Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter
Defence in depth for an EPM estate
Lesson 99 of 201 · 1 min
Seven layers, and you have built four of them already. Identity — who exists (Modules 3, 6 and 7). Authentication — how they prove it (Module 8). Authorization — what they can do (Module 6). Network — where they can reach it from (this module). Data — encryption, and who holds the keys (this module). Provider access — what Oracle itself can see (this module). Observability — who did what (Module 14). Where most estates are weak: network and provider access. Identity gets attention because it is visible. The perimeter does not — because nothing appears to be wrong. NOT EVERY ESTATE NEEDS CUSTOMER-MANAGED KEYS AND MANAGED-ACCESS APPROVAL. A regulated financial institution does. A mid-size manufacturer may not. MATCH THE CONTROL TO THE REQUIREMENT, AND LET THE CLIENT'S SECURITY FUNCTION SET THE REQUIREMENT. And the over-control failure, which is real and under-discussed. A perimeter so tight that legitimate users cannot…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 9 · Securing the Perimeter
- 1Defence in depth for an EPM estate
- 2Network perimeter
- 3Migrating from per-environment IP allowlists
- 4Sign-on policies
- 5Break Glass: managed provider access
- 6Approving access requests
- 7Customer-managed keys: the concepts
- 8Configuring customer-managed keys
- 9Compliance reports and the security capability set
- 10Answering a security questionnaireFree preview
- 11What breaks
- 12Lab: proportionate security, and ten questionnaire answers
