MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter

Defence in depth for an EPM estate

Lesson 99 of 201 · 1 min

Seven layers, and you have built four of them already. Identity — who exists (Modules 3, 6 and 7). Authentication — how they prove it (Module 8). Authorization — what they can do (Module 6). Network — where they can reach it from (this module). Data — encryption, and who holds the keys (this module). Provider access — what Oracle itself can see (this module). Observability — who did what (Module 14). Where most estates are weak: network and provider access. Identity gets attention because it is visible. The perimeter does not — because nothing appears to be wrong. NOT EVERY ESTATE NEEDS CUSTOMER-MANAGED KEYS AND MANAGED-ACCESS APPROVAL. A regulated financial institution does. A mid-size manufacturer may not. MATCH THE CONTROL TO THE REQUIREMENT, AND LET THE CLIENT'S SECURITY FUNCTION SET THE REQUIREMENT. And the over-control failure, which is real and under-discussed. A perimeter so tight that legitimate users cannot

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 9 · Securing the Perimeter

  1. 1Defence in depth for an EPM estate
  2. 2Network perimeter
  3. 3Migrating from per-environment IP allowlists
  4. 4Sign-on policies
  5. 5Break Glass: managed provider access
  6. 6Approving access requests
  7. 7Customer-managed keys: the concepts
  8. 8Configuring customer-managed keys
  9. 9Compliance reports and the security capability set
  10. 10Answering a security questionnaireFree preview
  11. 11What breaks
  12. 12Lab: proportionate security, and ten questionnaire answers