U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

CIS Oracle SaaS Cloud Applications Benchmark 1.0.0 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Oracle Cloud Infrastructure cpe:/a:oracle:cloud_infrastructure:- (View CVEs)

Checklist Highlights

Checklist Name:
CIS Oracle SaaS Cloud Applications Benchmark
Checklist ID:
1303
Version:
1.0.0
Type:
Compliance
Review Status:
Candidate
Authority:
Third Party: Center for Internet Security (CIS)
Original Publication Date:
11/14/2025

Checklist Summary:

This document, CIS (Center for Internet Security) Oracle SaaS Foundations benchmark, provides prescriptive guidance for establishing a secure baseline configuration for Oracle SaaS environments. The scope of this benchmark is to establish a base level of security for organizations utilizing the included Oracle SaaS applications. The benchmark is not an exhaustive list of all possible security configurations and architectures. The benchmark should be taken as a starting point and tailored as appropriate to meet site-specific needs. This benchmark covers Oracle Fusion and EPM SaaS Applications where explicitly highlighted, and will be extended to other Oracle SaaS applications in future releases. Additionally, Oracle SaaS applications are associated with an Oracle Cloud Infrastructure tenancy. Therefore, organizations should also leverage the Oracle Cloud Infrastructure Foundations Benchmark to establish a secure baseline configuration for their OCI tenancy running Oracle SaaS.

Checklist Role:

  • Application Server
  • Web Application Server

Known Issues:

Not provided.

Target Audience:

This document is intended for system and application administrators, security specialists, auditors, help desk staff, platform deployment teams, and DevOps personnel who plan to develop, deploy, assess, or secure solutions within Oracle SaaS environments.

Target Operational Environment:

  • Managed

Testing Information:

Not provided.

Regulatory Compliance:

Not provided.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Product Support:

https://www.cisecurity.org/support

Point of Contact:

[email protected]

Sponsor:

Not provided.

Licensing:

https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Change History:

Created New Checklist - 12/1/2025
Changed Status to Candidate - 12/09/2025

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 12/09/2025


* This checklist is still undergoing review for inclusion into the NCP.