cancel
Showing results for 
Search instead for 
Did you mean: 

CC / RAR 5.2 - Multiple Rule Set Question

Former Member
0 Kudos

How does the system handle the use of multiple rule sets in CC / RAR 5.2?

For example, letu2019s say I want to keep a standard SAP rule set in tact to use for testing and comparison in RAR, but I also want to load another one.

I realize that only 1 can be the u201CDEFAULTu201D so what does that mean? I know that a risk analysis is only run against the rule set you set as default. I also know that you can select the rule set to use in processing when you manually run either through Informer or Configuration tab a risk analysis. What I am really concerned with is what happens if you take the results to u201Cmanagement reportsu201D from 2 different rule sets?

First, can you even do it?

Second, if you can, then I think you must have to come up with a different RISKID configuration schema for each rule set otherwise, I do not see how you can differentiate from which rule set the violation is generated. That said, you will also need to export the report information into Excel and make any u201Crule set sortu201D there as I donu2019t see a way to do it directly in RARu2026.maybe a future improvement?

Can anyone confirm the impact of multiple rule sets and how you manage them?

Regards,

Greg

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Greg,

Even though, you can have more than one rule set in RAR right now, it has limited functionality around it. You should be able to generate management reports for both rule sets but it won't be able to show you a comparison. To do comparative analysis, you will have to download the report to excel.

Regards,

Alpesh

Answers (1)

Answers (1)

Former Member
0 Kudos

Can anyone confirm the impact of multiple rule sets and how you manage them?

Former Member
0 Kudos

Greg,

You can maintain the different severity levels for different Rule Sets. For example, in one Rule Set you can keep the "Critical" Risks and in other you can keep "High", "Medium" & "Low". Run your analysis against first Rule Set if you want to know the "Critical" Risks and second Rule set you can use for rest of the severity levels. I hope this way you can manage your multiple Rule Sets in RAR.

Thanks,

Tavi

SAP Security & GRC Consultant.