

This guide provides security-related usage and configuration recommendations for Oracle Banking Microservices Architecture. It also describes the procedures required to implement or secure certain features, but it is not a general-purpose configuration manual.


This guide is primarily intended for IT department or administrators deploying Oracle Banking Microservices Architecture and Third-party or vendor software’s. It includes the information related to IT decision makers and users of the application.


Readers are expected to have basic operating system, network, and system administration skills with an awareness of vendor/third-party software’s and knowledge of Oracle Banking Microservices Architecture application.


Read Sections Completely

Each section should be read and understood completely. Instructions should never be blindly applied. Relevant discussion may occur immediately after instructions for an action, so be sure to read whole sections before beginning implementation.

Understand the Purpose of this Guidance

The purpose of the guidance is to provide security-relevant configuration recommendations. It does not imply the suitability or unsuitability of any product for any particular situation, which entails a risk decision.


The guide is limited in its scope to security-related issues. This guide does not claim to offer comprehensive configuration guidance. For general configuration and implementation guidance refer to other sources such as Vendor specific sites.

Test in Non-Production Environment

To the extent possible, guidance should be tested in a non-production environment before deployment.

Ensure that any test environment simulates the configuration in which the application will be deployed as closely as possible.

Related Resources

For more information on any related features, refer to the following documents:
  • Oracle Banking Microservices Architecture Product User Guides
  • Oracle Banking Microservices Architecture API Security Guide


The following text conventions are used in this document:

Convention Meaning


Boldface type indicates graphical user interface elements associated with an action, or terms defined in text or the glossary.


Italic type indicates book titles, emphasis, or placeholder variables for which you supply particular values.


Monospace type indicates commands within a paragraph, URLs, code in examples, text that appears on the screen, or text that you enter.

Acronyms and Abbreviations

The list of acronyms and abbreviations used in this guide are as follows:

Table -1 Acronyms

Abbreviation Description
JWE JSON Web Encryption
JWS JSON Web Signature
JWT JSON Web Token
OAM Oracle Access Manager
OSSA Oracle Software Security Assurance
SAML Security Assertion Mark-up Language
SSO Single Sign-On
SSL Secure Sockets Layer