cancel
Showing results for 
Search instead for 
Did you mean: 

GRC v10 AC Owners

paul_ksobiech4
Explorer
0 Kudos

Good day,

OK, it seems that I am missing something with GRC 10. We are upgrading from CC4.0 to GRC 10. I believe I have everything configured through SPRO correctly. I can run a risk analysis on end users and I get results. I am now at the point where I put the mitigations into the system but I have seem to run into a snag. When I go to master data > Mitigation, I start to fill in the information but when I try to add a AC Owner I get "No Results Found".

I have tried adding a Owner to a risk and then going back, I have also added a user under "Access Management" tab with "Access Control Owners". I have reviewed almost every node in SPRO and I can not seem to find where I am missing something.

I am sure it is simple since I can not find any documentation on this almost anywhere. We are currently running GRC v10 SP5. We are only planning to use the RAR (5.3 term) portion of AC not the other part (Example: Risk Terminator). Please let me know if there is a simple solution to get a user populated in the AC Owner tab.

Kind Regards,

Paul

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Kudos

Hi Paul

I think I found "Access control owners" - Its in Setup folder and not under Access Management. My issue is resolved.

Thanks

Snehal Pandya

Former Member
0 Kudos

Hi Paul

I am in exactly the same situation as you were but unfortunately, I dont see any link "Access Control Owner" within Access Management so I am unable to define and control owner. I think I have verified all the config steps and am not missing any steps. Role or user leve risk analysis is running perfectly fine.

Any clues??

Appreciate your help.

Thanks

Snehal Pandya

paul_ksobiech4
Explorer
0 Kudos

What Roles do you have assigned to your user? I would suggest assigning all SAP_GRAC* roles to your user. It will be there. I am not sure which of those roles give that access at the moment but I would guess that you do not have the role that has the "GRC Role Assignments" section under the "Access Management" tab.

Let me know if you find it.

Have a good day.

Paul

Former Member
0 Kudos

Some of the GRC Roles ..

SAP_GRAC_ACCESS_APPROVER Role for Access Request Approver

SAP_GRAC_ACCESS_REQUESTER Role for End user

SAP_GRAC_ACCESS_REQUEST_ADMIN Role for Access Request Administrator

SAP_GRAC_ALERTS Generate, clear and delete SOD Alerts

SAP_GRAC_ALL Super Admin for AC

SAP_GRAC_BASE Base Role for all Access Control Users.

SAP_GRAC_CONTROL_APPROVER Create AC MIT control, approve, assign, alert and perform Risk analysis

SAP_GRAC_CONTROL_MONITOR Ability to assign MIT control to Risk and perform risk analysis

SAP_GRAC_CONTROL_OWNER Create AC MIT control.

SAP_GRAC_DISPLAY_ALL Display Access To All AC Objects.

SAP_GRAC_END_USER End User as a GRC Guest

SAP_GRAC_FUNCTION_APPROVER Approve Function for Workflow

SAP_GRAC_NWBC View Access Control Information Architecture.

SAP_GRAC_REPORTS Ability to run all AC reports.

SAP_GRAC_RISK_ANALYSIS Ability to Perform Risk Analysis

SAP_GRAC_RISK_OWNER Risk maintainence And Risk Analysis

SAP_GRAC_ROLE_MGMT_ADMIN Role Management Admin

SAP_GRAC_ROLE_MGMT_DESINGER Role Management Designer

SAP_GRAC_ROLE_MGMT_ROLE_OWNER Role Owner

SAP_GRAC_ROLE_MGMT_USER Role Management Business User

SAP_GRAC_SUPER_USER_MGMT_USER Super User Firefighter

SAP_GRAC_SUPER_USER_MGMT_ADMIN Super User Administrator Role

SAP_GRAC_SUPER_USER_MGMT_CNTLR Super User Controller Role

SAP_GRC_MSMP_WF_ADMIN_ALL MSMP Overall Administrator

SAP_GRC_MSMP_WF_CONFIG_ALL MSMP Overall Configurator

SAP_GRAC_RULE_SETUP Ability to define Access Rules

SAP_GRAC_SETUP Ability to setup Access Control

SAP_GRC_FN_BASE GRC - Base role to run applications

Hope it helps ..

Vikas

paul_ksobiech4
Explorer
0 Kudos

OK I believe I figured it out. I must have went too quickly. I created the user in Access Management > Access Control Owners, adn then went directly to the Organization structure to try to assign hte user. That user was not there. I just went back to it and found that the user is now there so I can choose that user.

Thanks,

Paul