You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Welcome to the Solution Definition template. It is a document structure describing pre-sales documentation for customers embarking on their cloud journey.
4
+
5
+
The intent is to provide a high-quality piece of documentation, improving the implementation time for customers and partners, and resulting in quicker business benefit realization of the proposed solution.
6
+
7
+
The template comes in two flavors: ‘Mandatory’ or ‘Complete’. The mandatory version is smaller and includes the minimum required chapters for an Oracle solution. The complete version includes more chapters for optional content that might be situational relevant from project to project.
8
+
9
+
Please feel free to add, change, remove, or rearrange content as needed. This is a flexible toolbox then a time-consuming process.
10
+
11
+
# When to use this asset?
12
+
13
+
Use this template if you want to describe a solution for a customer.
14
+
15
+
# How to use this asset?
16
+
17
+
Write the document usually from top to bottom, removing guiding content and replacing examples with actual content. Decide if you need a chapter or not.
18
+
19
+
Chapters are described within the template.
20
+
21
+
You might want to use a Markdown editor, or possibly copy the structure into a Word document if you prefer.
22
+
23
+
You can find prewritten documents for various use cases in this repository, or create an Issue if you are missing something.
24
+
25
+
# License
26
+
27
+
Copyright (c) 2023 Oracle and/or its affiliates.
28
+
29
+
Licensed under the Universal Permissive License (UPL), Version 1.0.
30
+
31
+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
Copy file name to clipboardExpand all lines: others/customer-documentation/solution-definition-complete/files/solution-definition.md
+38-36Lines changed: 38 additions & 36 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -284,7 +284,7 @@ At the time of this document creation, no Security requirements have been specif
284
284
285
285
*Guide*
286
286
287
-
*Capture the Non-Functional Requirements for networking-related topics. You can use the networking questions in the [Annex](#networking-requiremend-considerations)*
287
+
*Capture the Non-Functional Requirements for networking-related topics. You can use the networking questions in the [Annex](#networking-requirement-considerations)*
288
288
289
289
*Example:*
290
290
@@ -421,87 +421,88 @@ Any deviations from these recommendations needed for the scope of this document
421
421
422
422
\<Customer Name\> is responsible for implementing, managing, and maintaining all listed topics.
423
423
424
-
<tablestyle="width:26%;">
424
+
<tablestyle="width:25%;">
425
425
<colgroup>
426
426
<colstyle="width: 2%" />
427
427
<colstyle="width: 2%" />
428
428
<colstyle="width: 19%" />
429
-
<colstyle="width: 0%" />
430
429
</colgroup>
430
+
<thead>
431
+
<trclass="header">
432
+
<th>CATEGORY</th>
433
+
<th>TOPIC</th>
434
+
<th>DETAILS</th>
435
+
</tr>
436
+
</thead>
431
437
<tbody>
432
438
<trclass="odd">
433
-
<tdrowspan="2"><h4id="category">CATEGORY</h4>
434
-
<p>User Management</p></td>
435
-
<tdrowspan="2"><h4id="topic">TOPIC</h4>
436
-
<p>IAM Default Domain</p></td>
437
-
<tdcolspan="2"rowspan="2"><p>DETAILS | ======================================================================================================================================================================================================+ Multi-factor Authentication (MFA) should be enabled and enforced for every non-federated OCI user account. |</p>
439
+
<td>User Management</td>
440
+
<td>IAM Default Domain</td>
441
+
<td><p>Multi-factor Authentication (MFA) should be enabled and enforced for every non-federated OCI user account.</p>
442
+
<ul>
443
+
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/Content/Identity/mfa/understand-multi-factor-authentication.htm">Managing Multi-Factor Authentication</a>.</li>
444
+
</ul>
445
+
<p>In addition to enforcing MFA for local users, Adaptive Security will be enabled to track the Risk Score of each user of the Default Domain.</p>
438
446
<ul>
439
-
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/Content/Identity/mfa/understand-multi-factor-authentication.htm">Managing Multi-Factor Authentication</a>. | | In addition to enforcing MFA for local users, Adaptive Security will be enabled to track the Risk Score of each user of the Default Domain.</li>
440
-
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/Content/Identity/adaptivesecurity/overview.htm">Managing Adaptive Security and Risk Providers</a>. |</li>
447
+
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/Content/Identity/adaptivesecurity/overview.htm">Managing Adaptive Security and Risk Providers</a>.</li>
441
448
</ul></td>
442
449
</tr>
443
450
<trclass="even">
444
-
</tr>
445
-
<trclass="odd">
446
451
<td></td>
447
452
<td>OCI Emergency Users</td>
448
-
<tdcolspan="2"><p>A maximum of <strong>three</strong> non-federated OCI user accounts should be present with the following requirements: |</p>
453
+
<td><p>A maximum of <strong>three</strong> non-federated OCI user accounts should be present with the following requirements:</p>
449
454
<ul>
450
-
<li>Username does not match any username in the Customer’s Enterprise Identity Management System |</li>
451
-
<li>Are real humans. |</li>
452
-
<li>Have a recovery email address that differs from the primary email address. |</li>
453
-
<li>User capabilities have Local Password enabled only. |</li>
454
-
<li>Has MFA enabled and enforced (see IAM Default Domain). |</li>
455
+
<li>Username does not match any username in the Customer’s Enterprise Identity Management System</li>
456
+
<li>Are real humans.</li>
457
+
<li>Have a recovery email address that differs from the primary email address.</li>
458
+
<li>User capabilities have Local Password enabled only.</li>
459
+
<li>Has MFA enabled and enforced (see IAM Default Domain).</li>
455
460
</ul></td>
456
461
</tr>
457
-
<trclass="even">
462
+
<trclass="odd">
458
463
<td></td>
459
464
<td>OCI Administrators</td>
460
-
<tdcolspan="2"><p>Daily business OCI Administrators are managed by the Customer’s Enterprise Identity Management System. | This system is federated with the IAM Default Domain following these configuration steps: |</p>
465
+
<td><p>Daily business OCI Administrators are managed by the Customer’s Enterprise Identity Management System. This system is federated with the IAM Default Domain following these configuration steps:</p>
461
466
<ul>
462
-
<li>Federation Setup |</li>
463
-
<li>User Provisioning |</li>
464
-
<li>For configuration guidance for major Identity Providers see the OCI IAM Identity Domain tutorials. |</li>
467
+
<li>Federation Setup</li>
468
+
<li>User Provisioning</li>
469
+
<li>For configuration guidance for major Identity Providers see the OCI IAM Identity Domain tutorials.</li>
465
470
</ul></td>
466
471
</tr>
467
-
<trclass="odd">
472
+
<trclass="even">
468
473
<td></td>
469
474
<td>Application Users</td>
470
475
<td>Application users like OS users, Database users, or PaaS users are not managed in the IAM Default Domain but either directly or in dedicated identity domains. These identity domains and users are covered in the Workload design. For additional information see <ahref="https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/iam-security-structure.htm">Design Guidance for IAM Security Structure</a>.</td>
471
-
<td></td>
472
476
</tr>
473
-
<trclass="even">
477
+
<trclass="odd">
474
478
<td>Cloud Posture Management</td>
475
479
<td>OCI Cloud Guard</td>
476
-
<tdcolspan="2"><p>OCI Cloud Guard will be enabled at the root compartment of the tenancy home region. This way it covers all future extensions, like new regions or new compartments, of your tenancy automatically. | It will use the Oracle Managed Detector and Responder recipes at the beginning and can be customized by the Customer to fulfill the Customer’s security requirements. |</p>
480
+
<td><p>OCI Cloud Guard will be enabled at the root compartment of the tenancy home region. This way it covers all future extensions, like new regions or new compartments, of your tenancy automatically. It will use the Oracle Managed Detector and Responder recipes at the beginning and can be customized by the Customer to fulfill the Customer’s security requirements.</p>
477
481
<ul>
478
-
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-start.htm">Getting Started with Cloud Guard</a>. | Customization of the Cloud Guard Detector and Responder recipes to fit the Customer’s requirements is highly recommended. This step requires thorough planning and decisions to make. |</li>
479
-
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-customize.htm">Customizing Cloud Guard Configuration</a> |</li>
482
+
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-start.htm">Getting Started with Cloud Guard</a>. Customization of the Cloud Guard Detector and Responder recipes to fit the Customer’s requirements is highly recommended. This step requires thorough planning and decisions to make.</li>
483
+
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/cloud-guard/using/part-customize.htm">Customizing Cloud Guard Configuration</a></li>
480
484
</ul></td>
481
485
</tr>
482
-
<trclass="odd">
486
+
<trclass="even">
483
487
<td></td>
484
488
<td>OCI Vulnerability Scanning Service</td>
485
489
<td><p>In addition to OCI Cloud Guard, the OCI Vulnerability Scanning Service will be enabled at the root compartment in the home region. This service provides vulnerability scanning of all Compute instances once they are created.</p>
486
490
<ul>
487
491
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/scanning/home.htm">Vulnerability Scanning</a>.</li>
488
492
</ul></td>
489
-
<td></td>
490
493
</tr>
491
-
<trclass="even">
494
+
<trclass="odd">
492
495
<td>Monitoring</td>
493
496
<td>SIEM Integration</td>
494
497
<td>Continuous monitoring of OCI resources is key for maintaining the required security level (see <ahref="#regulations-and-compliances-requirements">Regulations and Compliance</a> for specific requirements). See <ahref="https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/siem-integration.htm">Design Guidance for SIEM Integration</a> to implement integration with the existing SIEM system.</td>
495
-
<td></td>
496
498
</tr>
497
-
<trclass="odd">
499
+
<trclass="even">
498
500
<td>Additional Services</td>
499
501
<td>Budget Control</td>
500
502
<td><p>OCI Budget Control provides an easy-to-use and quick notification on changes in the tenancy’s budget consumption. It will be configured to quickly identify unexpected usage of the tenancy.</p>
501
503
<ul>
502
504
<li>For configuration details see <ahref="https://docs.oracle.com/en-us/iaas/Content/Billing/Tasks/managingbudgets.htm">Managing Budgets</a></li>
503
505
</ul></td>
504
-
<td></td>
505
506
</tr>
506
507
</tbody>
507
508
</table>
@@ -796,7 +797,8 @@ Synchronized clocks are a necessity for securely operating environments. OCI pro
796
797
797
798
*Reference:*
798
799
799
-
[HA Reference for EBS](https://github.com/oracle-devrel/technology-engineering/tree/main/cloud-architecture/oracle-apps-erp)
800
+
-[Resilliance on OCI](https://docs.public.oneportal.content.oci.oraclecloud.com/en-us/iaas/Content/cloud-adoption-framework/era-resiliency.htm)
801
+
-[Workload Related Content](https://github.com/oracle-devrel/technology-engineering/)
Welcome to the Solution Definition template. It is a document structure describing pre-sales documentation for customers embarking on their cloud journey.
4
+
5
+
The intent is to provide a high-quality piece of documentation, improving the implementation time for customers and partners, and resulting in quicker business benefit realization of the proposed solution.
6
+
7
+
The template comes in two flavors: ‘Mandatory’ or ‘Complete’. The mandatory version is smaller and includes the minimum required chapters for an Oracle solution. The complete version includes more chapters for optional content that might be situational relevant from project to project.
8
+
9
+
Please feel free to add, change, remove, or rearrange content as needed. This is a flexible toolbox then a time-consuming process.
10
+
11
+
# When to use this asset?
12
+
13
+
Use this template if you want to describe a solution for a customer.
14
+
15
+
# How to use this asset?
16
+
17
+
Write the document usually from top to bottom, removing guiding content and replacing examples with actual content. Decide if you need a chapter or not.
18
+
19
+
Chapters are described within the template.
20
+
21
+
You might want to use a Markdown editor, or possibly copy the structure into a Word document if you prefer.
22
+
23
+
You can find prewritten documents for various use cases in this repository, or create an Issue if you are missing something.
24
+
25
+
# License
26
+
27
+
Copyright (c) 2023 Oracle and/or its affiliates.
28
+
29
+
Licensed under the Universal Permissive License (UPL), Version 1.0.
30
+
31
+
See [LICENSE](https://github.com/oracle-devrel/technology-engineering/blob/main/LICENSE) for more details.
0 commit comments