cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10- Supplementary Rule

Former Member
0 Kudos

Hello Experts,

I would like to get some information regarding Supplementary Rules.

Any one who can provide explanations, links etc Please post here

Regards,

Michal

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Answers (4)

Answers (4)

Former Member
0 Kudos

Hi Everyone,

How would you transport supplementary rules?

Also, how would you import them after system refresh?.

When I exported the ruleset from GRC 10.1, the files only included function, risks and bp.

Please advise.

Thank you

Kiran

Former Member
0 Kudos

Hello Kiran, though the original context of this post is different from your question, but still hopefully it can be answered here.
For future best practice, please open a separate question so it is better tracked and answered too.

Regarding transport of Supp. Rules, these rules are not a part of standard rules delivered by SAP.
Customers build their own rules and have a separate working logic from SOD rules.
Since these Supp. Rules are defined in NWBC, the transports can be raised directly from the console depending on the system settings which would ask for a transport pop-up while running any save operation.
This should help, if I understood your question correct.
All the best!

Former Member
0 Kudos

Hello All,

Thanks for all those links you sent,

But what im looking for is something a bit more detailed.

As i still didnt understand why we should use supplementary rules as opposed toany other remediation plan.

Thanks and regards,

Michal

Former Member
0 Kudos

These rules are defined in addition to GRC rules set, these would serve as additional check for example to Permission Rules.

Example: You have Permission Rules defined for an authorization 02 for field ACTVT and some User Group value - SUPER. Now, if you want an additional check in the rules to check if the user being analyzed within this user group has access to approve payments more than 50000 USD.

For this, you will define a custom table in the ECC (plugin/connected) system which contains this information for that user to be authorized to make such payments. This custom table will contain a field for Payment Approval and so, a check can be placed for the user in Supplementary Rules, to see if the user contains that value or not.


PS: Supplementary Rules will be triggered in addition to Permission Rules. So, in any case Permission Rules have to be fired for these Supplementary Rules to trigger and produce results.

Hope this helps.

0 Kudos

Hi Mike,

Below Link will provide you the complete information on supplementary Rules for GRC 10.0

Supplementary Rules - Access Control - SAP Library

Best Regards,

Ravi Kumar

madhusap
Active Contributor
0 Kudos

Hi Michal,

Check out the below discussions also on Supplementary rules which gives overview on how these rules work.

http://scn.sap.com/thread/993083

http://scn.sap.com/thread/3152358

Regards,

Madhu.