OCI-Database-Database-Policy-Protection
Severity : Medium
Description: This control ensures that OCI database instances are protected against unintended and malicious deletion by unauthorized groups and users. database users/groups should be able to create database table-spaces but not delete them. Security policies for database users and groups should remove statements for permission for DB_SYSTEM_DELETE, DATABASE_DELETE, DB_HOME_DELETE with where statement request.permission !={DB_SYSTEM_DELETE, DATABASE_DELETE, DB_HOME_DELETE} . It is recommended that minimum possible set of IAM users and groups have database delete permissions . Only give DELETE permissions to tenancy and compartment administrators
Remediation Steps:
Perform following to update bucket access policies :
Login to the OCI console at Cloud Sign In .
In the navigation, Click Identity & Security.
Under Identity, click Policies.
Select the compartment and then reported policy . Â The policy's details and statements are displayed.
Click Edit Policy Statements.
In Policy Builder Select Basic or Advance editor to update the policy statements with request.permission != INSTANCE_DELETE.
Click Save Changes.
Important:
Reference:
Blue Hexagon Proprietary