Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Severity : HighMedium

Description: This control ensures that OCI block volumes are protected against unintended and malicious deletion by unauthorized groups and users. Access privilege for IAM users/groups for resources types in volume-family should be configured with least privilege. Access policies for volumeusers and groups should replace statements for permission for VOLUME_DELETE, VOLUME_BACKUP_DELETE or VOLUME_ATTACHMENT_DELETE with statement request.permission != {VOLUME_DELETE, VOLUME_BACKUP_DELETE, VOLUME_ATTACHMENT_DELETE}.

...