cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigated Role Question

Former Member
0 Kudos

I have created a mitigating Control for a role and added the specific Risk ID. If I run Risk Analysis on the role; it now shows up clean. But if I run Risk Analysis on the users that have the role; the still show the risk. Do I need to create the mitigating control for the role as well as each user that has the role?

Thank You,

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Kudos

Thanks to all that helped. My problems are now solved.

I tried to give each of you points for your help; but i get an error every time I click on one of the point levels.

Thank You,

Ryan Dearman

Former Member
0 Kudos

Sirish,

I did have to set "Include Role/Profile Mitigating Controls in User Analysis" to Yes. Thanks for that. When I run Risk Analysis on the user the mitigated Risks are no longer visible.

So, I am halfway there.

I still see the Risks while viewing CUP tickets. Is there a background job that pushes the change to CUP?

Thanks,

Ryan Dearman

Former Member
0 Kudos

Go to CUP: configuration -> Risk Analysis -> Check what you have in consider mitigation controls. Change the settings and log out from CUP. Log back in and run the risk analysis in CUP.

--Alpesh

Former Member
0 Kudos

Hi Ryan,

When you run the risk analysis on user level, did you selected the option "Exclude mitigated risks"?

In addition, you have set the configuration parameter "Include Role/Profile Mitigating Controls in User Analysis"

to YES by going to Configuration -> Additional Options.

In the configuration -> Risk Analysis -> Default Values -> Exclude Mitigated Risks needs to be set to YES.

In addition put * after the risk((ex: F001*) in your mitigation control.

Hope this helps.

Best Regards,

Sirish Gullapalli.

Former Member
0 Kudos

Follow what the expert suggested and make sure to put an '*' in the Risk ID field. Also, the best practice is to mitigate an user.. should not mitigate a role. Just a suggestion.

Regards,

Alpesh