ITSO: total effort is very small to perform security review on data transmission and business practices.


These notes are a result of CIT's brainstorming meetings about Workday on 4/12 and 4/13 2011.

Assumptions

  • A list of all integrations in and out of Workday and their transmission method and the data elements is available

Effort

Tasks in more detail

  • perform security review on
    • data transmission
      • batch and transactional
      • mode of transmission; Workday can transfer with SFTP, FTP with PGP, FTP with SSL,
      • data elements
    • Business practices:
      • data handling: will want to know how Workday Inc manages the their employees, CU data, business continuity, etc...
      • workday to other vendors: will be included in the review but since they are already vendors we do business with it will be a small part;

Open Questions:

  • How are keys escrowed?
  File Modified
Microsoft Powerpoint 97 Slideshow secQs-Workday-11apr11.ppt per Tom Young May 18, 2011 by Vicky L. Mikula