cancel
Showing results for 
Search instead for 
Did you mean: 

Role Analysis Report

Former Member
0 Kudos

I'm a user of the GRC 10.0 module, and have a question around the role analysis report.  I’ve run a risk analysis violations report, and noted SoD/violations for 1169 roles, out of 35214 total roles (see attached screenshot).  That said, my understanding is that some of these ‘violations’, by risk category, could in fact be false positives? Is this correct? If correct, how do we know for certain that there are role violations for the 1169 roles? Is there another maneuver, report or analysis we can do to assure us that we’re looking at 1169 roles with real violations? Any help would be greatly appreciated. 

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi Joe,

Have you got your issues/concerns cleared with the suggestions, if yes; kindly close this thread with marking the appropriate answers unless you have any follow-up questions on the same.

Regards,

Ameet

alessandr0
Active Contributor
0 Kudos

Dear Joe,

this management report gives you an overview of the current state. To further analyze your roles you can use the Risk Analyisis on Role Level report. This report will show the violations in more detail and you can define further actions.

Does this help?

Regards,

Alessandro

Former Member
0 Kudos

Alessandro,

This is helpful, thank you. Although, is my understanding correct that these violations could be in fact false positives? What kind of outputs can I expect from the role level report?

Regards,

Joe

Former Member
0 Kudos

Hi Joe,

As Alessandro suggested, you need to run Access risk analysis reports on role level.

It will show you what exactly is the violation and at what level.. at action, permission, critical action, critical permission et al.

This report will even let you see the corresponding risk IDs, Rule IDs and risk criticality levels like medium/hig/critical and so.

Hope this is clear now

Regards,

Ameet