5 Security Shield Software Development Security

The Oracle Communications Security Shield Cloud Service (Security Shield) strictly follows Oracle Software Security Assurance (OSSA) guidelines for software development. Software security is always the top focus during software design, development, and deployment. Oracle Communications statically scans all source code and third-party software within our Continuous Integration-Continuous Delivery pipeline. Oracle Communications dynamically tests (fuzzing, penetration) all releases. All Oracle Communications Docker images pass through security and virus scans. Oracle Communications audits, fixes, or mitigates all security issues. Each Security Shield release is reviewed by Oracle Cloud Architecture Review (CAR), Corporate Security Solution Assurance Process (CSSAP), and verified by Security Assessment Review (SAR).

Security Shield Security Patching

The Oracle Communications Security Shield Cloud Service (Security Shield) cloud components follow the Continuous Integration-Continuous Delivery pipeline to patch any security vulnerabilities in the Oracle Cloud Infrastructure and the Cloud Native Environment, as is Oracle's responsibility. Security patches for the Cloud Communication Service (CCS) are a shared responsibility between Oracle and its customers. The CCS follows the Oracle Software Security Assurance requirement for handling security vulnerabilities and security fixes, which Oracle provides through the Oracle Critical Patch Update (CPU) process. Use the following link for the Oracle CPU portal :https://www.oracle.com/security-alerts/#CriticalPatchUpdates. It is your responsibility to check Oracle's CPU bulletin for security patches for the CCS and download and apply the proper security patches.