Fortova lockupFortovaORACLE CLOUD SECURITY

Engagements · Shape 01

The architecture review.

The entry point for every Fortova engagement. In two to three weeks we produce the picture of your Oracle estate as it actually runs, measure it against the CIS OCI Foundations Benchmark, and hand you a numbered findings register and a roadmap. Fixed scope. Every artifact is yours to keep whether or not anything follows.

What you receive

Five artifacts, one register.

01

Current-state tenancy diagram

Compartments, networking, identity domains and integration topology, drawn from what is running rather than what the code intended. The anchor diagram of every later document.

02

CIS benchmark baseline report

The CIS OCI Foundations Benchmark run by your administrator, read-only, from the published source, with a run guide and a pairing session from us. The "before" that later work is measured against.

03

Cloud Guard posture

Cloud Guard enabled (or reviewed, if already on), high-level problems triaged, and the resolution path for each written down.

04

Identity and integration inventory

A first inventory of identity domains, federation, privileged accounts, and every OIC, VBCS and API connection with its authentication method.

05

Findings register and roadmap

Findings numbered from F-01, each with severity, evidence and a recommended fix, sequenced into a roadmap your team can run or we can deliver as the full assessment.

A working session

Findings and roadmap walked through with your sponsor and the people who will own each item. Decisions get sessions, not email chains.

How it runs

Three weeks, in order.

The review is phases 0 to 2 of the full method, run to the same standard as a complete engagement.

  1. Week 1

    Intake and seeding

    Documentation review from the outside. The tenancy diagram is pre-built from your intended design with every area marked to verify. Access is read-only and yours to grant; benchmark tooling is run by your administrator with our run guide.

  2. Week 2

    Capture and baseline

    Verification turns the seeded diagram into the current state; drift between intent and reality becomes the first findings. The CIS benchmark report is produced and Cloud Guard is enabled or reviewed.

  3. Week 3

    Register, roadmap, session

    Findings are written up with evidence and sequenced. The roadmap is circulated early in the week and decided in a working session with owners assigned.

What we need from you

Very little, and nothing elevated.

  • A sponsor and a technical contact who can grant read-only access to the tenancy and Fusion security console.
  • Whatever architecture and security documentation exists, in whatever state it is in.
  • An administrator willing to run the benchmark script from the published source, with us on the call.
  • Ninety minutes for the closing working session.

Questions we are asked

Before the review.

Do we have to continue after the review?

No. The artifacts are complete in themselves and are written so your team can act on them. Many clients do continue into the full assessment; the register makes that scope precise.

Is this a penetration test?

No. It is an architecture and configuration review against the CIS benchmark and Oracle's published patterns. It tells you whether the estate is built to the plan, and where it is not.

Can it run on a Fusion-only estate?

Yes. The Fusion identity and role review, integration inventory and monitoring design apply without OCI workloads. The tenancy diagram becomes an identity and integration diagram.

Who does the work?

A principal. The person on the first call is the person who produces the register and presents it.

Start with an architecture review.

Tell us what runs in the estate and when you need the picture. A principal replies directly.