๐ก๏ธ Oracle Tenancy default CreatedBy and CreatedOn tags are not configured๐ข
- Contextual name: ๐ก๏ธ Tenancy default CreatedBy and CreatedOn tags are not configured๐ข
- ID:
/ce/ca/oracle/tenancy/default-createdby-and-createdon-tags - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
- ๐ Oracle Tenancy
- ๐ Oracle Resource - object.extracts.yaml
- ๐งช test-data.json
Descriptionโ
Descriptionโ
This policy identifies Oracle Tenancies that do not have both required root-level default tags named
CreatedByandCreatedOn. In OCI, default tags configured at the tenancy root compartment are inherited by child compartments and help ensure supported resources receive baseline creation metadata during provisioning.Rationaleโ
Default tags support consistent resource governance across the tenancy. Applying baseline creator and creation-time metadata at provisioning time improves accountability, operational traceability, inventory hygiene, and downstream reporting.
Configuring these defaults at the tenancy root compartment is the broadest and most maintainable approach because child compartments inherit the setting. This reduces reliance on manual tagging practices and helps establish a consistent tagging baseline across environments and teams.
When the required root-level default tags are missing, supported resources may be created without standard attribution metadata. That weakens governance controls and makes it harder to investigate ownership, review provisioning activity, and apply consistent operational processes.
... see more
Remediationโ
Remediationโ
Configure Root-Level Default Tags for CreatedBy and CreatedOnโ
Create root-level default tags named
CreatedByandCreatedOnin the tenancy root compartment so supported OCI resources inherit baseline creation metadata during provisioning.From Oracle Cloud Consoleโ
- Log in to the OCI Console.
- From the navigation menu, select
Governance & Administration.- Under
Tenancy Management, selectTag Namespaces.- Under
Compartment, select the root compartment.- If no tag namespace exists, click
Create Tag Namespace, enter a name and description, and clickCreate Tag Namespace.- Click the name of the tag namespace that will hold the required tag keys.
- Click
Create Tag Key Definition.- Enter the tag key name
CreatedBy, add a description, and clickCreate Tag Key Definition.- Repeat the previous two steps to create the
CreatedOntag key definition.- From the navigation menu, select
Identity & Security.- Under
Identity, selectCompartments.- Click the name of the root compartment.
... see more
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS Oracle v3.1.0 โ ๐ผ 4.1 Ensure default tags are used on resources - Level 1 (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ System Configuration | 61 | no data |