๐ก๏ธ Oracle IAAS Instance in-transit encryption is disabled๐ข
- Contextual name: ๐ก๏ธ Instance in-transit encryption is disabled๐ข
- ID:
/ce/ca/oracle/compute/instance-in-transit-encryption - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Descriptionโ
Descriptionโ
This policy identifies Oracle IAAS Instances that do not have in-transit encryption enabled for the attached boot volume.
Rationaleโ
In-transit encryption protects storage traffic between an Oracle compute instance and its boot volume. Without this protection, data moving between the instance and the storage service may be exposed to interception or unauthorized inspection within the network path.
Enabling in-transit encryption for boot volume attachments helps maintain confidentiality for workload data and supports consistent encryption controls across compute storage connections.
Auditโ
This policy flags an Oracle IAAS Instance as
INCOMPLIANTwhen theBoot Volume: PV Encryption In Transitfield is set to Disabled.Instances where
Boot Volume: PV Encryption In Transitis set to Enabled are marked asCOMPLIANT.Instances where the field is empty or contains an unexpected value are marked as
UNDETERMINED.
Remediationโ
Remediationโ
Enable Boot Volume In-Transit Encryptionโ
In-transit encryption for boot and block volumes is available only for virtual machine (VM) instances launched from platform images and for bare metal instances that use one of the following shapes:
BM.Standard.E3.128BM.Standard.E4.128BM.DenseIO.E4.128In-transit encryption is not supported on other bare metal instance shapes. If the affected instance does not support changing this setting in place, recreate the instance using a supported configuration and enable in-transit encryption during instance creation.
From Oracle Cloud Consoleโ
If the Use in-transit encryption option is available for the affected instance, update the instance configuration:
- Navigate to
https://cloud.oracle.com/compute/instances.- Select the affected instance from the audit results.
- Click More actions or Actions.
- Click Edit.
- Select Show Advanced Options.
- Enable Use in-transit encryption.
- Click Save changes.
If the Use in-transit encryption option is not available for the affected instance, recreate the instance with boot volume in-transit encryption enabled:
... see more
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS Oracle v3.1.0 โ ๐ผ 3.3 Ensure In-transit Encryption is enabled on Compute Instance - Level 1 (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Data Encryption | 65 | no data |