You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: security/security-design/shared-assets/oci-security-health-check-standard/files/oci-security-health-check-standard/README.txt
+17-17
Original file line number
Diff line number
Diff line change
@@ -36,23 +36,23 @@ Usage
36
36
- If "Domains" are listed you are migrated to Identity Domains
37
37
- Create a group grp-auditors
38
38
- Create a policy pcy-auditing with these statements:
39
-
- For tenancies without Identity Domains use
40
-
allow group grp-auditors to inspect all-resources in tenancy
41
-
allow group grp-auditors to read instances in tenancy
42
-
allow group grp-auditors to read load-balancers in tenancy
43
-
allow group grp-auditors to read buckets in tenancy
44
-
allow group grp-auditors to read nat-gateways in tenancy
45
-
allow group grp-auditors to read public-ips in tenancy
46
-
allow group grp-auditors to read file-family in tenancy
47
-
allow group grp-auditors to read instance-configurations in tenancy
48
-
allow group grp-auditors to read network-security-groups in tenancy
49
-
allow group grp-auditors to read resource-availability in tenancy
50
-
allow group grp-auditors to read audit-events in tenancy
51
-
allow group grp-auditors to read users in tenancy
52
-
allow group grp-auditors to read vss-family in tenancy
53
-
allow group grp-auditors to read dns in tenancy
54
-
allow group grp-auditors to use cloud-shell in tenancy
55
-
- For tenancies *with* Identity Domains use
39
+
- For tenancies without Identity Domains use
40
+
allow group grp-auditors to inspect all-resources in tenancy
41
+
allow group grp-auditors to read instances in tenancy
42
+
allow group grp-auditors to read load-balancers in tenancy
43
+
allow group grp-auditors to read buckets in tenancy
44
+
allow group grp-auditors to read nat-gateways in tenancy
45
+
allow group grp-auditors to read public-ips in tenancy
46
+
allow group grp-auditors to read file-family in tenancy
47
+
allow group grp-auditors to read instance-configurations in tenancy
48
+
allow group grp-auditors to read network-security-groups in tenancy
49
+
allow group grp-auditors to read resource-availability in tenancy
50
+
allow group grp-auditors to read audit-events in tenancy
51
+
allow group grp-auditors to read users in tenancy
52
+
allow group grp-auditors to read vss-family in tenancy
53
+
allow group grp-auditors to read dns in tenancy
54
+
allow group grp-auditors to use cloud-shell in tenancy
55
+
- For tenancies *with* Identity Domains use
56
56
allow group 'Default'/'grp-auditors' to inspect all-resources in tenancy
57
57
allow group 'Default'/'grp-auditors' to read instances in tenancy
58
58
allow group 'Default'/'grp-auditors' to read load-balancers in tenancy
0 commit comments