MSAMM
Back to course

Free preview · Administering Cloud EPM: The Platform Beneath the Business Processes

Answering a security questionnaire

Sooner or later somebody in security, in audit, or in a customer's procurement team sends a questionnaire. It arrives with a deadline. And it lands on the platform administrator.

The method, and the whole method is the sorting. Separate the questions into: what the PLATFORM PROVIDES. What WE HAVE CONFIGURED. And what we have CHOSEN NOT to configure.

The first is documented and citable. The second is your evidence — configuration screenshots, reports, policy documents. The third is a DECISION that needs an owner and a rationale. NOT A BLANK. An unanswered question reads as an oversight. A decision with a name against it reads as governance, and they are frequently the same fact.

NEVER GUESS. If you do not know whether a control is in place, say you will confirm. A wrong answer in a security questionnaire is worse than a late one.

NEVER CLAIM A CONTROL YOU HAVE NOT CONFIGURED BECAUSE THE PLATFORM SUPPORTS IT. AVAILABILITY IS NOT IMPLEMENTATION. That is the sentence to remember from this lesson. It is also the commonest way these documents become false.

The artifacts to keep ready, so the next questionnaire takes an hour instead of a week. The estate register. The role model. The access review record. The security decision log. And the DR test record. Every one of those is something you built in an earlier module.

And the honest answer to "who has access to our data?" Your users, per the role model. Your domain administrators. And Oracle's personnel, under whatever managed access arrangement you have configured. Be able to say that clearly — in one breath, without hedging, because the hedging is what prompts the follow-up questions.

That is the end of the free preview. The full course covers the rest of the curriculum, with the assessment and a certificate on completion.

See the full course