on ‎2018 Oct 05 4:12 PM
sap grc is asking to mitigate even old risks. Before the GRC was implemented, some roles were assigned to the users. But after the GRC system is set up and when we add the role to the user through access request, then the system asks to mitigate the new risks which are coming from the role being requested via access request, this is ok we will mitigate this.
But the grc is also asking to mitigate the old risks which are coming the old roles assigned to the user, i.e. before the GRC was implemented. if I dont mitigate the old risks then then i am not able to submit the access request. Is there a way, wherein I want to submit the access request by just mitigating the new risks but not the old risks.
Request clarification before answering.
HI Abdul
Before looking at the technical aspects, just wanted to check why you don't want to deal with old risks? Is there a remediation project on the side to address these issues? This is a process discussion. ARQ process provides an opportunity to deal with existing risks at the same time as new access.
However, I can understand that your access approvers may not be trained/equipped to deal with the older roles.
Without knowing about your system, I would suggest looking at following topics/options to see what you system is configured:
Regards
Colleen
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Colleen, Yes there is a separate remediation project on the
side, which is more holistic and with which we can deal with old risks.
Hi Abdul,
Can you explain more about the old roles assigned to the user? The roles are still assigned? the sync jobs were run? This risks are still relevant?
Regards
Rafael
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 32 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.