cancel
Showing results for 
Search instead for 
Did you mean: 

Mitigation ID / control not getting displayed for user in user level risk analysis

Former Member
0 Kudos

Dear All,

System : GRC10.1

connector type : Cross system

Through Mitigated users, we have mapped user to 3 different Risks and 2 of the risk holds same mitigation/control ID.

Once saved , we can filter for that particular user and see all the Risk, mitigation/control id mapping for user.

When we execute the User level Risk analysis for particular user , control column is coming blank for one of the Risk id.

same control is visible for different Risk id.

Can any please guide , what might be the reason.

Regards

Prasanna S

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member185447
Active Contributor
0 Kudos

Hello Prasanna,

  • Do you have Include Mitigated Risks checkbox checked (Parameter 1030) when running risk analysis at user level from NWBC

  • Running the risk analysis while considering the Org rules as well as including the mitigated user together, system only displays the control id and monitors corresponding to the ORG level risk. The control id and the monitor corresponding to the SOD risks are not displayed in the result.

  • Are you running the risk analysis "Offline" or "Online" mode? If it is "offline", check the last Batch Risk Analysis run and ensure the data is up to date.

  • Check the validity period of the Mitigation Controls.

Regards,

Rakesh Ram

Former Member
0 Kudos

Hi Prasanna,

A MC need to be assigned directly each User SOD risk.  You should run a risk violations report and find the SOD risk that is missing a MC, select it, go to Mitigate Risk, select the MC, set the validity**, and then save.  Then run the risk violations report again and see if it appears.

-Ken