Rationale for rules in standard ruleset

I'm reviewing the violations reported against out R/3 production system, and I'm struggling to understand why some of them, particularly in the "Basis" business process, are SoD violations. Is there a list or document somewhere that explains the thinking behind the standard rules and what issues they are trying to highlight. There are some rules I'm tempted to disable, but there's a nagging doubt in my mind that I might have missed something and disabling the rules would be a really bad idea! Obviously somebody, somewhere, thought all of these standard rules were right for them...
For example, we have some users that have transaction SE16 (display only) and transaction SM50. This trips over risk B009, but why? What am I missing?
Thanks,
Steve.

Thanks. Yes, I'm quite happy with the approach we're taking. Some of the default rules obviously don't apply to us and have been disabled. Some have needed fairly obvious changes before they are appropriate for us. Those rules have been copied, and the copies changed and the originals disabled - doing the same to affected functions where necessary. This gives us an easy audit trail. All of this has been done with the help of our internal auditors.
What we're left with now are rules that our users are triggering, but we don't understand well enough to know why. I like to think I have quite a devious mind, and so if there's a possible exploit somewhere I can figure it out. But some of the standard rules I just don't understand at all. Somebody, somewhere, must have thought all these rules worth including in the standard ruleset, so there must be an exploit hiding in there somewhere. That's what makes me nervous about disabling the ones I don't understand. It would have been really nice if the people compiling the standard ruleset had kept, and published, notes about why each rule was there and what it was intended to detect, rather than letting each customer figure it out for themselves. Yes, we're all different and need a different customised ruleset, but that doesn't mean we don't need to know what the standard rules are there for. We need to understand the starting point before we can be sure about what we get when we customise it.
Sorry. Rant over...!
Steve.

Similar Messages

  • Looking for a copy of the standard ruleset for CC GRC 5.1

    Our Corporate Controlling office wants a SoD report for both our customized CC ruleset and the standard Virsa ruleset.  However, the consultants we used to implement did not keep the standard ruleset (or back it up).  Does anyone know where I can find the standard ruleset.

    It comes with installation. You can always download the installation from service marketplace and extract the ruleset out.
    Alpesh

  • Can AAMEE 3.1 create pkg for CS6 Design Standard?  or just CS6 Mast Collection?

    can AAMEE 3.1 create pkg for CS6 Design Standard?  or just CS6 Mast Collection?

    ok, thanks,  just wanted to make sure. I have a volume serial no.   for CS6 Dest Stan.
    AAMEE 3.1 is for CS6 Suite,  so should be good for all CS6
    I created a pkg for CS6 Mast Coll using AAMEE 3.1 a few months ago and works fine  (.msi)

  • What is this message: Base Line Date for rule 11 not set ?

    Hello all,
    I am doing some test.
    Cenario:
    I need to create a Scheduling Agreement in transaction: VA41
    The material I am using to create the VA41, I have just created.
    I created in MM01 the views: Basic Datas 1 and 2, Sales View 1,2 and 3 and Account View 1.
    Issue:
    When I am creating the VA41 and I enter the material, the system shows the messages:
    1) Dates from:: Base line date for rule 11 not set
    2) Dates from:: Base line date for rule 9 not set
    *obs: the messages dos not block the creation of VA41. It is a information message.
    Question:
    What that means? What will happen if I do not fix that? What should I do in order to not have more these messages?
    Tks & Rgds,
    Barbara
    Message was edited by:
            Barbara Barbos

    Hi
    Please check whether you have assigned - payment terms both at company code and sales area level
    VVR

  • E613 SYST: You cannot determine the period for rule 03

    Dear All,
    We are configuring asset module and using MSTL dep key for Tax books. When we tried to create an asset with MSTL dep key, we encountered error - 'E613 SYST: You cannot determine the period for rule 03'. when verified config OAVH Define Calender Assignments transaction,  Period control '03' is missing for fiscal year variant K4. Period control is exisiting  in Maintain Period Control and but not in Define Calender Assignment. What I understand these period controls are being delivered by SAP. Not sure why period control '03' is missing.  all other period control keys are available.
    question is how to add period control 03 so that we can use MSTL dep key. we are currently using 4.7c. Any suggestions would be appreciated.
    thanks
    Sunil

    message went abruptly before I finish.
    +++++++++
    continuing from previous email
    Period control 01 has following entry in the transaction
    Fiscal Year Variant        Per control          Name of the period control             Year      Month      Day      Period        Mid Month
    K4                                      01                        Pro rata at period start date        blank       0            0             blank        not selected
    If I follow SAP help to define period control '03', then I just need to copy period control '01' which is listed above and select 'Mid Month' check box.
    Wondering anyone did this in the past. MSTL depreciation key is being used in MACRS tax for US. I am sure people who  have implemented assets module for US with tax dep, they might have encountered this issue.
    thanks
    Sunil

  • Documentation for Adobe Design Standard v6

    installation and documentation for Adobe Design Standard v6

    And exactly what is it that you are asking? You need to speak in comprehensible sentences rather than regurgitating bullet points....
    Mylenium

  • Rationale for Repairing Disk Permissions

    I repair permissions before and after installations, and I suggest others to do so. However, I have read in some threads in Discussions there there is no technical basis for repairing disk permissions before installation, and that only repairing after installation is necessary.
    I realize that there are different opinions about this, but beyond opinions is there a technical basis or rationale for repairing disk permissions before installations?
    Thanks.
    cornelius
    Message was edited by: cornelius

    Hi cornelius,
    Here is some reading about this topic. Mind that Apple DOES recommend repairing permissions as routine maintenance (see links at the bottom)! My suggestion to Repair permissions before and after an update has a very simple rational: If you forgot to repair permissions AFTER the last update you might get into trouble. Therefore it is safe and costs only a few seconds to do it before and after the update.
    mac.column.ted: Unravelling the Repair Disk Permissions controversy
    "Ted Landau
    May 2006
    Repairing Disk Permissions. Not exactly a topic that you would expect to spark much controversy. Yet, surprisingly, it is the focal point of a rather heated debate.
    The command itself is innocuous enough. It is included as part of the First Aid component of Disk Utility. Apple's Help for Disk Utility states: "User permissions associated with files, folders, or applications can become damaged and prevent a file or application from opening. Permissions problems can also cause your computer to run slowly. Using Disk Utility, you may be able to fix these permissions problems...Repairing permissions may also be recommended after updating the system or installing new software."
    Consistent with this, many users and Web sites (including MacFixIt and at least some postings on MacinTouch) recommend the use of Repair Disk Permissions, not only for specific signs of trouble, but as a part of generic troubleshooting and ongoing maintenance for your Mac.
    In contrast, other members of the Mac community (writing in locations such as the Daring Fireball , Unsanity, and the MDJ) argue that running this command just for maintenance, in the absence of any particular symptom, is essentially worthless. Some critics go even further and claim there is no justification for ever selecting to repair permissions. Not only is it useless, they contend, but it may even cause new problems to appear. This viewpoint is often expressed with inflammatory rhetoric such as "covering yourself in Vaseline and rolling around naked in the dirt and repairing permissions are just as likely to fix your Mac OS X problem" (Unsanity).
    Regardless of who's right or wrong, I don't believe that insulting users is merited here, especially when these users are simply following advice suggested by Apple itself. As it turns out, I also do not agree with the position of these critics. So, although I may be stepping into a minefield, here's my own take on this subject and my resulting recommendations. [Disclaimer: I was not involved in the authorship of previous MacFixIt articles on this subject. This column is my separate opinion, and does not necessarily reflect the views of MacFixIt.]: Continued"
    Mac OS X 10.3 Help: "It's a good idea to repair disk permissions as a regular maintenance task after upgrading or installing new software."
    Mac OS X 10.4 Help: "It's a good idea to repair disk permissions as a regular maintenance task after upgrading or installing new software."
    Randy B. Singer: Macintosh OS X Routine Maintenance

  • Windows 8 download for Acrobat 9 standard ed

    Since I "upgraded" to Windows 8, I can't make pdfs any more
    Where is the download I need to continue to use Acrobat 9?

    Kencohn I would recommend contacting our support team if you have previously purchased the software via electronic software download.  They may be able to re-enable the download for you.  You can contact our chat support at http://adobe.ly/yxj0t6. 
    Please be aware however that our support team does not provide installation support for Acrobat 9 Standard any longer.  You can find more details regarding the supported versions of our software at Adobe Support Policies: Supported Product Versions - http://www.adobe.com/support/programs/policies/supported.html.

  • How to create an IDOC as an output type for an SAP standard transaction

    Hi ,
    How to create an outbound IDOC as an output type for an SAP standard transaction.
    Regards,
    Beena

    In NACE tcode u can create output type with medium as EDI,
    u can assign the entry sub routine as ENTRY_EDI in RNASTED

  • How to switch licensed for "ADOBE DESIGN STANDARD" from iMac to Macbook Pro?

    I am currently licensed for "ADOBE DESIGN STANDARD" on an iMac. I have a new MacBook Pro and want to use that instead of the iMac. Do i need to get a new license key? or ??
    I know i can download an "eval" copy on the laptop, but how do i switch license keys? i'm not even sure i still have the (valid) license key for the iMac...can i request another??

    As long as you are staying within the same general platform (PC vs Mac) you do not need to change licensing.  You are allowed to have two activated installations with your license, so you should be able to install on the new machine without having to worry about the older one at all (unless you ever want to free up the second activation for yet another machine).  As you mentioned, you can download the trial version and use the serial number from your purchase to activate it to full use.
    If you registered your software with Adobe, the serial number should be available via your Adobe account online.  If you didn't register it then you will at least understand why it pays to do so. 
    IF you end up needing to resolve any issues with activating the product on the new machine you will need to contact Adobe Support directly.  Here are some links to help make contact:
    http://www.adobe.com/support/chat/ivrchat.html
    http://www.adobe.com/support/download-install/supportinfo/

  • I retrieved my serial number for Acrobat 8 Standard from Adobe because my system crashed.  I went to the downloads and can only retrieve Acrobat 8 Pro.  The installer will not take my serial number what can I do?

    I retrieved my serial number for Acrobat 8 Standard from Adobe because my system crashed.  I went to the downloads and can only retrieve Acrobat 8 Pro.  The installer will not take my serial number what can I do?

    Hi floyd99,
    You can download Acrobat 8 Standard from : https://files.acrobat.com/a/preview/80aa8c58-2951-494e-808a-fb61a6b4aa29
    Reagrds,
    Rave

  • Tables for rule sets

    Hi,
    Can you provide me the tables used for rule sets, activities, task etc in EM

    Hi Dipak,
    Below are the EM tables requested.
    Regards,
    Jonathan Hansen
    /SAPTRX/ACTIVITY – Activity Header Table
    /SAPTRX/ACTIVTXT – Activity Text Table
    /SAPTRX/ACT_TASK – Multi-Task Activity Task Table
    /SAPTRX/ACT_TSKT - Multi-Task Activity Task Text Table
    /SAPTRX/EM_RLSET – Rule Set header table
    /SAPTRX/EM_RLSTX – Rule Set text table
    /SAPTRX/EM_RULE - Rule table (Rule Set item)
    /SAPTRX/EM_RULET – Rule Set text table

  • Lost CD for Acrobat X Standard

    How do I replace or download a replacement Cd for Acrobat X Standard?

    Hi Kaner21,
    You can download Acrobat 10 Std. from: http://helpx.adobe.com/acrobat/kb/acrobat-downloads.html
    Regards,
    Rave

  • Table for rule details.

    Hi All ,
    I have written a rule in transformations. I want to see the details of rule like description , technical name etc. Is there any table where I can find out these details.
    Thanks & Regards,
    Rohit Garg

    Hi,
    RSTRAN - Transformation 
    RSTRANFIELD - Mapping of Rule Parameters - Structure Fields 
    RSTRANRULE - Transformation Rule 
    RSTRANSTEPROUT-  Rule Type: Routine 
    RSTRANRULESTEP - Rule Steps for a Transformation Rule 
    RSTRANSTEPMAP-  Mapping for Rule Step Within a Rule

  • Where is the download link for adobe 9 standard

    where is the download link for adobe 9 standard?@

    Downloads available:
    Suites and Programs:  CC 2014 | CC | CS6 | CS5.5 | CS5 | CS4 | CS3
    Acrobat:  XI, X | 9,8 | 9 standard
    Premiere Elements:  13 | 12 | 11, 10 | 9, 8, 7 win | 8 mac | 7 mac
    Photoshop Elements:  13 |12 | 11, 10 | 9,8,7 win | 8 mac | 7 mac
    Lightroom:  5.7.1| 5 | 4 | 3
    Captivate:  8 | 7 | 6 | 5
    Contribute:  CS5 | CS4, CS3
    Download and installation help for Adobe links
    Download and installation help for Prodesigntools links are listed on most linked pages.  They are critical; especially steps 1, 2 and 3.  If you click a link that does not have those steps listed, open a second window using the Lightroom 3 link to see those 'Important Instructions'.

Maybe you are looking for

  • Windows 7 won't print pdf to network printer connected to Mac

    Hi, I have a printer connected to my Mac and have shared the printer on my home network.  I can print documents from a Windows 7 computer on my network but when I try to print a pdf from adobe reader it will not print, or ever go to the print queue. 

  • Session problem in BSP

    Hi, I have a Stateful BSP application running from portal. In this application INIT method is not called. Do_REQUEST is the first method to get executed. While testing in portal I logon with user id user1, after some testing, I logout using logout bu

  • Drop Zone Animation

    Is there a way to make a drop zone slide across and off screen in DVD Pro, or is this something you must do in motion?

  • CIN reporting in BW

    Folks, I would want to extract data from the CIN tables (Excise table for Country India)for reporting in BW; The tables are as follows J_1IEXCHDR J_1IEXCDTL J_1IPART1 J_1IPART2 J_1IGRXREF Appreciate if people out there could share   your experiences

  • Skype Premium for one account within Skype for Bus...

    Hi! Can I purchase Skype Premium for one account (not the administrator) within my Skype Business account?