cancel
Showing results for 
Search instead for 
Did you mean: 

Risk having one function

mamoonr
Active Participant
0 Kudos

Dear Gurus,

Need your expertise in understanding risk. When I run risk anlysis for one business role, risk comes with one function id.

Although risk id is SOD risk with two function id.Attaching screen shot.

What is puzzling me that the risk with action FB01 is confliction with which action/permission???

Thanks,

Mamoon

Accepted Solutions (0)

Answers (3)

Answers (3)

former_member193066
Active Contributor
0 Kudos

Please open the risk. you will find it out. don't think it SOD risk its critical action risk or critical permission.

which will have 1 function id.

please run it again do not select critical action or permission.

Regards,

Prasant

Former Member
0 Kudos

Hello Mamoon,

Did you find your answer yet?

Otherwise I think you should take a look to the OSS Note 1600667 - Transactions that conflict with themselves.

The "FB01" action is one of them.

Regards,

Charles

mamoonr
Active Participant
0 Kudos

Attaching the screen shot

Former Member
0 Kudos

Hi,

Can you share the screen with inside content of GSD05 and GSD01- showing action,permission entry. Also share combination under risk S501-function combination, how made?

Hint/suspect:

Either standalone GSD05 is a standalone risk as well.

or this is the case of only permission level,wherein system have bug- what is the support pack level of your GRC system? (Have seen similar issue while working, already a note exists).

Regards,

Nishant

Former Member
0 Kudos

Risk S501 consist out of one rule and one function and not two functions. The report is correct. Not all risks are per definition segregation of duty conflicts, for example debug authorization alone is a high risk. In custom rule sets often more critical permissions/actions are defined than segregation of duty conflicts