Skip to content
AMTEXConsulting

Fusion security and OCI identity

Access that passes the audit the first time.

Fusion role design and segregation of duties, Risk Management Cloud, OCI IAM identity domains and federation, Data Safe, Cloud Guard and Security Zones, so security is designed once and provable every quarter.

Overview

Security & Identity, done properly.

Security in Oracle estates usually fails in the seams: a Fusion role copied from a seeded template that grants too much, an integration user with a human's privileges, an OCI policy written as allow-all to get a demo working. AMTEX designs the access model across Fusion and OCI together and leaves you with the evidence auditors ask for.

Technologies

  • Fusion Security Console
  • Risk Management Cloud
  • OCI Vault & IAM
  • OCI IAM Identity Domains
  • Oracle Data Safe
  • Cloud Guard & Security Zones

What we deliver

Capabilities

Everything AMTEX builds, configures and runs across Security & Identity.

  • Fusion role design

    Custom job and data roles built from the segregation-of-duties matrix, not copied from seeded roles.

  • Segregation of duties

    Conflict analysis, mitigating controls and periodic access reviews, with Risk Management Cloud where licensed.

  • Risk Management Cloud

    Advanced Access Controls and Financial Reporting Compliance configuration and rollout.

  • OCI IAM identity domains

    Domain design, groups, policies written for least privilege, dynamic groups for workloads.

  • Federation & SSO

    Entra ID or Okta federation for Fusion and OCI, MFA policy, and provisioning driven from HCM events.

  • Integration and service identities

    Dedicated integration users, OAuth clients, secret rotation in Vault; no shared human accounts anywhere.

  • Data Safe & database security

    Sensitive data discovery, masking for test pods and non-production, activity auditing on ATP.

  • Cloud Guard & Security Zones

    Posture management, detector tuning, responder rules and enforced guardrails per compartment.

  • Audit evidence

    Role catalogues, access review records, policy exports and change logs packaged for SOX and ISO audits.

The hard parts

Where these projects become difficult

The places programmes slip, and what we do about each one.

  1. 01

    Seeded roles in production

    The problem

    Users hold seeded roles with privileges nobody reviewed.

    How AMTEX approaches it

    Role redesign from the matrix, a phased cut-over with user acceptance, and access reviews scheduled.

  2. 02

    Allow-all policies

    The problem

    OCI policies granting manage on the tenancy because it worked in the demo.

    How AMTEX approaches it

    Policy review against the CIS OCI benchmark, compartment-scoped rewrites, Security Zones to stop regressions.

How we work

From first conversation to steady state

  1. 01

    Assess

    Roles, policies, integration identities, findings from the last audit.

  2. 02

    Design

    SoD matrix, role model, identity domain and policy design.

  3. 03

    Implement

    Roles, federation, Vault, Cloud Guard, Data Safe; cut-over with reviews.

  4. 04

    Prove

    Access reviews, evidence packs and quarterly posture checks.

An audit finding on access, or a migration that needs a clean role model?

We will assess the current state and give you a plan the auditors will accept.