cancel
Showing results for 
Search instead for 
Did you mean: 

UAM Risk analysis: ignore risks from already assigned backend roles

nguyen_huynh
Explorer
0 Kudos

hello, we are using GRC 10 AC. we would like to use UAM with risk analysis. For the first wave we want approvers to mitigate risk within approval. BUT we want only mitigating new risk coming from the UAM requesting roles and ignoring risks which comes from backend roles assigned already to the user. I remember that 5.3 did offer such an option. Any help is appriciated. Thanks. Nguyen

Accepted Solutions (0)

Answers (4)

Answers (4)

Former Member
0 Kudos

Hi Nguyen,

Set the Parameter - 1030 Include Mitigated Risks to NO

Thanks and Regards

Ankit sharma

Colleen
Advisor
Advisor
0 Kudos

would configuration parameter 1073 - Enable SoD violations detour on risks from existing roles

be used as part of your solution?

martin_trachsel
Participant
0 Kudos

Hi Nguyen

If the risk analysis will be started, there is a option is called "Additional Criteria" with the selection option "Include Mitigated Risk". If you don't set the tick, then only new risk, which are not mitigated, will be showed.

I hope this helps?

Regards

Martin

Former Member
0 Kudos

Use Risk Analysis - User simulation.

Schedule job and view the results. New introduced risks by assigning a new role are highlighted.

See attached snapshot

nguyen_huynh
Explorer
0 Kudos

Hi de Jong, this is not what we want to do . we have a 2 stage path. the first stage is for role approvers. in this stage the role approvers runs the risk analysis. and there we want to mitigate risk caused by new roles requested, risks caused by already assigned roles should be ignored. Thanks. Nguyen

Former Member
0 Kudos

Sounds like you need to trick the system

You could mitigate the assigned roles for your particular risk analysis period