Administering Cloud EPM: The Platform Beneath the Business Processes · Module 9 · Securing the Perimeter
Compliance reports and the security capability set
Lesson 107 of 201 · 2 min
Start with the compliance reports, because they are citable and everything else here is context for them. Then the capability set, grouped rather than listed, because a list is unusable and a grouping is a map. Transport and storage — TLS and certificate renewal, encryption at rest, keys in validated hardware security modules. Credentials — encrypted client credentials, secure credential storage, OAuth tokens for API and automation access. Access control — role-based access, multiple password policies, sign-on policies, network restriction, session duration and idle timeout. Data handling — data isolation between tenants, data masking. Content safety — virus scanning of uploaded files, blocking invalid file types. Provider access — restricted and monitored access by Oracle personnel, access logging. Resilience — immutable backup archive, air-gapped backup in a secondary region. Evidence — audit reports, login reports, activity reports, SIEM integration. Assurance — automatic patching, penetration testing, external audits, customer-initiated testing. Sector-specific…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 9 · Securing the Perimeter
- 1Defence in depth for an EPM estate
- 2Network perimeter
- 3Migrating from per-environment IP allowlists
- 4Sign-on policies
- 5Break Glass: managed provider access
- 6Approving access requests
- 7Customer-managed keys: the concepts
- 8Configuring customer-managed keys
- 9Compliance reports and the security capability set
- 10Answering a security questionnaireFree preview
- 11What breaks
- 12Lab: proportionate security, and ten questionnaire answers
