ELI5: OCI CloudGuard

ELI5: OCI CloudGuard

I like it when complex things are made simple. And the strange thing is, whilst most of what is in the cloud isn’t really all that complex, the hyperscalers seem to do a really good job of simultaneously giving you too much information and not enough (this is the one thing they all seem to have in common!)

I just want to know how something works. Like, conceptually.

No alt text provided for this image
OCI CloudGuard Functional Diagram

I put together the functional diagram above to capture the high-level function of OCI CloudGuard for a customer and figured it’d be worth sharing in the event it helps others who are seeking to communicate how a functional CloudGuard flow is constructed. For those that are unfamiliar, CloudGuard is (roughly) the OCI equivalent of Azure Defender for Cloud CSPM and AWS Security Hub. So here is my ELI5 (Explain Like I’m 5… thanks Reddit) for OCI Cloud Guard:

Targets: Associate an OCI compartment (and its included resources) with a set of Detector and Responder Recipes

Detector Recipes: A set of posture checks performed against the target resources

Problem: A problem is logged when a resource fails an enabled posture check (e.g. a Public IP address is assigned to a resource). Problems can have user defined severity levels.

Responder Recipes: Define a set of treatments for problems (i.e. notify or remediate)

Events: When a problem is logged, the responder emits an Event to OCI Events - a standardised messaging bus across OCI services

Notification: Rules in the OCI Events service can be configured to trigger on Events raised by the CloudGuard service which publish a message to a Topic.

Subscribers: Consumers of messages published to a Topic. These consumers are services in themselves which do things like Send an Email, triggering a Serverless Function to make an API call or alert a pager service.

Hope it helps!

Scott Evans

Finance & Technology Integration | Wealth Management | Unlock Tech-Driven Growth

1 年

It's also probably worth adding in Instance Principal Authentication. I find this a game changer.. especially when you use the PL/SQL SDK. Now that's impressive. Scott

Des McCrory

Enterprise Solutions Architect | Data, Infrastructure and Cloud | Oracle Cloud Infrastructure Specialist

1 年

Thanks Tom. I’m a visual person too.

Scott Fletcher

Principal Cyber Security Consultant

1 年

A great diagram Tom. There’s also the ability to ingest custom logs using the “Log Insight Detector” to extend out of the box detectors. And there’s detectors for Fusion App’s allowing you to gain insight into the security of your Oracle SaaS applications.

要查看或添加评论,请登录

Tom Walker的更多文章

  • Why we love Wiz

    Why we love Wiz

    What is it? Founded in 2020, Wiz set out with the simple goal of helping organisations visualise and contextualise…

    2 条评论
  • Why we love OCI

    Why we love OCI

    What is it? Oracle Cloud Infrastructure (OCI) is Oracle’s entry into the hyperscale cloud market. Launched in 2018, OCI…

    4 条评论
  • Connecting Wiz to your AWS Organization

    Connecting Wiz to your AWS Organization

    AWS is by a fair margin the most popular cloud hyperscale platform. It’s also been around the longest - so it’s not all…

    2 条评论
  • Connecting Wiz to your OCI Cloud Tenancy

    Connecting Wiz to your OCI Cloud Tenancy

    We love OCI here at Cordant. Sure, it doesn't do everything - but what it does do, it does very well.

    2 条评论
  • Making Azure Update Manager work with Ubuntu 24

    Making Azure Update Manager work with Ubuntu 24

    I like what Microsoft are trying to do with Azure Update Manager, but it's still a little bit..

  • What does it mean to be pragmatic in IT?

    What does it mean to be pragmatic in IT?

    I’m unashamedly parsimonious. I'm not sure if it’s my Scottish heritage, or the fact that I’m surrounded by Lean…

    6 条评论
  • Microsoft Teams (New) Outlook Add-In Fix

    Microsoft Teams (New) Outlook Add-In Fix

    Customers have been reporting an issue whereby after Microsoft Teams (New) is centrally deployed to Azure Virtual…

    4 条评论
  • Zero Trust: Why the bright sparks are going dark.

    Zero Trust: Why the bright sparks are going dark.

    A "Sophisticated Attack". That's what the Medibank breach and exfiltration is being described as.

    6 条评论
  • The Multi-cloud Blueprint

    The Multi-cloud Blueprint

    Ten years ago there were but a brave few who dared untether from the safe confines of Mother Earth and venture to the…

    8 条评论
  • It's time for OCI to shed its Oracle cocoon and build its own brand

    It's time for OCI to shed its Oracle cocoon and build its own brand

    Just a quick one this morning - I was going through my LinkedIn feed and stumbled across a post discussing global cloud…

    6 条评论

社区洞察

其他会员也浏览了