cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10: Allows Approval without mitigation

Former Member
0 Kudos

Hi GRC Fellows,

We are operating on GRC 10 SP6. While performing configuration for ARQ-User Provisioning we observed there is not parameter to control the request approval despite risks. At this stage we are able to approve high risk/sod without having mitigation assigned to it.

We have referred OSS Note 1587489 - Allows Approval without mitigation. This note is applicable to SP4 below.

Having said that we are also referring to guide u201CMaintaining Configuration Settings in Access Controlu201D

This guide talks about all GRC 10 configuration parameters.

If you are operating on SP6 or SP5 can you please specify the Parameter Group and ID to control this behavior?

Thanks

Prasad Chaudhari

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Prasad,

I haven't tested this out yet, but have you checked the setting under the stage definition in MSMP? There is a check field for "Approve Despite Risk". In config, there is Parameter ID 1072 "Mitigation of critical risk required before approving the request". Hope one of these things helps. Kind Regards, ~Triera

Former Member
0 Kudos

Hi Triera

Iam sure the parameter 1072 does not control that. I will check MSMP stage config and update.

Between have you done HR triggers in GRC 10?

Regards,

Prasad

Answers (1)

Answers (1)

Former Member
0 Kudos

The setting comes under the "Maintain Path" section of configuring the MSMP process flow.

Select the stage to maintain and the setting is under the Maintian Task Setting Options.

Former Member
0 Kudos

Hi Guys,

Thanks for the input.

As I see in MSMP>Maintain Paths>Maintain Stages>Modify Task Settings

The item Approve despite risk is unchecked. With these settings itu2019s still able to approve the request.

Is this behavior controlled only by MSMP?

Regards,

Prasad

Former Member
0 Kudos

Have you set Param "Risk Analysis - Access Request 1072 (Mitigation of critical risk required before approving the request) to Yes? It should work.

anand_ogirala
Explorer
0 Kudos

Kaushal,

Just in case if you are still looki for a solution

Please refer to SAP Note 1667440

Former Member
0 Kudos

Hi Anand,

I wasnt looking for the solution

anand_ogirala
Explorer
0 Kudos

Sorry my mistake, I guess it was Prasad

Former Member
0 Kudos

Thanks Anand,

Your answer helped me in resolving my issue.

Regards,

Sumanth