Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Regd : Rules in SAP Virsa

Former Member
0 Kudos

I am a beginner in SAP Virsa. I am having one doubt in it

How to create rule in SAP virsa ? Is this rule is automatically generated for each module ? As as security consultant how can we identify the risks in the Functional module . Is that we need help of functional guys in each module to explain the critical risks. Also i understand that it is Segregation of duties of each employee in organization. But how we identify the risk factors in it. How to generate the corresponding role for it.

Can any one please brief me out ... I am very eager to know about this Virsa. Thanks for your help in advance

1 ACCEPTED SOLUTION

Former Member
0 Kudos

I agree, the guides are the best place to learn about the GRC applications. Briefly though, in Virsa CC, you only maintain the function groups (list of tcodes) and the risks, the system will generate the corresponding roles which represent all the tcode combinations contained in the conflicting function groups as stated in the particular risk.

4 REPLIES 4

Former Member
0 Kudos

Hi Sanjeev,

It's worth checking out the user guide for c/c:

https://websmp203.sap-ag.de/~form/sapnet?_FRAME=OBJECT&_HIER_KEY=501100035870000015092&_HIER_KEY=601...

That will tell you how to create rules or change the ones supplied with the tool & goes the structure of how they are set up.

When identifying the risks you need to get the business and the functional consultants to analyse the existing ruleset and make any changes that are relevant to your business.

The best place for questions on the GRC products is the SDN GRC forum:

Former Member
0 Kudos

I agree, the guides are the best place to learn about the GRC applications. Briefly though, in Virsa CC, you only maintain the function groups (list of tcodes) and the risks, the system will generate the corresponding roles which represent all the tcode combinations contained in the conflicting function groups as stated in the particular risk.

0 Kudos

Hi Guys;

Thanks for your useful information and prompt replies....... I will refer those guides prescribed by you.

My last question

Identifying risk in each module is the work of a functional experts ? for example as Security consultant how can we know that what are the risk involved in sales processing or financial accounting etc...

0 Kudos

Usually business process experts and functional consultants should be involved in identifying the risks in the different area.

Ideally an experienced security consultant would have some of that knowledge, but this takes time to develop.