MEDIUM
Source
CloudSploit
ID
instance-policy-protection

Instance Policy Protection

Ensures policy statements have deletion protection for compute instances unless it is an administrator group.

Adding deletion protection to Oracle compute instance policies mitigates unintended deletion of instances by unauthorized users or groups.

When writing policies, avoid blanket statements, and add a where statement with the line request.permission != INSTANCE_DELETE.