7.1 OCI Shared Security Responsibility Model
Key Takeaways
- The Cloud Shared Security Responsibility Model establishes a definitive operational boundary between Oracle (the cloud provider) and the customer (the cloud subscriber).
- Oracle assumes exclusive responsibility for 'Security OF the Cloud,' encompassing the physical security of data centers, host hardware, custom hypervisors, physical cabling, core networking infrastructure, and global compliance certifications (such as SOC, ISO 27001, and PCI-DSS).
- The customer retains primary responsibility for 'Security IN the Cloud,' including customer data classification, Identity and Access Management (IAM), multi-factor authentication, guest operating system security and patching, network security rules (NSGs and Security Lists), and application logic.
- Security obligations shift across cloud delivery tiers: Infrastructure as a Service (IaaS) places the greatest operational burden on the customer (including guest OS and runtime), Platform as a Service (PaaS) delegates OS and database engine maintenance to Oracle, while Software as a Service (SaaS) delegates virtually the entire application and infrastructure stack to Oracle.
- Regardless of the cloud deployment architecture (IaaS, PaaS, or SaaS), the customer always retains 100% ownership and non-delegable responsibility for their data classification, user credential governance, and access authorization.
7.1 OCI Shared Security Responsibility Model
[!NOTE] Foundations Blueprint Focus: The Shared Security Responsibility Model is one of the most frequently tested concepts on the OCI Foundations Associate (1Z0-1085-26) exam. Candidates must clearly differentiate between security OF the cloud (Oracle's responsibility) and security IN the cloud (the customer's responsibility), identify how duties shift across IaaS, PaaS, and SaaS, and recognize that customer data ownership and access control never transfer to the cloud provider.
Migrating enterprise workloads from on-premises datacenters to the public cloud fundamentally alters how security operations, risk management, and regulatory compliance are governed. In a traditional corporate datacenter, the organization assumes total responsibility for the entire technology stack—from the perimeter fences, biometric badges, backup generators, and physical server racks up through hypervisors, operating systems, network firewalls, and application source code.
In Oracle Cloud Infrastructure (OCI), this operational burden is partitioned through the Shared Security Responsibility Model. Under this framework, security obligations are divided between Oracle (the cloud provider) and the customer (the cloud tenant). Understanding where Oracle's perimeter ends and where customer governance begins is paramount for maintaining robust defense-in-depth and passing the 1Z0-1085-26 examination.
The Core Division: Security "OF" vs. Security "IN" the Cloud
Oracle summarizes the shared responsibility framework using a foundational distinction:
+-------------------------------------------------------------------------+
| OCI SHARED SECURITY RESPONSIBILITY MODEL |
+------------------------------------+------------------------------------+
| SECURITY "OF" THE CLOUD | SECURITY "IN" THE CLOUD |
| (Oracle's Responsibility) | (Customer's Responsibility) |
+------------------------------------+------------------------------------+
| • Physical data center security | • Customer data & classification |
| • Perimeter guards & biometrics | • Identity & Access Management |
| • Server hardware & SmartNICs | • User credentials & MFA policies |
| • Host hypervisor isolation | • Guest OS installation & patching |
| • Physical cabling & power grids | • Virtual firewalls (NSGs & SLs) |
| • Core network backbone | • Application code & API endpoints |
| • Global compliance (SOC, ISO, PCI)| • Database schemas & access grants |
+------------------------------------+------------------------------------+
1. Security "OF" the Cloud (Oracle's Responsibility)
Oracle assumes complete, unilateral custody of the physical facilities, underlying hardware, and foundational software systems that power OCI:
- Physical and Facility Security: Oracle designs, constructs, and operates state-of-the-art datacenters equipped with multi-layered perimeter defenses, 24/7 armed security personnel, continuous CCTV surveillance, biometric mantraps, and strict visitor vetting protocols.
- Environmental and Hardware Infrastructure: Oracle manages redundant power grids, uninterrupted power supplies (UPS), backup diesel generators, industrial HVAC cooling systems, fire suppression infrastructure, and physical server hardware decommissioning (including cryptographic disk shredding adhering to NIST SP 800-88 guidelines).
- Off-Box Virtualization & Hypervisor Architecture: A hallmark of OCI's Gen 2 Cloud architecture is isolated off-box network virtualization. In traditional clouds, the hypervisor resides on the server host and manages both compute and network traffic, creating potential attack surfaces for hypervisor breakout vulnerabilities. OCI moves network and storage virtualization onto customized SmartNIC silicon cards. The hypervisor running on the physical host machine is hardened and isolated, and Oracle maintains full responsibility for hypervisor updates, microcode patches, and host firmware integrity.
- Core Physical Backbone: Oracle owns and maintains the high-speed, non-blocking multi-terabit physical network fabric connecting datacenters, Availability Domains, and regions worldwide.
- Regulatory Certifications: Oracle maintains independent third-party audits and compliance attestations across international security standards, including SOC 1/2/3, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, PCI-DSS Level 1, HIPAA, and FedRAMP.
2. Security "IN" the Cloud (Customer's Responsibility)
The customer retains total control over what is deployed inside their OCI tenancy, how network traffic is routed, and who is permitted access:
- Customer Data Protection: The customer is the sole owner and custodian of their data. Customers are responsible for data classification (public, internal, confidential, restricted), determining retention lifecycles, and configuring encryption keys (whether utilizing Oracle-managed keys or customer-managed keys via OCI Vault).
- Identity and Access Management (IAM): Customers are responsible for creating users, provisioning groups, establishing least-privilege policy statements, enforcing strong password complexities, configuring Multi-Factor Authentication (MFA), and managing federation with corporate identity providers.
- Guest Operating System Hardening & Patching: When deploying IaaS compute virtual machines or bare metal instances, the customer is responsible for installing OS security patches, updating kernels, disabling unused daemons, configuring host-based firewalls (iptables/firewalld), and managing SSH private keys.
- Software-Defined Networking & Traffic Filtering: Customers architect their Virtual Cloud Networks (VCNs), configure route tables, define public vs. private subnets, and establish ingress/egress firewall rules using Network Security Groups (NSGs) and Security Lists.
- Application Security: Writing secure, vulnerability-free application code, securing REST API endpoints, defending against OWASP Top 10 vulnerabilities, and integrating Web Application Firewalls (OCI WAF) rests squarely on the customer.
Shifting Responsibilities Across Cloud Service Models
The boundary dividing Oracle's obligations from the customer's obligations shifts dynamically based on the cloud service delivery model deployed: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS).
+-------------------------------------------------------------------------+
| OPERATIONAL RESPONSIBILITY SPECTRUM BY TIER |
+-------------------+-------------------+----------------+----------------+
| LAYER | IaaS (e.g. Compute| PaaS (e.g. ADB,| SaaS (e.g. |
| | & Block Volumes) | OKE, APEX) | Fusion Cloud) |
+-------------------+-------------------+----------------+----------------+
| Customer Data | Customer | Customer | Customer |
| IAM & Access | Customer | Customer | Customer |
| Application Code | Customer | Customer | Oracle |
| Database Engine | Customer | Oracle | Oracle |
| Operating System | Customer | Oracle | Oracle |
| Virtualization | Oracle | Oracle | Oracle |
| Physical Hardware | Oracle | Oracle | Oracle |
| Data Center | Oracle | Oracle | Oracle |
+-------------------+-------------------+----------------+----------------+
1. Infrastructure as a Service (IaaS)
In IaaS (such as OCI Compute virtual machines, Bare Metal instances, and Block Volumes), the customer enjoys maximum architectural flexibility but bears the highest operational security responsibility:
- Oracle manages the physical facilities, power, compute hardware, and bare metal provisioning hypervisor.
- The customer selects the operating system (e.g., Oracle Linux, Ubuntu, Windows Server), configures local user accounts, applies OS-level security patches, configures storage volume encryption keys, and hardens the application runtime.
2. Platform as a Service (PaaS)
In PaaS (such as Oracle Autonomous Database, OCI Kubernetes Engine managed control planes, and OCI GoldenGate), Oracle abstracts away the operating system and underlying middleware:
- Oracle provisions, monitors, tunes, and automatically patches the guest operating system, container runtime, and database engine with zero downtime.
- The customer is relieved of server maintenance but remains fully responsible for database schema security, table-level user grants, SQL query optimization, connection IP whitelisting, and application-level IAM policies.
3. Software as a Service (SaaS)
In SaaS (such as Oracle Fusion Cloud Applications, ERP, HCM, and NetSuite), Oracle operates and manages virtually the entire technology stack:
- Oracle manages the application code, runtime, middleware, database, OS, hypervisor, server hardware, and datacenter facilities.
- The customer is solely responsible for user identity governance, role-based access assignment, multi-factor authentication, and data classification.
Service Delivery Model Comparison Matrix
The following matrix details the granular division of security ownership across all layers of the cloud computing stack:
| Technology Stack Layer | Infrastructure as a Service (IaaS) | Platform as a Service (PaaS) | Software as a Service (SaaS) |
|---|---|---|---|
| Physical Data Center & Perimeter | Oracle | Oracle | Oracle |
| Physical Server Hardware & SmartNICs | Oracle | Oracle | Oracle |
| Hypervisor & Core Virtualization | Oracle | Oracle | Oracle |
| Guest Operating System & Kernel Patching | Customer | Oracle | Oracle |
| Runtime Environment & Middleware | Customer | Oracle | Oracle |
| Database Engine Installation & Patching | Customer | Oracle | Oracle |
| Application Code & Custom Logic | Customer | Customer | Oracle |
| Network Ingress/Egress (NSGs & Firewalls) | Customer | Customer / Shared | Oracle |
| Identity & Access Management (IAM) | Customer | Customer | Customer |
| Customer Data Governance & Classification | Customer | Customer | Customer |
High-Risk Exam Traps & Real-World Pitfalls
When preparing for the 1Z0-1085-26 examination, watch out for these subtle, commonly tested traps:
- The "Cloud Provider Secures My Data" Fallacy: The exam frequently tests whether Oracle is responsible for securing, classifying, or backing up customer data in IaaS or PaaS. Oracle is never responsible for classifying customer data or managing user authorization. Even if data is encrypted at rest by default using Oracle-managed keys, the customer remains responsible for credential integrity, access permissions, and data retention rules.
- PaaS Database Misconceptions: While Oracle Autonomous Database is "Self-Securing" (automatically applying database patches and encrypting data at rest and in transit), the customer remains 100% responsible for database user accounts, password policies, client wallet access credentials, and network access control lists (ACLs).
- Network Security Defaults: In OCI, a newly created custom route table or Network Security Group contains no allow rules by default. If a customer writes an overly permissive security rule (such as
0.0.0.0/0ingress on port 22 or port 3389), Oracle does not block or modify that rule. Network exposure resulting from misconfigured security lists is exclusively a customer security failure. - Data Deletion and Backup Retention: If a customer deletes an Object Storage bucket or an autonomous database, Oracle will not restore it unless the customer configured automated backup policies, retention locks, or Object Storage lifecycle rules. Business continuity planning remains a customer obligation.
An enterprise deploys a fleet of compute virtual machines running Oracle Linux in an OCI Virtual Cloud Network to host an e-commerce platform. A zero-day security flaw is announced in the Linux kernel. Under the OCI Shared Security Responsibility Model, which party is responsible for applying the operating system security patch to the running instances?
Which critical security responsibility remains the exclusive obligation of the customer across ALL cloud service delivery models (IaaS, PaaS, and SaaS)?
A systems architect is evaluating the security architecture of Oracle Cloud Infrastructure. Which of the following components is managed entirely by Oracle under the category of 'Security OF the Cloud'?