About Security Controls

For any cloud project—whether you're migrating an application to Oracle Cloud, using an application from Oracle Cloud Marketplace, or building enterprise and cloud-native applications—it’s important for your development and security teams to work together in a DevSecOps model. Security controls enable your development team and security administrators to collaboratively manage the security of your cloud resources.

Use these controls to manage access to your services and segregate operational responsibilities to reduce the risk associated with potentially malicious and accidental user actions.

The remainder of this document presents all the security controls available in Oracle Cloud Infrastructure, as checklists that you can use when designing, deploying, and managing your workloads in Oracle Cloud.

A separate checklist is provided for each of the following security areas:
  • Authentication
  • Authorization
  • Resource isolation
  • Network security
  • Compute instance security
  • Service-level security
  • Data protection
  • Governance, audit, and monitoring
  • Incident management and response
  • Compliance and application security
  • Operational resilience and business continuity