This image shows a secure architecture for OCI cyber resilience, organized into compartments and shows the flow of data, network segmentation, and key OCI services.

Tenancy - Root Compartment: Shows Oracle Identity and Access Management, with the following roles/policies:

Network Compartment: Hosts OCI Network Hub VCN (Virtual Cloud Network) compartment which hosts a "Firewall Subnet" that includes a Firewall Compute Appliance or Oracle-managed Firewall service.

Application Compartment: Hosts Applications VCN with an Application subnet.

Database Compartment: Hosts the Database VCN with a Database Subnet hosting three services:

The DRG Attachment connects to the Internet gateway using the DRG. The compartment connects to the Oracle Services Network using the Sevice Gateway.

OCI Vault Compartment: Hosts the OCI Vault Isolated VCN Cyber Resilience Architecture Orchestration subnet.

Oracle Services Network

Security Compartment: Hosts OCI security-related services, including:

Flow and Connectivity