cancel
Showing results for 
Search instead for 
Did you mean: 

CUP Request Risk Analysis is returning risks of all levels in RAR

Former Member
0 Kudos

Our company has identified risks with High, Medium, and Low risk levels. We have risks of all three levels. We only analysis on High level risks in RAR. In Configuration tab we set the default risk level to High. All our Risk Analysis reports are for High level risks only. We keep Medium and Low risks in the system just in case if we want to elevate them to High, or if we want a history of those risks.

When a CUP request ito add a new role to a user, we can click on Risk Analysis. The system will go and find all the risks for the user. It picks up all risks regardless of the risk level - high, medium, and low. Therefore, it is returning with many risks that we don't really care. We just want it to check the High level risks.

Does your company have the same requirement or problem? If so, what do you do?

Thanks,

John.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hello John,

Unfortunately, at the moment there is no way in CUP using which we could achieve that. CUP will bring in risk for all levels and does not segregate the risks based on risk levels. It is not in the design of the application. You can well send in an enhancement request with SAP Support for this feature.

Regards,

Varun

Former Member
0 Kudos

Thanks for the reply. Theoretically the SAP GRC Solution Management Group is looking into this.

We are just wondering if other companies have experienced the same issue, and what are their solutions (work around?).

Former Member
0 Kudos

Hi John,

One work-around solution can be that you can put all the High risk under single rule set. Then you can define this rule set as a default rule set under RAR configuration.

So whenever analysis will be done from CUP or ERM only risk defined under default rule set will be considered. This way only High level risk will be considered.

I hope this helps.

Regards,

Shweta