MEDIUM
Source
CloudSploit
ID
object-store-policy-protection

Object Store Policy Protection

Ensure policy statements have deletion protection for object store services unless it is an administrator group.

Adding deletion protection to Oracle object store policies mitigates unintended deletion of object store services by unauthorized users or groups.

When writing policies, avoid blanket statements, and add a where statement with the line request.permission != {OBJECT_DELETE, BUCKET_DELETE} .