Maximo

Maximo

Come for answers, stay for best practices. All we're missing is you.

 View Only

The Security Questions No One Asks During a Maximo Deployment – But Should

  • 1.  The Security Questions No One Asks During a Maximo Deployment – But Should

    Posted 3 days ago

    Most Maximo conversations focus on integrations, licensing, or mobility. But there's a hidden area of concern: security blind spots during implementation that often go unaddressed.

    Key concerns that clients should be asking, but don't:

    1. Who owns Maximo audit logs? Are they monitored in your SIEM (like QRadar)?
    2. Are password reset attempts and login failures from mobile devices audited and geo-tagged?
    3. How are unused/non-rotating admin accounts managed after go-live?
    4. Is encryption at rest enabled for all environments, including test/staging?
    5. What's your response time if your Maximo API is exposed via public integration?

    Let's start a conversation around operational security in Maximo implementations, especially as we move into cloud-native and SaaS models. Security isn't just an IT concern, it's a business continuity concern.



    ------------------------------
    Srikar Ande
    Director Of Innovation
    ZPro Solutions Limited
    Markham ON
    7024994655
    ------------------------------