Article 14 – IAM Audit Logging, Cloud Guard, and Security Posture Monitoring

1. Introduction to Posture Monitoring and Auditability

In enterprise cloud governance, tracking who performed what action, on which resource, and from which IP address is a critical requirement for security compliance and incident investigation.

Oracle Cloud Infrastructure (OCI) delivers native, immutable security visibility through the OCI Audit Service and OCI Cloud Guard.

While the Audit Service automatically records every control plane API call across your tenancy, Cloud Guard acts as an automated security posture monitor, detecting IAM drift, weak password policies, or unauthorized policy modifications in real-time.

2. The OCI Audit Service Architecture

The OCI Audit Service is enabled by default across every tenancy at zero additional cost.

Key Audit Features:
  • Automatic Recording: Automatically captures all administrative API calls, Web Console actions, CLI commands, and SDK invocations.
  • Immutable Logs: Audit log events cannot be edited, tampered with, or disabled by any user (including tenancy root administrators).
  • IAM Event Format: IAM events are formatted in JSON under the com.oraclecloud.iam.* event type namespace.
{
  "eventType": "com.oraclecloud.iam.createpolicy",
  "eventTime": "2026-08-25T14:30:00.000Z",
  "principalId": "ocid1.user.oc1..aaaaaaaaxxxuser",
  "sourceIpAddress": "203.0.113.15",
  "targetId": "ocid1.policy.oc1..aaaaaaaaxxxpolicy",
  "compartmentId": "ocid1.tenancy.oc1..aaaaaaaaxxxtenancy"
}
3. Cloud Guard IAM Detector Rules

OCI Cloud Guard analyzes audit logs and resource configurations to detect security risks automatically.

Key IAM Detector Rules in Cloud Guard:
  1. IAM Policy Modification: Triggers an alert whenever a policy statement granting manage all-resources is created.
  2. User Inactivity: Flags user accounts that have not authenticated for 90 days.
  3. MFA Non-Compliance: Detects user accounts operating without active Multi-Factor Authentication.
  4. API Key Age: Alerts administrators when API signing keys exceed rotation thresholds (e.g., 180 days).
4. OCI Web Console (GUI) Step-by-Step Walkthrough

Inspecting Audit Logs and configuring Cloud Guard is executed directly in the OCI Web Console GUI.

Step 1: Searching IAM Audit Logs in the Console
  1. Log in to the Oracle Cloud Console (https://cloud.oracle.com).
  2. Open Navigation Menu (≡) ➔ Identity & Security ➔ Audit (under Logging).
  3. Select target compartment (e.g., Root Tenancy).
  4. Set Search Parameters:
  5. Start Time / End Time: Select desired date range.
  6. Filter by Service: Select Identity.
  7. Click Search. The Console displays an interactive table of all IAM API calls.
  8. Click any event row to expand the complete JSON payload showing user OCID, source IP, and requested policy changes.
Step 2: Enabling Cloud Guard IAM Detectors
  1. Navigate to Identity & Security ➔ Cloud Guard ➔ Detector Recipes.
  2. Select OCI Configuration Detector Recipe (Oracle Managed).
  3. Search for detector rule: User with MFA disabled.
  4. Ensure the status is set to Enabled and set Risk Level to High.

Cloud Guard will now automatically flag any IAM user account created without MFA enforcement.

5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “OCI Audit Logging Can Be Disabled to Save Costs”
  • Reality: OCI Audit Service is permanently enabled by Oracle at the platform layer. It cannot be turned off, and basic audit log retention (up to 365 days) is included free of charge.
Misconception 2: “Cloud Guard Responders Automatically Delete Unauthorized Resources”
  • Reality: Cloud Guard provides Detector Rules (alerts) and Responder Rules (auto-remediation actions). Responders must be explicitly configured and enabled by security administrators; Cloud Guard will not modify resources automatically without approval.
6. OCI Audit & Cloud Guard vs. Google Cloud (GCP) Audit Logs & SCC

For cloud architects familiar with Google Cloud, the following table compares security monitoring features:

Monitoring FeatureGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
API Audit LoggingGCP Cloud Audit Logs (Admin Activity & Data Access)OCI Audit Service (com.oraclecloud.iam.*)OCI Audit Service is enabled by default tenancy-wide at zero cost.
Posture ManagementGCP Security Command Center (SCC)OCI Cloud GuardBoth provide automated threat detection and posture drift alerts.
Log Export / SIEM IntegrationGCP Log Sinks to Pub/Sub or BigQueryOCI Events Service ➔ OCI Streaming / Service Connector HubBoth allow real-time streaming of IAM audit events to external SIEM tools (Splunk, Datadog).