cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10.0 Migration : Missing SoD rules after rule generation

Former Member
0 Kudos

Hi Experts,

We are migrating from GRC AC 5.3 to 10.0 (SP8).

We used the migration tools and we exported all .dat files from our old system.

We imported all files using the transaction GRAC_DATA_MIGRATION.

All functions, risks, ruleset, BP are created but after the rule generation, we found that a large number of rules are not generated.

For example, for a risk related to several logical connector, all rules are well defined for a connector, partially defined for an other and totally missing for an other one...

We believe that it's not a question of maximum number of rules per risks as it works fine in 5.3 and furthermore the limit of rules related to a risk has increased (Note 1310365) in 10.0.

Have anyone an idea for us?

Best Regards,

Nicolas

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Kudos

Hi Nicolas,

In 5.3 it was resolved by splitting the function.
You can consider going for logical system instead of physical systems.The change history for the risk & function will show any changes you do in them, be it addition/deletion of system,actions etc.

Please review these sap notes for additional information.

1729934

1667530

986996  

1033326 

1178372 

I hope this gives you some relevant information.

Regards,

Yukti

Former Member
0 Kudos

Hi Nicolas,

For your issue you can ref to the below SAP note

#1716931: Entries missing in the tables GRACFUNCACT for SAP R3 Ruleset

#1715465 - SOD RULE UPLOAD incorrect in GRACACTRULE

And also recommend to make sure that all the data is properly exported from GRC5.3.

If the Functions and Risks are successfully imported into the GRC10.0 release then the Rule Generation should also be correct.

Regards,

Shaily

Former Member
0 Kudos

Hi,

Thanks for your replies, we checked all mentioned points but issue still occurs...

Any Idea?

Best Regards,

Nicolas

saksham
Advisor
Advisor
0 Kudos

Hi Nicolas,

Kindly check if the authorization objects have been transported properly for the associated functions since rules are generated based on the authorization objects.

Best Regards,

Saksham