cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10 - Risk Simulation in Composite Role

Former Member
0 Kudos

I am trying to do risk simulation for composite role in GRC 10. I do this:

NWBC->Access Management -> Role Level Simulation:

Under Define Analysis Criteria I give the details of the single role -> System, Role Type, Roles (in comp role), Report Type @ permission Level.

Under Define Simulation Criteria I add action

Run in Foreground.

I don't get any risk.

Is this the correct way of doing it?

Can anyone suggest any document on such tasks.

Also can i do risk simulation in derived roles from simulation reports under Access Management?

Accepted Solutions (0)

Answers (1)

Answers (1)

alessandr0
Active Contributor
0 Kudos

Dear Smriti,

it's correct - you can either simulate what happens if you add roles, actions or profiles to your composite role. Same possibility is given for single roles, derived roles, etc.

To simulated risks you have to ensure that the composite role conflicts with your added role, action or profile. You can easily check if your simulation works with profile SAP_ALL.

Hope this helps.

Best regards,

Alessandro

Former Member
0 Kudos

Thanks Alessandro. got it!

So for derived roles, I'll have to put all of my derived roles in Analysis Criteria and additional tcodes in Simulation Criteria.

Are there documents for details on GRC 10 other than the ones on

alessandr0
Active Contributor
0 Kudos

Great 🙂

You can check the GRC Wiki - Governance, Risk and Compliance Home - Governance, Risk and Compliance - SCN Wiki or if you don't find the answers let us know.

Best regards,

Alessandro

ps. please mark this thread as answered.