Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter
Configuring customer-managed keys
Lesson 106 of 201 · 15 min
Create a vault, create an encryption key, REPLICATE THE VAULT FOR DISASTER RECOVERY, create the policies granting the necessary access, configure the environment to use the key, verify, and show the key rotation path. REPLICATE BEFORE YOU CONFIGURE THE ENVIRONMENT, not after. A DR plan that cannot decrypt is not a DR plan. The policies are precise and unforgiving. Get them right in a test environment first. DOCUMENT THE RECOVERY PROCEDURE AND TEST IT. Module 12's recovery exercise should include the key.
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 9 · Securing the Perimeter
- 1Defence in depth for an EPM estate
- 2Network perimeter
- 3Migrating from per-environment IP allowlists
- 4Sign-on policies
- 5Break Glass: managed provider access
- 6Approving access requests
- 7Customer-managed keys: the concepts
- 8Configuring customer-managed keys
- 9Compliance reports and the security capability set
- 10Answering a security questionnaireFree preview
- 11What breaks
- 12Lab: proportionate security, and ten questionnaire answers
