GRC AC 10.0 SAP_R3_LG,SAP_HR_LG and SAP_BAS_LG Rule sets comparison
I was wondering if anybody has done any kind of comparison and analysis on these different rule sets?
What I would like to know is SAP_R3_LG rule set contains risks for all SAP modules including HR and BASIS. Therefore, does it mean that risks for BASIS containing in SAP_R3_LG is as same as in SAP_BAS_LG?
Also does it meant that risks containing in SAP_HR_LG for HR module is as same as in risks in SAP_R3_LG for HR?
It means that:
Risks for HR system in SAP_R3_LG = Risks for HR system in SAP_HR_LG
Risks for BASIS system in SAP_R3_LG = Risks for BASIS system in SAP_BAS_LG
Risks for other modules' system in SAP_R3_LG = Risks for other modules' system in SAP_NHR_LG
In which scenarios these different rule sets actually are used?
Please share your views and help me understand this in full.