cancel
Showing results for 
Search instead for 
Did you mean: 
Subscribe

Hi All,

Am in the process of implementing GRC 10 with the following components for a pharma client.

Access Risk Analysis (ARA)

Access Request Management (ARM)

Emergency Access (Firefighter)

Business Role Management (BRM)

I just wanted to know your views on what kind of approach is better?. Please comment your views with your best approach.

My view is to first implement  ARA and EAM together and then go ahead with ARM and BRM packed together.

Thank You for your idea.

0 Likes
View Entire Topic
Former Member
0 Likes

Hi Mani,

do you have 5.3, so that you would have to copy the provisioning process. if yes, then it will only be left to configure GCR 10. Else, you would have to design Provisioning process first and then get sign off. from all Lead/ approvers/Stake holders.

For EAM and ARA, ARM would be required, to handle workflows.So, it is better to implement ARM simultaneously. Else, for ARA, you would have to make Workflow as 'No', for Risk/Function/Mit. Control Creation/assignment. For EAM, FF and FF log review requests are made through ARM.

For EAM, you would need to decide whether you are going with Central or Decentralized.

For ARA, you would need to set up parameters, in IMG->...> Maintain Configuration settings.

Please go through GRCAC  docs at ,

Regards

plaban