Quantcast
Channel: SCN : Popular Discussions - Governance, Risk and Compliance (SAP GRC)
Viewing all 1383 articles
Browse latest View live

Connecting BW to GRC 10.1

$
0
0

Hello

 

We're implementing GRC 10.1 as part of a transition from 5.3. We have been able to configure the system correctly for ECC (Role Import, Provisioning, FF), however we haven't been able to configure successfully the BW connection.

Right now to do a Role Import we're able to see the Landscape but can't populate the Source System for BW.

 

We configured the BW sandbox as BI and as SAP in the connectors to test both scenarios but we just can't see the Source System. We can see the Landscape when we select either SAP or BI, but can't populate the Source System to show the BW RFC connection.

 

If you have a doc or a link I can check out to configure systems other than ECC for GRC that would be great!

 

Thank you very much.

Maria


SAP GRC How does Mitigation Monitoring work ?

$
0
0

Hello All,

 

I am trying to learn the processes related to mitigation control monitoring. I understand a control requires an approver and a monitor. So what functions
does the mitigation monitor perform ?.

 

I'm interested in any reports that need to be working that would be employed by the monitor. Is there an enforcement mechanism logging or reporting
when the monitor runs related reports on mitigating controls ?  Also, is there available documentation on this
process ?

 

All information on this topic is welcome.

 

Thanks !

Jamie

Role was not found in ARM

$
0
0


Dear Colleagues,

 

Could you please assit me here.

 

I have created the role in the system ( Development ) and I logged in as a role owner  and approved the role .  and  the request is completed status .

When I went raise to riase a request , I could not find  the role  I have created .

 

I have dont the repository sync and tried again , but didn't work.

 

Could you please assist me ?

 

Should I first transport the role production  and raise a request ? If yes can you also mention how we shuld transport the role

 

 

Thanks and Reagds,

RAghu

security grc interview questions

$
0
0

1. What are the components of GRC?

2. What are the upgrades happened in GRC 5.3 from GRC 5.2?

3. Is it possible to have a request type by which we can change the validity period of a user? If possible, then what are the actions?

4. What's the latest Support Pack for GRC 5.3? How it differs from the previous one?

5. What are the issues faced by you in ERM & CUP after golive?

6. Can we change Single roles, objects & Profile description through mass maintenance of role? If yes, how?

7. What are the prerequisites for creating a workflow for user provisioning?

8. How will you control GRC system if you have multiple rulesets activated?

9. Can we view the changes of a role, happened in PFCG, through GRC?

10. How will you mitigate a user against an authorization object which is decided as sensitive by Business?

11. Give an example of SOD with object level control & also decide the Risk implication from the Technical standpoint.

12. Is it possible to assign two roles with different validity period to a user in one shot through GRC? If yes, how?

13. What's the use of Detour path? How Fork path differs from Detour path?

14. How can you enable self password reset facility in GRC?

15. Can we have customized actions for creating request types in CUP?

16. Which SOX rules got inherited in SAP GRC?

17. How many types of Background job you are familiar with? Why Role/Profile & User Sync. job is required?

18. Where from can we change the default expiration time for mitigating controls? What's the default value for the same?

19. How will you do the mass import of role in GRC?

20. Explain the total configuration & utility of SPM?

21. Can we create Logical systems in GRC? If yes, how & what can be the advantages & disadvantages of the same?

22. Can we have different set of number ranges activated for request generation?

23. Explain, how can we create derived roles in ERM? What will be the significant changes in methodology for creating composite roles?

GRC 10.0 MSMP Workflow configuration

$
0
0

Hello,

 

I have tried doing the MSMP workflow configurations as per AC 10.0 Customizing Workflows for Access Management.pdf

 

But still i am not getting idea about what many things like, in 5.3 we configure stages, and we include multiple stages in one path.

 

Can any one explain in details how to configure stage and paths...

 

Regards,

Sumanth

GRC 10 : EAM Logs are showing 'No Records'

$
0
0

Hello  Experts,

 

I am working on GRC 10 EAM configuration at SP07.

 

The EAM Firefighting scenario is working on ie.Firefighter can login to backend R3 system and performed

 

FF activities but when i update the FF Logs GRC system doesnt show any logs in the system.

 

The logs are present in R3 system in STAD, CDPOS, SM20 etc.

 

The TIme Zones are same in both GRC and R3 system.

 

But Except Table GRACFFLOG.

 

NO other Log related table is getting updated after running log update Sync job successfully.

 

Please let me know if anybody has faced this issue or any advise on what is need to be checked.

 

Any help is much appreciated.

 

Regards,

Yatin Phad

Role was not found in ARM

$
0
0


Dear Colleagues,

 

Could you please assit me here.

 

I have created the role in the system ( Development ) and I logged in as a role owner  and approved the role .  and  the request is completed status .

When I went raise to riase a request , I could not find  the role  I have created .

 

I have dont the repository sync and tried again , but didn't work.

 

Could you please assist me ?

 

Should I first transport the role production  and raise a request ? If yes can you also mention how we shuld transport the role

 

 

Thanks and Reagds,

RAghu

GRC AC-Password self service

$
0
0

Hi experts,

 

Looking for solution on how to implement PSS in GRC AC10 with the following option:

 

Steps are

 

1. User wants to reset his/her password.

2. Goes to NWBC Link

3. Put the user id

4. Clicks on < Forgot Password >

5. Security question is asked

6. User gets a mail in his/her mail box with a link to reset the password

 

Regards,

Sudha M


SAP GRC FI Standard SOD Matrix..

$
0
0

Hi Gurus,

 

Can you one guide me to find a Standard FI SOD Conflitcs matrix...

 

JC

Header text change in End User Logon page

$
0
0

Hello All,

 

Could you please let me know where can i change the Header text of End User logon page which is SAP GRC Access Control, 10 to an different description.

 

Thanks in advance.

GRC 10 : EAM Logs are showing 'No Records'

$
0
0

Hello  Experts,

 

I am working on GRC 10 EAM configuration at SP07.

 

The EAM Firefighting scenario is working on ie.Firefighter can login to backend R3 system and performed

 

FF activities but when i update the FF Logs GRC system doesnt show any logs in the system.

 

The logs are present in R3 system in STAD, CDPOS, SM20 etc.

 

The TIme Zones are same in both GRC and R3 system.

 

But Except Table GRACFFLOG.

 

NO other Log related table is getting updated after running log update Sync job successfully.

 

Please let me know if anybody has faced this issue or any advise on what is need to be checked.

 

Any help is much appreciated.

 

Regards,

Yatin Phad

GRC AC 10.0 : Issue with downloading SOD Rules

$
0
0

Hello Experts,

 

I am trying to download SOD rules.

 

When I am doing this, When I am using the connector group, its showing 0 bytes transferred code page 4110 but the data is getting populated into all the files except function action and function permission.

 

If I am using a standard SAP_R3_LG connector group, its able to download all the data from SOD rules.

 

 

please guide me where I have gone wrong.

 

Thanks in advance

Regards

Deepak

Need Help to Face the Issue

$
0
0

Hi Experts,

I am New to GRC. I dont know wich questions are askable and wich not.

But here i am facing the issue like No Cross system-ids maintained..

what is this means..???

GRAC10 "Role not update; role does not meet the selected updated criteria".

$
0
0

Hi,

 

 

 

We have maintained other attributes of the role in the SAP GRC AC 10 (SP14) system. However,Unable to do mass role update for role owner. While doing mass role update, the status is Error for all roles and the reason statement is "Role not update; role does not meet the selected updated criteria". Not able to interepret this reason description exactly. Any suggestion or comment would be of great help.

 

 

 

Thanks,

kjoshi

GRC - Restricting owners and controllers from approving own requests

$
0
0

Hi Everyone,

 

We are implementing GRC 10.1. I have the SAP_GRAC_ACCESS_REQUEST and SAP_GRAC_FIREFIGHT_LOG_REPORT workflows working as expected except for one issue.

 

I am unable to restrict users from approving their own requests and FF id activity.

 

I wanted to create a condition in the workflow to  cancel whenever approver = user but couldnt figure out how to add the user value to the condition.

I have an option to add the workflow initiator but if i do that this will fail when we have someone else requesting a ff id for the user who is also the approver for a ff id.

 

Any ideas?

 

Please advise.

 

Sushni


SAP GRC AC 10 Workflow

$
0
0

Hi Experts,

 

I am new to GRC AC 10 and I need to configure workflow for various modules of AC.

 

How do I configure the same and are there any documents highlighting the various steps involved in the same.

 

Thanks,

Arjun

GRC 10.1 new functionalities

$
0
0

Hello,

Anyone saw a presentation of GRC 10.1? What about new functionalities? (in particular in AC)

It looks likes the ramp up will be available for customers from tomorrow...

Julien

ARQ: Need help on BRF Rule for Decision Table Design???

$
0
0

Hi All,

 

Hope you are doing good!

 

I need you help to map my business requirement which is explained below:

 

Currently, I am using 2 request types: New Account and Change Account. "New Account" is used to create a new user account and for also role assignment.

 

 

My workflow for both: New and Change Account request types is like this:

 

 

Manager->Role Owner

 

 

In my current configuration, Roles addition to a request is made "mandatory". Meaning, a request cannot be submitted until a single is added. This goes well if any role assignment/validity extension is needed.

 

 

Requirement:

 

 

Users' account get expired due to business reason. Now these business users would like to use Access Request application to extend the SAP Account's validity. As I brought to your notice that I have "Change Account" request type configured, I believe (and I would like to use) this can be used to achieve this.

 

 

Now what I did is, I made role addition as NON-MANDATORY (in EUP). As a result, if I dont add any roles I CAN submit the request. However, if I dont add anything (Role or System), I can not submit the request, which is good!

 

 

Now, when I add systemONLY and submit the request after modifying validity dates, the workflow is getting failed as it can not find the ROLE Owner (As there is no role entry in the request). Therefore, I would like to create another path for ONLY such type of requests (containing SYSTEM entry ONLY).

 

 

May somebody help me designing decision table to achieve this and return the required result set? I tried to use different comparison operators. But unfortunately they are not helping!

 

 

Can anybody advise to achieve above?

 

 

Waiting for your kind response(s)

 

 

Regards,

Faisal

Inactivated Auth objects getting deleted/activated in Parent role post creation&generation of derived & parent roles in BRM

$
0
0

Hi Thr,

 

We have an issue when maintaining a parent role in GRC 10 SP10.


ISSUE --> Inactivated Auth objects getting deleted/activated in Parent role post creation&generation of derived & parent roles in BRM


Please update at the earliest as this is a critical issue in hand.

 

Regards,

Arun

Creating root org units for Mitigation Control

$
0
0

Hi All, When I am trying to create root org unit in Root Organizational Hierarchy I am not able to create root org unit. I am getting the error "An exception occured". Could you please let me know the steps for creating root org unit .This is required for maintaining Mitigating controls. Regards, Rams. A

Viewing all 1383 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>