| CATEGORY | -TOPIC | -DETAILS | -
|---|---|---|
| User Management | -IAM Default Domain | -Multi-factor Authentication (MFA) should be enabled and enforced for every non-federated OCI user account. -
In addition to enforcing MFA for local users, Adaptive Security will be enabled to track the Risk Score of each user of the Default Domain. -
|
-
| - | OCI Emergency Users | -A maximum of three non-federated OCI user accounts should be present with the following requirements: -
|
-
| - | OCI Administrators | -Daily business OCI Administrators are managed by the Customer’s Enterprise Identity Management System. This system is federated with the IAM Default Domain following these configuration steps: -
|
-
| - | Application Users | -Application users like OS users, Database users, or PaaS users are not managed in the IAM Default Domain but either directly or in dedicated identity domains. These identity domains and users are covered in the Workload design. For additional information see Design Guidance for IAM Security Structure. | -
| Cloud Posture Management | -OCI Cloud Guard | -OCI Cloud Guard will be enabled at the root compartment of the tenancy home region. This way it covers all future extensions, like new regions or new compartments, of your tenancy automatically. It will use the Oracle Managed Detector and Responder recipes at the beginning and can be customized by the Customer to fulfill the Customer’s security requirements. -
|
-
| - | OCI Vulnerability Scanning Service | -In addition to OCI Cloud Guard, the OCI Vulnerability Scanning Service will be enabled at the root compartment in the home region. This service provides vulnerability scanning of all Compute instances once they are created. -
|
-
| Monitoring | -SIEM Integration | -Continuous monitoring of OCI resources is key for maintaining the required security level (see Regulations and Compliance for specific requirements). See Design Guidance for SIEM Integration to implement integration with the existing SIEM system. | -
| Additional Services | -Budget Control | -OCI Budget Control provides an easy-to-use and quick notification on changes in the tenancy’s budget consumption. It will be configured to quickly identify unexpected usage of the tenancy. -
|
-