Create a module access policy
-
- UpdatedJan 30, 2025
- 4 minutes to read
- Yokohama
- Now Platform Security
Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.
Before you begin
Role required: sn_kmf.cryptographic_manager or sn_kmf.admin
About this task
Field Encryption supports role-based module access policies and additional configuration options become available with (CLE_Ent) functionality.
- Configure the specific cryptographic operation in module access policies for cryptographic modules that support symmetric operations. For instance, a user can be enabled to encrypt data but not decrypt data.
- Set a default module access policy value or according to a cryptographic module.
- Associate script versions where changes to the script are tracked and invalidate the script policy providing better security for script-type module access policies.
Note: The default behavior of the module access policies (MAPs) is Reject to help prevent any unauthorized access, unless explicitly declared in MAP records.
Procedure