Skip to Content
avatar image
Former Member

CUP 5.3 issue

Dear Experts,

I have an issue with CUP 5.3. I have 3 systems say ECC, SEM, SCM.

I need to configure in such a way that If user requests for a new account in all these systems, the system should do Mandatory Riskanalysis for ECC and it should not perform risk analysis for SEM or SCM. How to achieve this scenario.

I appreciate your help.

Thanks,

Raj

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

4 Answers

  • avatar image
    Former Member
    Sep 18, 2011 at 05:48 PM

    Hi Raj,

    Option 1.

    If you have all the systems "applications", selected in the CUP request (ECC, SEM, SCM), the way to achieve the SOD only for ECC, is to have a specific rule set (group) for ECC instead of the GLOBAL rule set group. This option still gives you the possibility to run SOD for all systems in RAR(you can select the rule set), and only for ECC in CUP(default rule set only).

    1) RAR: Create a new rule set (group).

    2) RAR: Add the new ECC rule set group to all relevant risks.

    3) RAR: Change configuration "Default rule set for risk analysis" for the new ECC rule set group.

    This may also require a review to the Risks/Functions to include only ECC.

    Option 2.

    If you want to delete all rules and just keep the ECC:

    1) Backup entire rule set (export option in rule architect)

    2) Export only rules for the ECC system

    3) Delete all rules in RAR.

    4) Import the rules exported on 2).

    p.s.: I haven't tried the 2nd option, but in theory this should work.

    Regards,

    N

    Add comment
    10|10000 characters needed characters exceeded

    • Former Member Former Member

      Hi Raj,

      It is better to create 2 workflows with different intiators for ECC and SEM or SCM systems. In oneworkflow you can make stage as mandatory where in another workflow of SEM or SCM systems make SoD as not required

      I believe this will suffice the requirement

      Thanks and Best Regards,

      Srihari

  • avatar image
    Former Member
    Sep 19, 2011 at 08:23 AM

    Hi Raj,

    I agree with Srihari.

    Create different workflows for different needs.

    When you select Risk analysis mandatory at a stage level, it's not possible to run only for some systems, you have to run for all.

    My solution was, if you don't need SOD on SEM or SCM, why do you have risks for these systems?!.

    Regards,

    N

    Add comment
    10|10000 characters needed characters exceeded

    • Former Member Former Member

      Hello Raj,

      At least GRC 5.3 doesn't provide an option to control limiting the RA specific to systems with the option "Perform RA on Submission" turned on. This is a global param and we have requested SAP to consider this request to make the param configurable specific to systems.

      Basically the CUP will perform a RA for all systems, but would come out clean as there may not be any rules maintained for other systems.You can configure this by tweaking in a connector entry in RAR for the other systems.

      Regards, Anil

  • avatar image
    Former Member
    Sep 19, 2011 at 10:56 PM

    Hi Raj,

    regarding your question "how to restrict a user not to select SEM/SCM in the workflow"?

    You can create a more robust/complex workflow that will only be triggered when the user select the correct system.

    The negative part is when the user select all the systems, it will get an error message saying multiple initiators found.

    For example, create the initiators to trigger each workflow path based on:

    Request type:

    Application (ECC): NOT

    Application (SEM): AND

    ..and change the condition operator to address the correct path.

    Normally this is not recommend because it's complex to maintain or change in the future.

    Regards,

    N

    Add comment
    10|10000 characters needed characters exceeded

  • avatar image
    Former Member
    Sep 20, 2011 at 05:27 PM

    Thank you very much for your helpful answers. Points are awarded.

    Add comment
    10|10000 characters needed characters exceeded