MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter

Answering a security questionnaire

Lesson 108 of 201 · 2 min · Free preview

Sooner or later somebody in security, in audit, or in a customer's procurement team sends a questionnaire. It arrives with a deadline. And it lands on the platform administrator. The method, and the whole method is the sorting. Separate the questions into: what the PLATFORM PROVIDES. What WE HAVE CONFIGURED. And what we have CHOSEN NOT to configure. The first is documented and citable. The second is your evidence — configuration screenshots, reports, policy documents. The third is a DECISION that needs an owner and a rationale. NOT A BLANK. An unanswered question reads as an oversight. A decision with a name against it reads as governance, and they are frequently the same fact. NEVER GUESS. If you do not know whether a control is in place, say you will confirm. A wrong answer in a security questionnaire is worse than a late one. NEVER CLAIM A CONTROL YOU HAVE

This lesson is free

Watch the full lesson, with its written notes, without an account. It is one of the free lessons this course opens with.

Watch the full lesson

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 9 · Securing the Perimeter

  1. 1Defence in depth for an EPM estate
  2. 2Network perimeter
  3. 3Migrating from per-environment IP allowlists
  4. 4Sign-on policies
  5. 5Break Glass: managed provider access
  6. 6Approving access requests
  7. 7Customer-managed keys: the concepts
  8. 8Configuring customer-managed keys
  9. 9Compliance reports and the security capability set
  10. 10Answering a security questionnaireFree preview
  11. 11What breaks
  12. 12Lab: proportionate security, and ten questionnaire answers