๐ก๏ธ Oracle IAAS Instance Secure Boot is disabled๐ข
- Contextual name: ๐ก๏ธ Oracle IAAS Instance Secure Boot is disabled๐ข
- ID:
/ce/ca/oracle/compute/instance-secure-boot - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Descriptionโ
Descriptionโ
This policy identifies Oracle IAAS Instances where Secure Boot is disabled when platform configuration data is available.
Rationaleโ
Secure Boot helps verify the integrity of the boot process by allowing the instance to start only trusted boot components. Enabling Secure Boot reduces exposure to bootkits, rootkits, and other boot-level tampering that can compromise an instance before the operating system security controls are fully active.
Secure Boot is part of OCI shielded instance platform configuration. Where this platform configuration is available, Secure Boot should be enabled unless the workload has a documented compatibility exception, such as a dependency on unsigned boot components or drivers.
Auditโ
This policy flags an Oracle IAAS Instance as
INCOMPLIANTwhen thePlatform Config JSONfield does not containisSecureBootEnabledset to true.Instances where
Platform Config JSONcontainsisSecureBootEnabledset to true are marked asCOMPLIANT.Instances where the platform configuration JSON is empty, malformed, or does not contain a boolean Secure Boot value are marked as
UNDETERMINED.... see more
Remediationโ
Remediationโ
Recreate the Instance with Secure Boot Enabledโ
Existing OCI compute instances cannot be converted in place to Shielded instances with Secure Boot enabled. To remediate this finding, replace the affected instance with a new compatible Shielded instance that has Secure Boot enabled at launch.
Before remediation, review workload compatibility and availability requirements:
- Secure Boot is not available for every instance shape or operating system image.
- Secure Boot can prevent startup if the image, bootloader, kernel modules, or drivers are not compatible with Secure Boot verification.
- Shielded instances with Secure Boot do not support live migration because the hardware TPM is not migratable.
- During OCI infrastructure maintenance, an instance that cannot live migrate might experience an outage instead of being moved to a healthy host with minimal disruption.
From Oracle Cloud Consoleโ
- Identify the affected instance, its image, shape, boot volume, attached block volumes, VNICs, network configuration, metadata, tags, and application dependencies.
... see more
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS Oracle v3.1.0 โ ๐ผ 3.2 Ensure Secure Boot is enabled on Compute Instance - Level 2 (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Threat Protection | 33 | no data |