MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter

Customer-managed keys: the concepts

Lesson 105 of 201 · 2 min

Customer-managed encryption keys, held in a vault the customer controls, used to encrypt the environment's data. What it gives you: the ability to demonstrate — and if necessary exercise — control over the keys protecting your data. WHAT IT COSTS YOU. THIS IS THE PART THAT IS USUALLY UNDERSTATED. You now own key lifecycle management. Creation, rotation, replication for disaster recovery, and access policies. IF YOU LOSE CONTROL OF THE KEY, YOU LOSE ACCESS TO THE DATA. That is the point of the feature. And also its risk. Those are the same sentence read two ways, and a client needs to hear both. The replication requirement. A key that exists in one region only is a single point of failure for a disaster recovery plan that spans regions. Module 12's connection, and it is the failure that turns a resilience feature into an outage. Who this is for: organizations with

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 9 · Securing the Perimeter

  1. 1Defence in depth for an EPM estate
  2. 2Network perimeter
  3. 3Migrating from per-environment IP allowlists
  4. 4Sign-on policies
  5. 5Break Glass: managed provider access
  6. 6Approving access requests
  7. 7Customer-managed keys: the concepts
  8. 8Configuring customer-managed keys
  9. 9Compliance reports and the security capability set
  10. 10Answering a security questionnaireFree preview
  11. 11What breaks
  12. 12Lab: proportionate security, and ten questionnaire answers