OCI Connection Concepts

Prev Next

1.0 Introduction

This article describes the Oracle Cloud Infrastructure (OCI) connection concepts and supported features in Fortanix Key Insight. Fortanix Key Insight enables you to apply uniform key lifecycle management policies and processes to cryptographic key management systems across multiple clouds.

2.0 Concepts

The following table summarizes the OCI connection concepts used in Fortanix Key Insight:

CONCEPT

DESCRIPTION

OCI Tenancy

An OCI tenancy is an isolated environment in Oracle Cloud Infrastructure that contains an organization’s cloud resources. Resources within a tenancy are organized into compartments, which are used to manage resources and control access.

Fortanix Key Insight scans an OCI tenancy and all the resources within its compartments, including cryptographic resources such as keys.

OCI Compartments

A compartment is a logical container for resources within an OCI tenancy. You create and manage your OCI resources, such as vaults and keys, within compartments. Fortanix Key Insight scans all resources within the compartments in an OCI tenancy.

OCI Role

OCI Identity and Access Management (IAM) controls who can access OCI resources and what actions they can perform. IAM policies define the permissions granted to users, groups, dynamic groups, and other identities. Fortanix Key Insight requires an OCI IAM user to have permission to access the OCI tenancy and scan resources within its compartments.

OCI Services

OCI services allow users to build, deploy, and manage their IT infrastructure in the cloud. Common OCI services include Compute, Object Storage and File Storage.

OCI Key Management and Vault

OCI Key Management provides centralized management of cryptographic keys through vaults. A vault is a secure container that stores and manages cryptographic keys. Each key is identified by an Oracle Cloud Identifier (OCID). Fortanix Key Insight scans the OCI tenancies and compartments it has permission to access and identifies the compliance status of cryptographic keys across OCI regions.

OCI Dedicated Region

An OCI Dedicated Region (previously known as OCI Dedicated Cloud@Customer (DRCC)) is an OCI infrastructure deployment hosted in a customer data center that provides OCI cloud services within the customer's environment. Fortanix Key Insight connects to the OCI Dedicated Region environment and scans the configured compartments and supported OCI services to discover cryptographic assets.

OCI Scan

The process of connecting with the OCI services and obtaining information about the resources of interest to Fortanix Key Insight.

3.0 Supported Features

The Fortanix Key Insight OCI connection supports the following features:

  • Supports selecting a region (European Union (EU) or North America (NA)) when accessing Fortanix Key Insight SaaS from Fortanix Armor. All scanned data is displayed in the Key Insight UI based on the selected region, enabling region-specific data handling, reporting, and visualization while supporting compliance and governance requirements.

    NOTE

    The Region field is available only in the Fortanix Key Insight Software-as-a-Service (SaaS) environment. It is not displayed in the on-premises user interface.

  • Allows users to scan all OCI regions across compartments within an OCI tenancy, identifying cryptographic assets such as Vault keys and encryption configurations for OCI services, Object Storage, and File Storage. The scan determines which services and resources are encrypted, the keys used for encryption, and the status of those keys.

  • Generates reports on OCI Vault non-compliant keys and services.

    The assessment report shows the following information:

    • The risk score

    • Cryptographic key sources

    • Top security issues

    • Service violations

    • Key violations by sources

    • Post Quantum Cryptography (PQC) readiness of keys and services

  • Provides a dashboard view of cryptographic key and service compliance status across multiple OCI regions.

    The dashboard shows the following information:

    • Scanned OCI compartments, regions, keys, and services

    • Cryptography Bill of Materials (CBOM) export

    • Top three compartments with the most keys

    • Protected services

    • Key types

    • Key by status

    • Key by source

  • For each OCI key in a region:

    • Provides a tabular view that shows key details, such as key name, version, state, key algorithm, compartment ID, region, vault name, rotation date, creation date, and so on.

    • Displays a map of the key compliance status.

    • Detects non-compliant keys based on the applied policies and issues vulnerability alerts according to NIST standards.

    • Provides essential information such as key properties, key owner(s), rotation details, service mappings, and related violations.

  • For each OCI service in a region:

    • Displays a comprehensive overview that allows you to filter by service name, service type, violation type, key ID, encryption status, compartment ID, and region. You can click on each service to view a detailed list of associated vulnerabilities, if applicable.

    • Provides a tabular view that shows key information, such as the service name, service type, violation type, key ID, encryption status, compartment ID, and region.

    • Provides detailed insights into service configurations and violations associated with each service, helping you understand potential issues and compliance gaps.

  • Allows users to export all scanned keys and service data in comma-separated values (CSV) format and track export activities.

  • Allows users to export all scanned keys and service metadata in CBOM-compliant JSON format to track post-quantum readiness and cryptographic risk.

  • Supports secure, secret-based authentication for OCI connections and requires users to provide a User ID and RSA private key for authentication.

  • Allows users to create and manage user-defined policies, duplicate and modify system-defined, Fortanix DSM, or existing user-defined policies, and automatically retrieve cryptographic policies from Fortanix DSM to apply them to scanned connections.

  • Provides an assessment report that identifies vulnerabilities by providing a snapshot of the data security posture and risk score, highlighting areas of strength and identifying opportunities for improvement.

  • Provides a dashboard for assessing Post-Quantum Cryptography (PQC) readiness of OCI connections. The dashboard features a sunburst chart that simplifies the visualization of keys and services data points and provides drill-down capabilities for deeper insights.

Fortanix-logo

4.6

star-ratings

As of August 2025