cancel
Showing results for 
Search instead for 
Did you mean: 

GRC SoD Matrix without any functions

0 Kudos

Hello,
I want to know if there is a possibilty to implement an SoD Matrix without any functions. I want to analyse some roles of my system just on there authority objects. I have downloaded the standard ruleset, so I Know how to write and upload the Matrix.


Is there a chance to implement this?

Accepted Solutions (0)

Answers (6)

Answers (6)

RameshVithanala
Active Participant
0 Kudos

Hi Stefan,

If the issue is resolved then please close the thread.

Thanks

Ramesh

0 Kudos

Hi Ramesh,

thanks for your answer. Yes I solved the problem.

Stefan

0 Kudos

hey Madhu Babu #MJ,

thanks for your reply and your screenshots. Can you also show me your excel sheet (risk sheet and function_permissions sheet)?

Iam looking for the right linking of the different sheets. What do I need to write, so that my Matrix will proof on critical permissions? I changed the status in my risks to critical permissions but unfortunately, I received no violations.

regards,

Stefan

RameshVithanala
Active Participant
0 Kudos

Hi Stefan,

SOD risk is combination of two functions & Critical Permission risk consists of only one function and when you are running risk analysis you should select critical permissions.

Thanks

Ramesh

madhusap
Active Contributor
0 Kudos

Hi Stefan,

Your requirement is quiet standard. You have to create CRITICAL PERMISSION risks using the function you have already created with only PERMISSIONS and no ACTIONS.

For example, if I want to check which users have access to DEBUG in the system then my function and risk will look as shown below:

Regards,

Madhu

0 Kudos

Hi Vijayakumar,

thanks for your answer. I created functions without any actions underneath, so my Plan was to run a security check just on the permissions fields. But it seems that, there is no possibility to run a check without the correct linking of functions and actions.

vijayakumarsuth
Advisor
Advisor
0 Kudos

Hi Stefan,

I guess you referring to Function which has Actions underneath it. If i am correct, the Risk analysis engine in Access Control works when you have risks which is formed based on functions hence I dont think y ou can create risk without functions. In case, you come across any other option please let us know as well.