cancel
Showing results for 
Search instead for 
Did you mean: 

Add/Deleting T-Codes from Global Roles while GRC v5.2 is implemented

Former Member
0 Kudos

I would like to find out how are companies which have set up Global Roles and then decided to add/delete t-codes from these Roles after GRC is already implemented deal with the SoD issue. T-codes are constantly being added because the organizational structure differs from country to country; in addition to statutory regulations. Therefore, our SoD analysis become obsolete each time adjustments are made to Global Role. The derived roles, localized for country, takes on the exact t-codes in the Global Roles.

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Sanders,

Once GRC is implemented, an SoD analysis will be run for all the Global roles. Based on the conflicts, mitigation or role-redesign exercise will be taken up as an one time activity for clean up of the SoD Conflicts.

Once this is complete whenever a new t-code is added or existing t-codes are deleted - use simulation for the risks and identify the mitigation or provide no access to the role

Hence in your case the SoD conflicts should not be an obsolete as Risk is always a risk even at various company levels.

If you want to avoid SoD conflicts for the various org levels you can develop the Org level risks to avoid false positives between the organizations.

I have a question for you If the risk is applicable for the Global role why can't it be applicable to the Derived roles?

Please let me know if you need any further information or clarifications

Thanks and Best regards,

Srihari.K

Answers (1)

Answers (1)

Former Member
0 Kudos

Hello.,

Thanks for your reply. You are right that the change in Global Roles automatically affects the Derived Roles. One of the solutions that I was exploring was to use a Request-Based strategy i.e. instead of making changes to Global Roles, suggest creating new roles specifically to address the unqiue situation in that location. This way, the change will not the other countries that are already in full implementation and did not require those additional t-codes.