Creating a Security Zone

Create a security zone to help ensure that the resources in a compartment comply with security policies.

Before you create a security zone, you must enable Cloud Guard in the tenancy. See Getting Started with Cloud Guard.

When you create a security zone, you can select an Oracle-managed recipe or a custom recipe.

When you create a security zone for a compartment, Cloud Guard performs the following actions:
  • Deletes any existing Cloud Guard target for the compartment and its subcompartments
  • Creates a security zone target for the compartment
  • Adds the default Oracle-managed detector recipe to compartments in the security zone

If you create a security zone for a subcompartment whose parent compartment is already in a security zone, Cloud Guard creates a separate security zone target for the subcompartment. No changes are made to the existing target for the parent compartment.

The following diagram illustrates the Cloud Guard configuration for a new security zone in a subcompartment:


The parent compartment is in a security zone and the child compartment is in a different security zone. Each compartment is associated with a different security zone target in Cloud Guard. The security zone target for the child compartment is associated with default detector recipes.

View full-size image.

Caution

For maximum flexibility, avoid assigning a security zone to the root compartment of the tenancy. Security zones applied to the root compartment might constrain the actions that are possible across an entire tenancy. Although this configuration might be preferable for specific use cases, it's too restrictive for most users.