CIS Oracle SaaS Cloud Applications Benchmark 1.0.0 Checklist Details (Checklist Revisions)
Supporting Resources:
-
Download Prose - CIS Oracle SaaS Cloud Applications Benchmark v1.0.0
- Center for Internet Security (CIS)
Target:
| Target | CPE Name |
|---|---|
| Oracle Cloud Infrastructure | cpe:/a:oracle:cloud_infrastructure:- (View CVEs) |
Checklist Highlights
- Checklist Name:
- CIS Oracle SaaS Cloud Applications Benchmark
- Checklist ID:
- 1303
- Version:
- 1.0.0
- Type:
- Compliance
- Review Status:
- Candidate
- Authority:
- Third Party: Center for Internet Security (CIS)
- Original Publication Date:
- 11/14/2025
Checklist Summary:
This document, CIS (Center for Internet Security) Oracle SaaS Foundations benchmark, provides prescriptive guidance for establishing a secure baseline configuration for Oracle SaaS environments. The scope of this benchmark is to establish a base level of security for organizations utilizing the included Oracle SaaS applications. The benchmark is not an exhaustive list of all possible security configurations and architectures. The benchmark should be taken as a starting point and tailored as appropriate to meet site-specific needs. This benchmark covers Oracle Fusion and EPM SaaS Applications where explicitly highlighted, and will be extended to other Oracle SaaS applications in future releases. Additionally, Oracle SaaS applications are associated with an Oracle Cloud Infrastructure tenancy. Therefore, organizations should also leverage the Oracle Cloud Infrastructure Foundations Benchmark to establish a secure baseline configuration for their OCI tenancy running Oracle SaaS.
Checklist Role:
- Application Server
- Web Application Server
Known Issues:
Not provided.
Target Audience:
This document is intended for system and application administrators, security specialists, auditors, help desk staff, platform deployment teams, and DevOps personnel who plan to develop, deploy, assess, or secure solutions within Oracle SaaS environments.
Target Operational Environment:
- Managed
Testing Information:
Not provided.
Regulatory Compliance:
Not provided.
Comments/Warnings/Miscellaneous:
Not provided.
Disclaimer:
https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/
Product Support:
https://www.cisecurity.org/support
Point of Contact:
Sponsor:
Not provided.
Licensing:
https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/
Change History:
Created New Checklist - 12/1/2025 Changed Status to Candidate - 12/09/2025
Dependency/Requirements:
| URL | Description |
|---|
References:
| Reference URL | Description |
|---|
NIST checklist record last modified on 12/09/2025
* This checklist is still undergoing review for inclusion into the NCP.
