cancel
Showing results for 
Search instead for 
Did you mean: 

Business Role Testing/Transport

0 Kudos

Can someone please tell me what their Business Role methodology is regarding creating/testing/transporting business roles?

My current understanding is that we don't 'transport' business roles and everything is created in the prod GRC client. My question then becomes, does this mean you don't 'test' the business role in DEV GRC as you would for a regular security role before moving it to the Q then on to Prod GRC boxes?


Thanks in advance

Dan

Accepted Solutions (1)

Accepted Solutions (1)

madhusap
Active Contributor
0 Kudos

Hi Dan,

As per our process, roles for all systems are Created/Modified by Role Management Team.

But Business Roles Creation/Modification is done GRC Operations and Support Team and this team creates/modifies business roles as per Service Request. This is because Business roles are just containers which hold roles from different systems and main purpose of these roles is to make end user role selection easy based on their appointments or positions.

So, its GRC O&S team sole responsibility to Create/Change the business roles, Execute Risk Analysis and if there are no Violations, send it for approval. In case of violations share the Risk analysis report with Mitigation Approver for analysis and to mitigate the risks (if required).

So, basically Business Roles maintenance should be defined as part of your governance process on who maintains these roles.

Regards,

Madhu.

Answers (1)

Answers (1)

former_member197694
Active Contributor
0 Kudos

Dear Murphy,

Yes,no need to transport business roles,we can include step as test cases in methodology for testing.

Role methodology depends on your business/customer requirement.

please go through the below links for more information on business roles concept

Business Roles concept and usability in GRC AC10 - Governance, Risk and Compliance - SCN Wiki

Let us know if you need more details

Regards

Baithi