MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter

Configuring customer-managed keys

Lesson 106 of 201 · 15 min

Create a vault, create an encryption key, REPLICATE THE VAULT FOR DISASTER RECOVERY, create the policies granting the necessary access, configure the environment to use the key, verify, and show the key rotation path. REPLICATE BEFORE YOU CONFIGURE THE ENVIRONMENT, not after. A DR plan that cannot decrypt is not a DR plan. The policies are precise and unforgiving. Get them right in a test environment first. DOCUMENT THE RECOVERY PROCEDURE AND TEST IT. Module 12's recovery exercise should include the key.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 9 · Securing the Perimeter

  1. 1Defence in depth for an EPM estate
  2. 2Network perimeter
  3. 3Migrating from per-environment IP allowlists
  4. 4Sign-on policies
  5. 5Break Glass: managed provider access
  6. 6Approving access requests
  7. 7Customer-managed keys: the concepts
  8. 8Configuring customer-managed keys
  9. 9Compliance reports and the security capability set
  10. 10Answering a security questionnaireFree preview
  11. 11What breaks
  12. 12Lab: proportionate security, and ten questionnaire answers