Control: 4.3 Ensure a notification is configured for Identity Provider changes
Description
It is recommended to setup an Event Rule and Notification that gets triggered when Identity Providers are created, updated or deleted. Event Rules are compartment scoped and will detect events in child compartments. It is recommended to create the Event rule at the root compartment level.
OCI Identity Providers allow management of User ID / passwords in external systems and use of those credentials to access OCI resources. Identity Providers allow users to single sign-on to OCI console and have other OCI credentials like API Keys. Monitoring and alerting on changes to Identity Providers will help in identifying changes to the security posture.
Remediation
From Console
- Go to the Events Service page.
- Select the
compartment
that should host the rule. - Click
Create Rule
. - Provide a
Display Name
andDescription
. - Create a
Rule Condition
by selectingIdentity
in the Service Name Drop-down and selectingIdentity Provider – Create
,Identity Provider - Delete
andIdentity Provider – Update
. - In the
Actions
section selectNotifications
as Action Type. - Select the
Compartment
that hosts theTopic
to be used. - Select the
Topic
to be used. - Optionally add Tags to the Rule.
- Click
Create Rule
.
From CLI
- Find the
topic-id
of the Event Rule which should be used for sending Notifications by using the topicname
andCompartment OCID
oci ons topic list --compartment-id=<compartment OCID> --all --query "data [?name=='<topic_name>']".{"name:name,topic_id:\"topic-id\""} --output table
- Create a JSON file to be used when creating the Event Rule. Replace topic id, display name, description and compartment OCID.
{ "actions": { "actions": [ { "actionType": "ONS", "isEnabled": true, "topicId": "<topic id>" }] }, "condition": { "eventType": ["com.oraclecloud.identitycontrolplane.createidentityprovider", "com.oraclecloud.identitycontrolplane.deleteidentityprovider", "com.oraclecloud.identitycontrolplane.updateidentityprovider"], "data":{} }, "displayName": "<display name>", "description": "<description>", "isEnabled": true, "compartmentId": "compartment OCID"}
- Create the actual event rule
oci events rule create --from-json file://event_rule.json
- Note in the JSON returned that it lists the parameters specified in the JSON file provided and that there is an OCID provided for the Event Rule.
Usage
Run the control in your terminal:
powerpipe control run oci_compliance.control.cis_v200_4_3
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run oci_compliance.control.cis_v200_4_3 --share
SQL
This control uses a named query:
events_rule_notification_identity_provider_changes