Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter
Customer-managed keys: the concepts
Lesson 105 of 201 · 2 min
Customer-managed encryption keys, held in a vault the customer controls, used to encrypt the environment's data. What it gives you: the ability to demonstrate — and if necessary exercise — control over the keys protecting your data. WHAT IT COSTS YOU. THIS IS THE PART THAT IS USUALLY UNDERSTATED. You now own key lifecycle management. Creation, rotation, replication for disaster recovery, and access policies. IF YOU LOSE CONTROL OF THE KEY, YOU LOSE ACCESS TO THE DATA. That is the point of the feature. And also its risk. Those are the same sentence read two ways, and a client needs to hear both. The replication requirement. A key that exists in one region only is a single point of failure for a disaster recovery plan that spans regions. Module 12's connection, and it is the failure that turns a resilience feature into an outage. Who this is for: organizations with…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 9 · Securing the Perimeter
- 1Defence in depth for an EPM estate
- 2Network perimeter
- 3Migrating from per-environment IP allowlists
- 4Sign-on policies
- 5Break Glass: managed provider access
- 6Approving access requests
- 7Customer-managed keys: the concepts
- 8Configuring customer-managed keys
- 9Compliance reports and the security capability set
- 10Answering a security questionnaireFree preview
- 11What breaks
- 12Lab: proportionate security, and ten questionnaire answers
