on 2020 Jan 28 7:15 PM
Hello,
We are currently on GRC 10.1 SP15.
We have defined the risk type as Critical or non-critical. The request mitigation policy is set to have mitigation only for the critical risks.
From what I understand, GRAC_MSMP_DETOUR_SODVIOL function helps route the request in cases of a risk. Currently, both critical and non-critical risks are routed and the risk owner cannot close a request with critical risk without mitigation.
Is there any standard function available where in the request is routed only in case of critical risks and the non-critical risks does not invoke the routing.
Thank you,
Praman Mulay
Request clarification before answering.
Hi Praman,
I am little confused with your request. Normally Risk Type will be SOD,CP,CA?You can leverage mitigation policy on the risk level instead of risk type...
EX:
SOD + Critical + High Risk Level should be routed for approval
SOD + Medium + Low Risk Level should be auto approved with no stages
Thanks
Ramesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 10 | |
| 9 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.