cancel
Showing results for 
Search instead for 
Did you mean: 

Role Risk Analysis Issue

Former Member
0 Kudos

Hi All,

I have a question relating to role risk analysis. We currently have GRC 10.0 (not using CUP yet). One of our users wants to add a new role, so we wanted to run a risk analysis on the user with the new role added. Would this be a role risk analysis? I currently enter the system, user, ruleset etc, then add the role and then run the analysis, but when the analysis finishes, there are no SOD violations. To ensure I was doing it properly, I used two roles that I knew would create an SOD conflict, and once again there were no violations. Is this the correct analysis, and what do I need to correct for this to work properly?

Thanks,

Ray

Accepted Solutions (1)

Accepted Solutions (1)

alessandr0
Active Contributor
0 Kudos

Hi Raymond,

to see if a new role might be conflicting with existings for a user you have to run the User Level Simulation analysis.

Step by step:

Define the user, system and rule set you are going to analyze:

Next select a technical role to be simulate with the user (this role is the new assignment and will be simulated):

And run the report in Foreground. The result will show with upcoming risks.

Does that help?

Regards,

Alessandro

Former Member
0 Kudos

Thank you!

Answers (0)