GRC Step by Step Notes
GRC Step by Step Notes
SLL-LEG
SLL-NFE
SAP GRC10.1
SAP NW AS 7.40 SP02
GRCFND_A V1100
000-----------------------------DDIC
SAINT/SUM Tool - ADD ONS
add ons available .sar file
client copy
a. now establish the communication between 400 (front grc server) and 399 (backend
ecc system) client through RFC
2. ACTIVATING APPLICATIONS
SPRO
sap reference img
GRC
GENERAL SETTINGS
GRC-PC
GRC-RM
GRC-AC NOW SELECT THE CHECK BOX: ACTIVATE
NOW SAVE.
T-CODE SICF
EXECUTE
EXPAND SAP
SCPR20
ARA----1 1
ARM----4 7
BRM----5 6
EAM----1 1
BACKEND SYSTEM----1
connector groups
now save
note: source connector and logical port must be the same
NOW SELECT EH6CLNT455
NOW DOUBLE CLICK ON DEFINE CONNECTOR GROUP
CLICK ON NEW ENTRIES
CONTINUE
ENTER
AUTH - ARA
PROV - ARM
ROLMG - BRM
SUPMG - EAM
UNICODE
TABLE:
GRFNCGRPCONLK Connector Group and Connector Type Link
GRFNCONNGRP Connector Group definition
SAVE.
OR
SAVE.
FROM THIS STEP WE SPECIFY THE SYSTEM BELONGS TO WHICH TYPE OF ENVIRONMENT, WHETHTER
IT IS DEV, QUA, PRO
In this Customizing activity, you can assign the actions to a connector group and
then choose the default connector for each group.
SPRO - SAP REF IMG- GRC- ACCESS CONTROL- MAINTAIN MAPPING FOR ACTIONS AND CONNECTOR
GROUPS
NEW ENTRIES
save
SPRO- SAP REF. IMG- GRC (PLUGINS)- MAINTAIN PLUG-IN CONFIGURATIN SETTINGS
NEW ENTRIES
NEW ENTRIES
SAVE
AUTHORIZATIN SYNCH
BY THIS STEP WE ARE GOING TO SYNCH BACK END SU24 DATA INTO THE GRC SYSTEM.
USOBT AND USOBX TABLES, CUSTOMER TABLE ARE USOBT_C AND USOBX_C.
SPRO- SAP REF. IMG- GRC- ACEESS CONTROL- SYNCHRONIZATION JOBS- AUTHORIZATION SYNCH
NOW GRAC_PFCG_AUTHORIZATION_SYNC JOB IS SHEDULE WHICH WILL SYNCH SU24 DATA FROM
BACKEND TO FRONT END SYSTEM.
PROGRAM: GRAC_PFCG_AUTHORIZATION_SYNC
FOLLOWING ARE THE TABLES connector specific users, roles and profiles
SPRO- SAP REF IMG- GRC- ACCESS CONTROL- ACCESS RISK ANALYSIS- SOD RULES- GENERATE
SOD RULES
RISK ID: *
SCHEDULE IT IN BACKGROUND JOB
RULE SET
BUSINESS PROCESS BASIS related
Z_RISK
FUNCTION1 FUNCTION2
ACTIONS/PERMISSIONS A/P
ACTIONS - T-CODES
TABEL: GRACRULESET
15. CREATION OF BUSINESS PROCESS:
SPRO- SAP REF IMG- GRC- ACCESS CONTROL- MAINTAIN BUSINESS PROCESS AND SUB PROCESS
SAVE
TABLE
GRACBPROC Business Process
GRACBSUBPROC SUB BUSINESS PROCESS
GRACBPROCT Business Process Text
FUNCTIONS
CREATE-
FUNCTION ID: B10FUN1
BUSINESS PROCESS: BATCH10 BUSINESS PROCESS
DESCRIPTION: SU01
CLICK ON ADD
SAVE
CREATE-
FUNCTION ID: B10FUN2
BUSINESS PROCESS: BATCH10 BUSINESS PROCESS
DESCRIPTION: pfcg
CLICK ON ADD
SAVE
NOW GENERATE FUNCTIONS
TABLE: GRACFUNC
17. NOW CREATE A RISK AND ATTACH THE ABOVE TWO FUNCTIONS TO THIS RISK:
CREATE
save
CREAT
OWNER: GRCUSER4
SAVE CLOSE
NOW GO TO BACKEND SYSTEM AND CREATE ROLE WITH THE COMBINATION OF SUO1 AND PFCG
COME TO FRONT END SYSTEM AND PERFORM SYNCHRONIZATION
EAM:
FF:lara
FFID: backend as service user
FFOWNER:
FFCONTROLLER:
ff
ffowner
ffcontroller
/N/VIRSA/VFAT 5X
GRAC_SPM
SAP_GRAC_SUPER_USER_MGMT_USER
SAP_GRC_FN_BASE
SAP_GRC_FN_BUSINESS_USER
The Background Job for Log Collection can be scheduled periodically from SM36
using program GRAC_SPM_LOG_SYNC_UPDATE.
2. Maintain AC owners
Go to NWBC ?Access Management ?Access Control Owners and maintain the owners
BRF+
Please check table FDT_ADMN_0000 for Object Type AP (Application) and FU
(Function). See if you ZINIT_CUST01 exists already
GRFNMW_DBGMONITOR_WD
slg1
sost
CREATE APPROVER:
ROLES:
SAP_GRC_FN_BASE
SAP_GRC_FN_BUSINESS_USER
SAP_GRC_NWBC
SAP_GRAC_ACCESS_APPROVER
GRFNMW_CONFIGURE
RSUVM002
TUTYP
USMM
GRC_MSMP_CONFIGURATION
https://www.youtube.com/watch?v=9vWiJ3tNTTg