Enter the following main data of a function category.
Property |
Description |
---|---|
Function definition |
Name of the SAP function. |
Functional area |
The SAP function is valid for this functional area. |
Function category |
Grouping criteria for the SAP function. To create a new function categories, click . Enter the name and a description of the function category. |
Manager/supervisor |
Application role whose members are responsible for the function definition in terms of content. To create a new application role, click . Enter the application role name and assign a parent application role. |
Authorization objects |
Spare text field for entering information about the authorization objects that are used in the function definitions. |
Risk index |
Defines the risk for the company if an SAP user account matches this SAP function. Use the slider to enter a value between 0 and 1. 0: No risk. 1: Every SAP user account that matches the SAP function poses a problem. This field is only visible if the QER | CalculateRiskIndex configuration parameter is set. |
Risk index (reduced) |
Show the risk index taking mitigating controls into account. An SAP function’s risk index is reduced by the significance reduction of all mitigating controls assigned to it. The risk index (reduced) is calculated for the original SAP function. To copy the value to a working copy, run the Create working copy task. This field is only visible if the QER | CalculateRiskIndex configuration parameter is set. The value is calculated by One Identity Manager and cannot be edited. |
Severity code |
Specifies what it means to the company or the assigned functional area when an SAP user matches this SAP function. Enter a value between 0 and 1. 0: Just for information 1: Any SAP user account that matches the SAP function requires changes to the affected SAP authorizations. |
Significance |
Specifies a verbal description of the effects on the company (or the functional area) when an SAP user account matches this SAP function. In the default installation, the value list displays {low, average, high, critical}. |
Description |
Text field for additional explanation. |
working copy |
Specifies whether this is a working copy of the function definition. |
For more information about risk assessment, see the One Identity Manager Risk Assessment Administration Guide.