Give some examples for Remediation and Mitigation in RAR?

Answer Posted / ranjan dash

Remediate- after simulation of existing role or user , can know the risk., Avoid providing access with risk .

eg- employee cant have access to other employee's pay roll. access has been restricted to avoid risk.

Mitigate- after risk analysis for role assignment approver can approve access with risks existing via a mitigation control ID.

eg. if employee is a manager he ll have mitigated access to other employees i.e his team members payroll. access has been provided overcoming risk.

Is This Answer Correct ?    18 Yes 1 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

explain the personalization tab within a role?

847


how we Set up Central User Administration (CUA) to manage 4 systems/clients

1820


The user wants to create like a time table in BEX but when the open BEX its showing empty screen . in this situation what will u do.. And How will solve u …What r the steps u will take the to solve the solution..

2007


How we Educated client personnel in R/3 Security and general Basis knowledge

1798


the company needs to expand its region to another country which the same authorizations had previously what approach you will take

1639






what is hypercare and go live support?

4727


Explain network topology in sap systems?

607


Support types of WOs you have faced?

1787


how to do Restricting nodes and Hierarchies through characteristic values and authorization objects

1874


How would you do the 'a user logge into production system, changes a table and logged out'. How would you track him?

628


What is the difference between authorization object and authorization object class?

647


What does the account assessment category specify in a purchasing order in SAP Materials Management?

1004


What every changes done exist role in development system that changes are not reflected in quality system, but transport is successfully moved?

989


what is the process to find that one consultant had removed a table from sap tables

2041


Pfcg proposed activities but you need only two. What would you do?

665