New Security Zone policies offer more security controls
- Services: Security Zones
- Release Date: May 30, 2025
Security Zones has released 19 new policies to ensure that resources in security zones comply with security best practices.
Some new policies manage several actions under one policy. For example, deny manage_bastion_resource prevents a bastion or bastion session from being created, updated, or deleted in the security zone.
You can read the details for each of the following new policies in the user guide:
deny DRG_gatewaydeny LPG_gatewaydeny NAT_gatewaydeny SGW_gatewaydeny create_or_modify_vcn_security_listdeny create_drgdeny create_vcn_security_listdeny delete_all_load_balancer_back_end_setsdeny terminate_instancedeny update_network_security_group_egress_rulesdeny manage_bastion_resourcedeny manage_compute_and_block_storage_resourcedeny manage_DHCP_options_resourcedeny manage_DNS_resourcedeny manage_file_storage_resourcedeny manage_image_resourcedeny manage_oke_servicedeny manage_vcn_route_tablesdeny manage_virtual_network_resource
You can enable the new policies in security zone recipes.