6 Oracle SDM Cloud Cloud Security

The Oracle® Session Delivery Management Cloud service (Oracle SDM Cloud) deploys in the Oracle Cloud Native Environment (CNE), which is a highly secured Platform as a Service (PaaS) environment provided by the Oracle Cloud team in the Oracle Cloud Infrastructure (OCI).

The Oracle SDM Cloud SaaS can provide a highly secured cloud service and the Oracle SDM Cloud CI/CD pipeline routinely rotates client secrets for enhanced security operations. Oracle stores all logs that the Oracle SDM Cloud collects and monitors, including security logs, in a centralized application to detect any security violation in real time.

See the Oracle Cloud Infrastructure Security Guide at https://docs.oracle.com/en-us/iaas/Content/Security/Concepts/security_guide.htm.

On-premises Infrastructure Security

While the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) service provides high quality and secure Podman images for the Management Cloud Engine (MCE), the MCE is deployed in your network running on your platforms (for example, Operating System (OS) and file systems). It remains a joint responsibility to ensure that the MCE runs in a secured environment. Oracle recommends that you securely harden your OS, and that access to your OS, upon which MCE is running, is well managed. Inappropriate access to the MCE environments can lead to exposure of the configuration. Oracle recommends that you ensure that you reserve proper resources (memory, CPU, network bandwidth) for the MCE.

Secure MCE Deployment

The Management Cloud Engine (MCE) facilitates providing communication between Network Functions (NFs) on the customer premises (for example, SBC, ESBC, or OCSM) which are considered trusted components with the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) services in the cloud. Because the MCE is an important component in management and monitoring of the NFs, Oracle recommends that you deploy the MCE in the DMZ and ensure that the NFs have access to it in order to ensure MCE to NF communications can be established.

Often, security gateways (or firewalls) are deployed before DMZs in private networks. In such scenarios, you must configure the gateways to properly allow traffic to the NFs and the MCE. The MCE installation documents list the default ports, which you can modify. The port configuration is needed to configure security gateways. See the Oracle Session Delivery Management Cloud Getting Started Guide for the default ports and installation instructions.

Oracle SDM Cloud Service Security Auditing

Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) automatically records user-initiated activities in Security Manager audit logs. These logs support FCAPS (Fault, Configuration, Accounting, Performance, and Security), Route Management, Reporting and Analytics, Lifecycle Management, compliance and enable you to track user activity within Oracle SDM Cloud.

Audit logs are customer-owned and can be accessed through the Oracle SDM Cloud Security Manager portal or the REST API.

Users in the Administrators group can also configure Oracle SDM Cloud to export audit logs in CSV format to one or more customer-managed external endpoints using SFTP through the Management Cloud Engine (MCE). Audit log export supports scheduled transfers and on-demand synchronization, with either password-based or public key-based authentication.

The MCE initiates the SFTP connection outbound to the receiver host; the receiver host does not initiate a connection from Oracle SDM Cloud or MCE.

Oracle SDM Cloud does not copy or publish the contents of customer audit logs to internal logging systems.