cancel
Showing results for 
Search instead for 
Did you mean: 

AE risk analysis using only specific risk criteria

Former Member
0 Kudos

When running an SOD risk analysis from AE, is it possible to detect only critical and high risks? We do not want to consider any medium and low risks at this time. If this is possible, how is this done?

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hello,

I am afraid this is not possible.

Worse: you can not select the rule set on which the risk analysis is performed: the risk analysis runs on the rule set... defined by default in Compliance Calibrator (sheet "Configuration" => "Default values").

I hope that the functionality of selecting the rule set and the risk level from AE will be added in the next release.

Regards,

Nicolas.

Former Member
0 Kudos

Hey, I have finally an idea which should work:

You can create a second rule set in Compliance Calibritor (RS_HIGH_CR for instance) : it would be a copy of your first rule set, but with only the critical and high risks.

Then, you choose this rule set by default in the configuration option of CC: this will be this rule set which will be used for the risk analysis in AE.

Let me know if it solved your issue,

Nicolas.

koehntopp
Product and Topic Expert
Product and Topic Expert
0 Kudos

That is an option you could look into.

Basically, you could work on two rule sets, one for critical stuff that you want to record on in any case, that one would be your default rule set.

The second rule set could contain the not so critical stuff, and could be selected for extra reporting.

I'm not sure how good this will be in the long run, regarding rule maintenance, but it's certainly worth a try.

Frank.

Former Member
0 Kudos

We implemented CC with two rulesets, as this was exactly what we wanted to do. We created our own ruleset, so only had to split it when we uploaded it. If you are using the Virsa Default, it might be more "interesting".

We have two rulesets in CC with the High and Critical in one, and Medium and Low in the other. the High and Critical ruleset is the Default, and is used for AE. When we run the batch analysis in CC, we run for both rulesets, and so get a complete picture.

Good Luck!