0% found this document useful (0 votes)
20 views3 pages

Oracle Cloud Infrastructure Security Guide

Uploaded by

ttawk465
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views3 pages

Oracle Cloud Infrastructure Security Guide

Uploaded by

ttawk465
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

Security

Oracle Cloud Infrastructure (OCI) is a Gen-2, security-first cloud. The security


pillar focuses on protecting users, safeguarding data, and meeting regulatory and
compliance requirements.

OCI lets you migrate your organization's mission-critical workloads to the cloud
while continuing to maintain or even improve your security posture. Reduce the
overhead of building and operating data center infrastructure without sacrificing
security.

The best practices in the security pillar help your organization to define a secure
cloud architecture, identify and implement the right security controls, and monitor
and prevent issues such as configuration drift.

Quick Links
Whether you're a security architect, a security administrator, or in security
operations, OCI provides detailed security documentation and resources to support
your role.

The following table helps you to quickly navigate to our most popular security
resources.

The Services column is a collection of OCI cloud-native security services and


tools. These tools were designed and built as cloud services to help you achieve
and maintain your target security posture. There's an assortment of tools to help
you manage the security components at each layer of technology.
The Best Practices Framework for OCI column provides architectural guidance about
how to build OCI services in a secure fashion, based on recommendations in the Best
practices framework for Oracle Cloud Infrastructure. Topics cover all security
layers, and discuss recommended designs and configurations, including how best to
apply OCI security tooling.
The Security Guide column includes links to documentation in the Oracle Cloud
Infrastructure Security Guide. The Security Guide provides detailed instructions
about how to deploy and implement security functionality across OCI resources.
Review the security guide with your organization's architect and operations teams
in the planning phase of your implementation.
Services Best Practices Framework for OCI Security Guide
General concepts and architecture About Effective Strategies for Security and
Compliance
Security Overview

Security Services

Tenancy and Oracle Cloud Infrastructure Identity and Access Management

Organization Management
IAM with Identity Domains
IAM without Identity Domains
Manage Identities and Authorization Policies

Design guidance for IAM Security Structure

Best Practices for IAM in OCI

Securing Your Tenancy

Securing IAM

Security Credentials
Data security

Data Safe
Vault
Secure Your Databases

Protect Data at Rest

Database

Securing Database
Storage

Securing Block Volume


Securing File Storage
Securing Object Storage
Integration and management

Securing GoldenGate
Securing Data Integration
Securing Data Catalog
Platform and infrastructure security

Bastion
Shielded instances
OS Management
Oracle Autonomous Linux
Isolate Resources and Control Access
Platform operations

Security for Core Services


Securing Resource Manager
Securing Monitoring
Compute resources

Securing Compute
Securing Container Engine for Kubernetes
Network security

VCN security
Security lists and network security groups (NSGs)
Certificates
FastConnect with MACsec
DNS and Traffic Management
Ensure Secure Network Access
Securing Networking: VCN, Load Balancers, and DNS

Oracle Cloud Marketplace Security Partners

Application security

Web Application Firewall


Private access and endpoints
Container Registry image signing
Scanning Images for Vulnerabilities

Signing Images for Security


Enforcing the Use of Signed Images from Registry

Securing Email Delivery

Securing Notifications

Securing Service Connector Hub

Securing DevOps

Security operations

Cloud Guard
Security Advisor
Security Zones
Cloud Advisor
Vulnerability Scanning
Optimize the Security Posture of Your Environment

DevOps Security Challenges and Considerations

Design Guidance for SIEM Integration

Securing Vulnerability Scanning

Securing Cloud Advisor

Critical Patch Updates, Security Alerts and Bulletins


Oracle Cloud Security Testing Policies

Oracle Cloud Security Responses to Vulnerabilities

Legal, risk, and compliance

Audit
Compliance Documents
Monitor and Audit Your Environment

Integration with third-party security information and event management (SIEM)


solutions, such as Splunk and QRadar

-
Reference Implementation
Security checklist for Oracle Cloud Infrastructure
Cloud Adoption Framework Core Landing Zone
Explore More
Oracle Cloud Security Practices
Oracle Cloud Infrastructure Security Architecture
Oracle Cloud Security blog
A-Team Chronicles: Identity Access Management and Security
OCI Adoption Framework Thunder
Oracle Database Security Guide, Release 23ai

Common questions

Powered by AI

OCI addresses network security concerns by implementing features such as VCN security, security lists, and network security groups (NSGs) to manage access controls. It also offers FastConnect with MACsec for secure connections, along with DNS and traffic management to ensure secure network access. Additionally, OCI employs a Web Application Firewall for application-level protection . These tools collectively offer robust security measures to safeguard network components within the OCI environment .

OCI's Security Operations tools such as Cloud Guard and Security Advisor play significant roles in enhancing overall security by offering continuous monitoring and threat detection capabilities. Cloud Guard provides comprehensive security insights and automated responses to emerging threats, while Security Advisor assists in optimizing the security posture of the cloud environment, ensuring proactive risk management .

The Best Practices Framework for OCI provides architectural guidance on building services securely by recommending designs and configurations based on security standards. This framework covers all security layers and recommends taking advantage of Oracle's security tools, enabling organizations to achieve a secure cloud architecture and maintain their security posture .

OCI simplifies data security management for databases by offering tools like Data Safe for monitoring and managing data security operations. It provides services such as Vault for securing databases and ensuring data protection at rest. OCI also secures database storage, block volumes, file storage, and object storage, providing comprehensive security solutions across various data management aspects .

In OCI, IAM plays a critical role in maintaining security by managing identities and authorization policies, which ensure that only authorized users have access to resources. Best practices for IAM include designing a robust security structure, securing identities, and implementing multi-factor authentication. OCI provides detailed guidance on managing IAM effectively, both with and without identity domains, to ensure a secure environment .

OCI enhances security monitoring and analysis through integration with third-party SIEM solutions such as Splunk and QRadar. These integrations allow for more comprehensive security data analysis, ensure real-time monitoring of security events, and facilitate quicker incident response. By leveraging established SIEM capabilities, OCI can provide a more detailed and holistic security overview of the cloud environment .

OCI ensures the security of mission-critical workloads during cloud migration by providing a Gen-2 security-first architecture that focuses on protecting users, safeguarding data, and meeting regulatory and compliance requirements . OCI's Best Practices Framework helps organizations define secure cloud architectures, identify and implement security controls, and monitor any configuration drift. Additionally, OCI offers cloud-native security services and tools to maintain the security posture across all technology layers .

OCI assists with compliance and regulatory security requirements by offering a security guide that provides comprehensive instructions for deploying and implementing security functions. It also offers tools for monitoring and auditing the cloud environment to ensure compliance. Additionally, OCI provides services to integrate with third-party security solutions and uses audit compliance documents to manage security testing policies and responses to vulnerabilities .

OCI emphasizes application security through the use of Web Application Firewalls to protect web-based applications, container registry image signing for secure deployments, and scanning for vulnerabilities to mitigate potential threats. Furthermore, OCI enforces signing images for security and secures application-related services such as email delivery, notifications, and DevOps practices. These comprehensive measures ensure the protection of application-related resources .

OCI's vulnerability scanning aims to identify and address potential security weaknesses within the cloud environment. By scanning container images and other resources for vulnerabilities, OCI ensures that risks are mitigated before they can be exploited. This proactive scanning helps maintain a secure environment by preventing unauthorized access and potential security breaches .

You might also like