

    Hi Holger,
    I have 1 more doubt about the wizard. If there is 1 error at any step, i know we can execute that step again but what will happen to entries which were created sucessfully. will they be overwritten or they won't be created.
    For e.g. In step 2, some tasks were successfully created but 2 or 3 task failed. Now i will again execute the wizard for Step 2. My question is what will happen to the task which got created successfully?
    Thanks,
    Rahul

  • E2000 setting priority is not working for one PC

    my home has a max download speed of 300 KB/s. which can make gaming quite an issue if someone in the house starts using something that is a bit of a drain on the bandwidth.
    i fixed the issue for a few months by setting the gaming console to be the only device with high priority. but for some reason my sisters hp laptop still drains all the bandwidth shen he loads youtube. and the only way to stop it is a mac address block on that computer so the game isnt literally frozen still.
    i need to figure out how to get the priority working against this device.

    In this section, you can set the bandwidth priority for a variety of applications and devices. There are four levels priority: High, Medium, Normal, or Low. When you set priority, do not set all applications to High, because this will defeat the purpose of allocating the available bandwidth. If you want to select below normal bandwidth, select Low. Depending on the application, a few attempts may be needed to set the appropriate bandwidth priority.
    To Enable QoS service on your router you can follow this link and follow the steps on the website: http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&docid=05ef4bac579a47d39d9454a4b0583cbf_1701.xml&pid=80&r...
    Second, let me know the current firmware version in the router management page: http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&docid=df680dece5cd4f7ea8141ea0026db71a_4046.xml&pid=80&r...

  • Unable to set property Refresh Completed Items for UWL system

    Hello Experts,
    We are on NetWeaver 7.40 SP2 and UWLJWF version is 1000.7.40.2.0.20130411234700.
    We have configured a system object with system alias SAP_ECC_HumanResources pointing to the backend ECC system.
    I am creating a UWL WebFlowConnector system with this same system alias in the UWL Administration page to fetch ABAP Workflow workitems from the backend and display those in the portal UWL.
    When I try to check the checkbox for the Refresh Completed Items: property and click Save it shows me an error message saying Could not connect to back end SAP_ECC_HumanResources to check if it supports direct custom retrieval feature.
    I have already followed the steps for Prerequisites for Enabling Refresh of Completed Items and Activation in Back-end System mentioned in the link Enabling Refresh of Completed Items but still getting the above error.
    I have also tried restarting the UWL service as given here (UWL) Error while configuring the Refresh of Completed Items Mechanism
    Can anyone give any suggestions what else needs to be checked for this property to work for the UWL system?
    Regards,
    Saurabh
    Message was edited by: Vera Gutbrod

    Hello Experts,
    I have managed to resolve this problem. The RFC Destination configured for UWL WebFlowConnector had some problems and it was not able to ping to the backend system. I got this RFC Destination re-configured and then restarted the UWL service and following this I am now able to set the Refresh Completed Items property for the UWL WebFlowConnector system.
    However now when I am trying to set a value of 30 seconds in the Delta Pull Channel Refresh Period (in Seconds): property and saving the change, I am getting a warning message The backend of system SAP_ECC_HumanResources is not configured for optimized delta pull.
    How do I go about setting this value for the delta pull refresh?
    Regards,
    Saurabh

  • How to Set Up Multiple Muse Files for One Site

    I'm creating a massive web site, currently over 900 pages, heavy on images and file downloads. Currently the file size is 700 MB and growing. Muse starting moving PAINFULLY slow (just pasting a text box is taking over 15 minutes, all while the rainbow ball spins), but with smaller muse files everything works great. Due to the slow down, I want to be able to break up the file into sections but not sure how to export and upload the site to work properly.
    Is it as simple as deleting the extra sitemaps/index pages?
    If needed, working on iMac, OSX 10.9.2; 2.7 GHz Intel Core i5; 8 GB ram.
    Thank you in advance for any help.

    Hi Andria,
    Please refer to the reply by Zak in this post, Re: How large of a site can muse handle?
    You can use the above thread for any follow up questions that you might have.
    - Abhishek Maurya

  • Access Control Rule Set deletion in GRC 10

    Greetings,
    Has anyone tried deleting rulesets or have experienced any issues while deleting rule sets in GRC 10. I have tried to delete them from SPRO as well as from Setup Tab in Access Control , however its not working for me . Even in SPRO , after chooseing the physical system and logical system infromation , it stays on that screen for ever and nothing happens.
    Any help or guidance here will be much appreciated.
    Thanks everyone for your valueable time.
    Vikas

    Hey ,
    There are no tricks or tips.  It was something stupid on my part.
    I Just had a look at the system again and found a function left in the system which was mapped to this Ruleset , so that was the only i was not able to delete the ruleset . As soon as i deleted that function , it worked .
    So i was able to delete the entire rule set after deleting all the risks and functions mapped to this rule set.
    Have a great day ahead ...
    Vikas

  • GRC AC Rule Sets

    Hi
    We have a requirement of building up a custom rule set for our organization. The current requirement is to have a central rule set across for all system and have subsequent system specific Risks identified in addition.
    Scenario: Letu2019s say we have identified around 100 risks across the enterprise, however only 50 risks out of 100 risks are applicable for one system. While for the second system there are around 70 risks applicable. Finally for the third one all 100 risks are applicable.
    Should we have system specific rule sets to address the above scenario or should we have a common rule set for the enterprise.
    Appreciate your inputs about the approach for building up of rule set for such scenarios.
    Question: With GRC 10.0, can we run risks for a system on multiple rule set IDs at one time.
    Thanks.
    Anjan Pandey

    Hi,
    Most of the clients will prefer to go with one rule set. However System can allow create/maintain multiple rule sets.
    Anyway your requirement is to have one central rule set across all systems u2013 For that, Create Logical system and maintains one Rule set is the right approach and it gives flexibility for future usage to add /remove required systems. You can maintain risks by system specific, not required to maintain multiple rule sets.
    Refer  GRC Access Control Effective Rule Set Design document,  it gives some good explanation of Rule Set Design&typical Scenarios, Logical & Physical systems approach..etc.
    Regards,
    Ram
    Edited by: ram komma on Apr 13, 2011 1:55 PM

  • GRC53 Rule Set Migrated into GRC10

    Gurus, has anyone encountered the following situation. We migrated our 53 rule set into GRC 10 using the Migration Tool. On the surface all of the rule objects seem to move across as they should. We then began to run our risk reports. We noticed that for the same user, in the same backend ECC system, we get varying results from our 53 Rule Set which is in our GRC10 system vs the 5.3 Rule Set executed from our old 5.3 system. We see more violations returned from our old 5.3 system; entire risks are not reported from the GRC10 system.
    Consequently, I began reviewing the functions (actions/permissions). I picked a specific risk that was returned by the 5.3 system and reviewed it, line by line - comparing the 53 Rule Set in GRC10 against the 53 Rule Set in the 5.3 system. Everything lined up, with the exception of the activity values. In the 53 Rule Set that was migrated into GRC10 the activity values are single digits (1,2,5, etc) where as in the 5.3 System the activates are two digits (01, 02, 05, etc), Since the values are mainatined in SAP as double digits, could this be causing this? I would hope this is not the culprit, but I am unsure where else to turn.
    I will say for those risks that were returned in the results, the activities in those functions were single digits as well.

    Hi Penn,
    Can you check if your default SoD risk level is "Critical" and hence all the conflicts are not being thrown in 10.0
    There is an SAP Note 1632864 where you need to maintain parameter 1024 and se tthe default risk level to High. Since there is no option of All in 10.0 similar to 5.3
    Thanks and Best Regards,
    Srihari.K

  • CC / RAR 5.2 - Multiple Rule Set Question

    How does the system handle the use of multiple rule sets in CC / RAR 5.2?
    For example, letu2019s say I want to keep a standard SAP rule set in tact to use for testing and comparison in RAR, but I also want to load another one.
    I realize that only 1 can be the u201CDEFAULTu201D so what does that mean?  I know that a risk analysis is only run against the rule set you set as default.  I also know that you can select the rule set to use in processing when you manually run either through Informer or Configuration tab a risk analysis.  What I am really concerned with is what happens if you take the results to u201Cmanagement reportsu201D from 2 different rule sets?
    First, can you even do it?
    Second, if you can, then I think you must have to come up with a different RISKID configuration schema for each rule set otherwise, I do not see how you can differentiate from which rule set the violation is generated.  That said, you will also need to export the report information into Excel and make any u201Crule set sortu201D there as I donu2019t see a way to do it directly in RARu2026.maybe a future improvement?
    Can anyone confirm the impact of multiple rule sets and how you manage them?
    Regards,
    Greg

    Greg,
    You can maintain the different severity levels for different Rule Sets. For example, in one Rule Set you can keep the "Critical" Risks and in other you can keep "High", "Medium" & "Low". Run your analysis against first Rule Set if you want to know the "Critical" Risks and second Rule set you can use for rest of the severity levels. I hope this way you can manage your multiple Rule Sets in RAR.
    Thanks,
    Tavi
    SAP Security & GRC Consultant.

  • GRC AC 10 (RAR/CUP/ERM) configuration for EP system

    Hello Gurus,
    We are aware of configuring RAR/CUP/ERM in GRC AC 10 for ERP system(back-end)
    Are there any documents /links to provide information on configuring the above components for EP system ??
    Or rather specific which of the following configuration is possible for EP system ?? CUP /RAR/ ERM ??
    Also going further , is there any way in which we can configure the same for BO system ??
    I am not quite sure if there is any PLUG-In as such which is available for BO system or not .
    But in my opinion there is no need to perform configuration for BOBJ system as the roles in them are imported from Backend system (ERP/BI etc) , hence if these roles are already taken care during ERP system cleanup and SOD analysis , there should be no need to configure seperately RAR/ERM/CUP.
    Please provide your comments.
    Regards,
    Victor

    Hello Prasad,
    Thank You for your quick response .. the info was quite helpful.
    Will you please put some light on aspects of integrating AC 10 with BO ??
    Is there any connecter available for it?? Which scenarios are possible ??
    Humbly Requesting your help.
    Thanks in advance.
    Regards,
    Victor

  • Minimum Trusted RFC's for productive system

    Hi!
    We have very strict requirements dealing with set up of Trusted RFC for productive system for ChaRM approach in SOLMAN.
    Can some one tell me which Trusted RFC's and users for the productive system do I need?
    a) Trusted RFC is not mandatory for the productive system
    b) Trusted RFC only in productive system, client: 000, users: 1 communication user and 1Dialog user
    c) Trusted RFC in productive system for  each client with users...
    Thank you very much!
    H. Thomasson

    Create the function modules in SE37 and set the remote-enabled flag in the attributes section. Then import them into XI.
    Create a custom Z table through SE11 on each system to store any data, and the code in each function module would reference it. (Either that or just hard-code everything)
    In short yes it can be done through SE37, no you don't need SE38.
    I think you're talking about function groups which is a container for the function module. You can do everything through SE37 if you use the Goto->Function Groups-> Create Group option and give it the same name as your Function Module.

  • TMS configuration  for multi-clients in one system

    Hi All,
    we have got some problem defining transport routes in stms in transport domain...
    We have to add to target group for one system 6 clients:3 clients with the dev/test roles for country X and 3 clients with dev/test roles for country Y.
    Transport requests have to route only between clients for defined country (only for country X or only for country Y, must not mix).
    How i can get status when transport requests will route in one system only between clients of country X (or only for country Y)?
    Should i define two target groups and add to one group 3 clients for X and to the second 3 clinets for Y? I am not sure that it is enough. May be exists a lot of other options/ actions?
    Where is garanthy that requets from country X will not mixed with requests from Y?
    Thanks a lot.

    > The SSO is working fine for only the client which we used to import the certificate (verify.der).
    > 1>Is it that the certificate import should be done from all the clients exclusively ?
    Logon ticket certificate is instance wide, not client dependent. And you need to call STRUSTSSO2 in client 000 to export/import.
    > And the SSO is not working for other clients  in the same system .
    > 2>If yes  can you tell the procedure, why b'coz transaction STRUSTSSO2 is same for all clients and if we try to import the certificate again how about the existing one over there ?
    Could you provide more details about this issue you're facing? What is the Portal UME source? What application is it based on, BI or ESS/MSS?

Maybe you are looking for

  • Allow a simple form with "data" to be saved by the user.

    Back in version -x, it used to be so simple.  You created a form that could be read in a web browser.  Users could could fill out the form and save the form to their computers with their data.  Since that first version that allowed that, Acrobat has

  • Calendar Year

    "Members who spend $1500 in a calendar year earn My Best Buy Elite status with enhanced benefits like a 10% point bonus." Does Best Buy refer to a calendar year as 1/1-12/31 or a period of 365 days?

  • Item interest calculation configure

    < MODERATOR:  Message locked.  Please read the [Rules of Engagement|https://www.sdn.sap.com/irj/sdn/wiki?path=/display/home/rulesofEngagement] before posting next time. > hi , friends can you anyone send me the configuraton of item interest calculati

  • My HD took a dump over this 10.4.8 business

    Hello, I know quite a few others have experienced this problem and found no fix so far, but I wanted to create a thread about this specific problem we're having... After installing 10.4.8 onto my 12" ABook, it started behaving erratically and then st

  • Mirroring Content Viewer / Published DPS

    We are still in the testing phase and still using the free Content Viewer on our Original iPad and iPad 2. I've looked for this information but haven't been able to find anything. Does anyone know if your able to mirror Content Viewer to a projector?