cancel
Showing results for 
Search instead for 
Did you mean: 

"Global" Ruleset

Former Member
0 Kudos

All,

I wanted to get your opinion on building a "global" ruleset for multiple sites.

Currently we are using the standard ruleset, customized to meet our needs.As we roll out AC (RAR) to other sites around the world we are wondering how to localize the ruleset. How do we account for smaller offices with less people? They will violate many SoD violations we currently have.

Also, I know in CUP 5.2 SoD violation checks were run against the ruleset set as "default" in RAR. Is this still the case in 5.3? If so, how do you account for multiple rulesets?

Thanks so much,

Grace Rae

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

All,

I wanted to get your opinion on building a "global" ruleset for multiple sites.

Currently we are using the standard ruleset, customized to meet our needs.As we roll out AC (RAR) to other sites around the world we are wondering how to localize the ruleset. How do we account for smaller offices with less people? They will violate many SoD violations we currently have.

One way of attending this concern is to use Org rules and then run the Jobs/analysis based on Org rules and corresponding risks specific to that region

Also, I know in CUP 5.2 SoD violation checks were run against the ruleset set as "default" in RAR. Is this still the case in 5.3? If so, how do you account for multiple rulesets?

Unfortunately, still it is the same case. CUP picks up the same Ruleset which sets as u201Cdefaultu201D in RAR for analysis

Thanks

Qalid

Answers (1)

Answers (1)

Former Member
0 Kudos

Grace,

in older version of GRC i.e. 4.0 , we had option of one Global Ruleset for all system.

However in GRC AC 5.x, this option is gone. now we have to create one rule set per system.

in latest version 5.3 (may be it was in 5.2..... don't remember...), we have option to create one Logical System and under it's unbrella many system can be added. so now you can generate rule per LOGICAL system.

so now you can set one LOGICAL system as your default ruleset.

regards,

Surpreet