cancel
Showing results for 
Search instead for 
Did you mean: 

CUP 5.3 SP09 Riskanalysis

Former Member
0 Kudos

Hi together,

If we run the riskanalysis in CUP on a stage, we received all risks for the user.

But there I have a question: Why is there shown for one risk the responsible role and for another risk not?

E.g.:

A role "XY" is a critical role by itself (risk1). The role "Z" isn't, but in combination with the role "J" there is a SoD(risk2).

In the tab "risks for mitigation" there is shown the information for the risk1 and risk2.

But for the risk2 it is also shown the responsible roles regarding the SoD.

The specific risk1, because of the critical role "XY", doesn't show the role in the overview.

Has anybody an idea?

Thanks a lot.

Alexa

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi Frank,

actually I did define this as critical action.

But CUP Riskanalysis shows only for the SoD violations related roles but not for critical action. (only shows the critical actions but not in which role, this action was found)

Kind Regards,

Alexa

koehntopp
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Alexa,

you actually answered it in your question: a critical role is in fact NOT a risk, so it can't be mitigated.

If you want to achieve that, you need to put the critical role's critical stuff into a function and create a critical action/permission risk, which could then be mitigated.

Frank.