Ensure that encryption of data in transit between the OCI instance, the boot volume, and the block volume(s) is enabled for all Oracle Cloud Infrastructure (OCI) compute instances in order to protect sensitive data from interception and maintain compliance with regulatory and organizational requirements.
The data transmitted between the OCI compute instance and the associated disk volumes is delivered over a secure internal network. However, if you have specific compliance requirements related to the encryption of the data while in transit between the instance and the attached volumes, it is strongly recommended to enable in-transit encryption for all the disk volumes attached to your OCI compute instances.
The list of supported VM shapes and images are available here.
Audit
To determine if encryption of data in transit between the OCI instance and the attached volumes is enabled, perform the following operations:
Remediation / Resolution
To ensure that encryption of data in transit between the OCI instance and the attached volumes is enabled, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Overview of the Compute Service
- Overview of Block Volume
- Enabling In-Transit Encryption Between an Instance and Boot Volumes or Block Volumes
- Oracle Cloud Infrastructure CLI Documentation
- Compartment list
- Instance list
- Instance get
- Instance launch