cancel
Showing results for 
Search instead for 
Did you mean: 

Risk Rule Set Relationship

Former Member
0 Kudos

Hi,

   Can you please explain me how i can derive a relationship between the Risks and teh associated Rule ID's generated.As per my requirement i would need to gather the "Rule ID" from the GRC 10.0 application within a Risk ID.So as per my understanding the rules generated are stored in local files and would like a way to extarct this relationship.Can you please suggest me.

Thanks & Regards,

Srini.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Srinivas,

In your GRC 10 system activate the BC set for R3  rules"GRAC_RA_RULESET_SAP_R3".

Then you can download the rules from SPRO under your ABAP system.

There you can get the rule ids you ar elooking for.

Rajesh

Former Member
0 Kudos

Thanks Rajesh,

   I am able to download the rules through SPRO,but my user wants teh rules that are associated to a particular risk.For example a risk X with two functions will have some transactions.Based on Permutations and combinations of the 2 functions in teh Risk the rules A,B,C are generated for teh Risk X.So now my user wants to extratct the Rules A,B,C fo rteh Risk ID X.

Thanks & Regards,

Srinivas.

Former Member
0 Kudos

HI Srinivas,

Run the risk analysis for user DDIC and you will get all the risks with Rule id.

Hope this helps.

Rajesh

Former Member
0 Kudos

Yes,but this is leading me to inconsistent results and not sure whether all the Risks and Rule sets associated are included.Also the segragation based again on actions as a risk has multiple functons which inturn have multiple Actions would not be possible.Do we have any table where this rule ID and Risk are mapped.

Former Member
0 Kudos

Hi Srinivas,

DDIC user comes up with all the risks which are applicable to any user in the system as it has the maximum access.

There will be no combination that can be left when running for DDIC analysis.

If some risk is not popping up it means its not valid for that system.

You can cross check by doing manual comparison for one risk for all combination of tcodes i.e. rule ids. If it is ok for one its gonna be ok for all else send me the ruleset at my email id and I will have a look.

Regards,

Rajesh Nanda