cancel
Showing results for 
Search instead for 
Did you mean: 

GRC53 Rule Set Migrated into GRC10

Former Member
0 Kudos

Gurus, has anyone encountered the following situation. We migrated our 53 rule set into GRC 10 using the Migration Tool. On the surface all of the rule objects seem to move across as they should. We then began to run our risk reports. We noticed that for the same user, in the same backend ECC system, we get varying results from our 53 Rule Set which is in our GRC10 system vs the 5.3 Rule Set executed from our old 5.3 system. We see more violations returned from our old 5.3 system; entire risks are not reported from the GRC10 system.

Consequently, I began reviewing the functions (actions/permissions). I picked a specific risk that was returned by the 5.3 system and reviewed it, line by line - comparing the 53 Rule Set in GRC10 against the 53 Rule Set in the 5.3 system. Everything lined up, with the exception of the activity values. In the 53 Rule Set that was migrated into GRC10 the activity values are single digits (1,2,5, etc) where as in the 5.3 System the activates are two digits (01, 02, 05, etc), Since the values are mainatined in SAP as double digits, could this be causing this? I would hope this is not the culprit, but I am unsure where else to turn.

I will say for those risks that were returned in the results, the activities in those functions were single digits as well.

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi Michael,

Can you let us know whether you have two rulesets in the same GRC 10 System - old 5.3 and new 10.0 ?? Also whether you were able to resolve the issue of getting different results ??

Former Member
0 Kudos

Hi Penn,

Can you check if your default SoD risk level is "Critical" and hence all the conflicts are not being thrown in 10.0

There is an SAP Note 1632864 where you need to maintain parameter 1024 and se tthe default risk level to High. Since there is no option of All in 10.0 similar to 5.3

Thanks and Best Regards,

Srihari.K

Former Member
0 Kudos

Sri, thanks for your input on this. I checked our settings for this parameter it is 1 (High). I have confirmed that the functions are identical including the risk that is produced. I ran the risk analysis for this specific risk and get no results in 10 but I do get results in 5.3 (with the . I have opened a CSN with SAP. If they can point me to the issue I will be sure to update it here.

In the mean time has anyone else seen this....?

shehryar_qureshi
Discoverer
0 Kudos

Hi Michael,

I am curious to learn if you found a solution to the your issue. We are having the exact same problem here.

Thanks,

Shehryar