Application Configuration

The new implementation of Risk Management works for the SAP Direct application.

SAP Direct

Apart from basic SAP JCO connection settings and function module configuration, the SAP GRC settings should be enabled.

  1. Select the option to Enable SAP GRC.

  2. Enter the SAP GRC Connector Name as provided in the SAP GRC system.

SAP GRC

The following is a list of configuration parameters for SAP GRC:

  • The User Name and Password of the user with appropriate permissions.

  • The Integration Mode is Risk Management.

Risk Analysis API Detail

  • The end Point URL for the SAP GRC Access Risk Analysis Web Service.

    The format of the URL must be as follows:

    http://<SAP GRC Host Name>/sap/bc/srt/rfc/sap/grac_risk_analysis_wout_no_ws<WebService Binding URL>

Simulation Risk Only

  • If the value is set to false (default):

    • Violations will be analyzed for the combination of both the user's existing assignments and new assignments.

  • If the value is set to true:

    • Violations will be analyzed only for the user's new assignments.

Rule Set ID

  • A list of rule set IDs against which risk will be analyzed. The default value is empty.

    • If no rule set IDs are provided, the risk will be analyzed for all the configured rule set IDs in the SAP GRC system. Rule set IDs must be provided in list form, one below the other.

Report Type

  • A list of report types used for SAP GRC proactive checks. All values are selected, by default.

    • Risk will be analyzed only against the report types that are selected.

    • If no report types are selected, risk will be analyzed for all report types.