cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigation Control at role level works at user level???

mamoonr
Active Participant
0 Kudos

Hi ,

I created a Business Role in SAP GRC 10.0 mapped with couple of single roles from different systems.

I have done the role level risk analysis for the buiness role and assigned the Mitigation control for the Risk IDs generated.

when this business role is assigned to the user through  access request,mitigation control that is assigned to the Business Role, is assigned to the user or not?

Steps performed
End user select the business role and submit the request
Request triggers the Role owner
When the Role owner opens the request and done the risk analysis for the business role the Mitgated risk id are still showing.
But I have already assigned the mitigation control for the risk ids of the role.

I want to know if mitigation done at role(business) level is also reflected in user level.

#User is a new  and has not been provisioned yet.


Thanks,
Mamoon

Accepted Solutions (0)

Answers (2)

Answers (2)

0 Kudos

Mitigating role and Mitigating Risk of users are different.

Suppose Role1 has risk X and it has been mitigated, it does not mean that user assigned with Role1 and risk X(from other roles) would automatically have risk X mitigated.

Mitigating self conflicting roles means that given role wont show risk in itself for mitigated risk but it can show risk with combination of authorization from other roles.

mamoonr
Active Participant
0 Kudos

Hi Gurus,

Please reply if possible..I am stuck.

Thanks,

Mamoon

former_member304001
Active Contributor
0 Kudos

Hi,

May be useful

Check this parameter : 1033 - Include Role/Profile Mitigating Controls in Risk Analysis - YES

Regards,

Kishore