cancel
Showing results for 
Search instead for 
Did you mean: 

Query on RAR connectors to Production & Quality

Former Member
0 Kudos

Hi all,

We have deployed RAR component in one of our standalone servers and connected to the Quality System and performed Risk Analysis for the various users in QA system.

Now that we are planning to connect to the Production System the same RAR instance. We have couple of queries in this regard

a) Is it possible to have both the Production and Quality system data in the same GRC? To our knowledge we think this is possible

b) Since we have already configured the rules at permission level for the quality system data, do we need to change the rule set again with the production system OR can we use the same rule set

If we are using the same SoD rule set and perform a User Analysis/Role analysis for the production system, does the dashboard represents only the Conflicts for Production System or both Quality & Production System.

Please suggest, since GRC QA is already in Standalone server, our management doesnot want to use another server again.

Thanks and Best Regards,

Srihari.K

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Sri,

SAP recommends to have at least one staging server (Dev and/or QA) before deploying AC in Prod. Please find my response below:

a) Is it possible to have both the Production and Quality system data in the same GRC? To our knowledge we think this is possible.. Yes

b) Since we have already configured the rules at permission level for the quality system data, do we need to change the rule set again with the production system OR can we use the same rule set

Yes and No. If you use logical system concept, you don't have do anything else. If you didn't use logical system concept, you will have to upload authorization object data, transaction data and permission data into RAR for particular Prod system. Everything else (Business process, risk, rule configuration) will remain same.

Dashboard will report holistic output. It should all the information contained in GRC AC server which will include QA and Prod information.

Regards,

Alpesh

SAP Manager (PwC)

Former Member
0 Kudos

Hello Sri,

a) it is Yes, as Alpesh mentioned. You will have different connectors to each system. For that matter you can have N number of syntems connected to same GRC server.

b) Depends.

Condition 1: Would you be using the same rules of Q for P as well? If this is yes, then you use the same rule set. But this is ideally not the case as rules for Q and P are and should be different.

Condition 2: If you don't use the same rule set (which should ideally the case be), you should create a new rule set for P, which can be similar to the rule set for Q, with some minor changes as per your Organization policy.

Regards,

Hersh.

http://www.linkedin.com/in/hersh13