Oracle Cloud · OCI Landing Zone · IAM · VCN · Terraform · Security Zones
Your OCI Environment Is Only as Good as
the Foundation It Is Built On.
Most OCI problems are not OCI problems — they are design problems. IAM policies that are too permissive, compartments that do not reflect the business, networks with no micro-segmentation, and security configurations added after the fact. A Symhas OCI landing zone fixes these at the architecture level, before the first workload is deployed. Symhas designs and deploys OCI landing zones for Oracle Fusion workloads — tenancy structure, IAM, networking, Security Zones, and Terraform IaC — so every service that runs on OCI runs on a foundation that is secure, governed, and reproducible from day one.
100%Of OCI environments built on Symhas landing zones pass security baseline validation on first assessment
TerraformEvery landing zone codified as IaC — reproducible, version-controlled, auditable
Zero-TrustSecurity Zones and Bastion Service enforce no-standing-access from day one
3wkAssessment to production OCI landing zone — fixed price
OCI certified architects available now Active
100% Security baseline pass rate on first assessment — all Symhas OCI landing zones
Terraform All landing zone resources codified as IaC — reproducible and version-controlled
3wk Assessment to production landing zone — networking, IAM, and security all live
0 Misconfigured security controls discovered post-deployment across Symhas landing zones
What We Deliver
Core Capabilities.
Production-Grade from Day One.

Every capability designed, deployed, and documented by Symhas OCI-certified architects. Fixed price. Fixed timeline. SLA-backed from go-live.

Tenancy Design & Compartment HierarchyCompartments · Policies · Quotas · Tagging · Governance
The OCI compartment hierarchy and IAM policy structure is the governance backbone of the entire tenancy. Symhas designs compartments that mirror your organisational structure — business units, environments, and workloads — with IAM policies that enforce least-privilege access from the start.
Compartment hierarchy design — business unit, environment, and workload separation
IAM policy design — least-privilege access for every group and service principal
Tag namespace and tag key design — consistent resource tagging for cost allocation and governance
Service quota planning — compute, database, and networking quota requests aligned to growth plan
Governance policy — OCI Organisation Policies blocking prohibited actions at tenancy level
Every OCI resource in the right compartment with the right access from day one — not retrofitted after a security review
VCN & Network ArchitectureVCN · Subnets · DRG · FastConnect · Security Lists · NSGs
OCI network design for Oracle Fusion workloads — hub-and-spoke VCN topology, private subnets for application and database tiers, FastConnect or site-to-site VPN for on-premises connectivity, and network security groups enforcing east-west traffic controls.
Hub-and-spoke VCN topology — transit VCN with DRG routing to workload VCNs
Subnet design — public, private application, and private database tiers per workload
Network Security Groups — application-layer traffic rules per resource, not per subnet
FastConnect — private dedicated connectivity from on-premises or co-location to OCI
OCI-Azure Interconnect — direct private link for Microsoft 365 and Azure service integration
Network architecture that prevents lateral movement — not a flat network with a perimeter firewall
Security Zones & Baseline ControlsSecurity Zones · Cloud Guard · Vault · Bastion · Policies
OCI Security Zones enforce a no-public-internet-by-default policy on every resource deployed in the zone — preventing accidental exposure of databases, storage, and compute. Cloud Guard monitors for drift and remediates automatically.
Security Zone recipe configuration — maximum security recipe for production environments
Cloud Guard — all detector rules enabled, responder recipes configured for auto-remediation
OCI Vault — customer-managed master encryption key for all data at rest
Bastion Service — just-in-time SSH and RDP access, no standing privileged sessions
OCI IAM Identity Domain — MFA enforced, session policies, and federation to Azure AD or Okta
Security controls that enforce themselves — not a policy document that relies on humans remembering
Terraform IaC & Landing Zone AutomationTerraform · OCI Resource Manager · Modules · State · CI/CD
Every landing zone component codified in Terraform — so the environment is reproducible, changes are tracked, and drift is detectable. OCI Resource Manager manages Terraform state natively without an S3 backend or external state store.
Terraform module library — compartments, networking, IAM, and security as reusable modules
OCI Resource Manager — native Terraform state management and job execution
Resource naming convention — consistent naming enforced across all Terraform resources
CI/CD pipeline — landing zone changes reviewed, planned, and applied through pipeline
Drift detection — scheduled Terraform plan to detect manual changes from IaC baseline
The landing zone is code — every change is reviewed, every deployment is consistent, every drift is detected
Delivery Model
Assessment to Production.
Four Phases. Fixed Price.

Go/no-go gates at every phase. Scope and price agreed before week one. No surprises at handover.

01
Architecture Design & Approval Week 1

Tenancy structure, compartment hierarchy, network topology, and security posture designed. Diagrams and IAM policy framework approved by client architecture and security teams before any deployment begins.

02
Terraform Build & Review Week 2

All landing zone components written as Terraform modules. Peer review by Symhas senior architect. Terraform plan reviewed with client team. No OCI resources created until plan is approved.

03
Deployment & Security Validation Early Week 3

Terraform apply executed via OCI Resource Manager. Security Zone verification. Cloud Guard baseline established. Network connectivity tested. Bastion Service verified for just-in-time access. Vault keys rotated.

04
Handover & Onboarding Late Week 3

Client infrastructure team certified on Terraform workflow and OCI Resource Manager. Runbook for adding new workloads documented. Security baseline report produced. Symhas moves to advisory for workload migration phase.

Financial Services · OCI Landing Zone $25B AUM Asset Manager.
OCI Landing Zone Live in 3 Weeks. Zero Security Findings at Audit.

A global asset management firm migrating Oracle Fusion Finance from AWS to OCI needed a production-grade OCI landing zone that could pass their internal security audit before any data was migrated. Previous cloud landing zones had failed security review and required extensive remediation.

Symhas designed and deployed an OCI landing zone in 3 weeks — compartment hierarchy matching the firm organisational structure, network topology with FastConnect private connectivity from their co-location facility, Security Zones on all production compartments, and 100% Terraform IaC. Security audit passed with zero findings on first submission.

3wk Design to production
0 Security audit findings
100% Terraform IaC coverage
FastConnect Private co-lo connectivity
Discuss Your Programme
What was delivered

OCI Landing Zone — Financial Services Production Deployment

4-level compartment hierarchy — Root, Business Unit, Environment, Workload — matching firm org structure
47 IAM policies — least-privilege access for 12 IAM groups and 8 OCI service principals
Hub-and-spoke VCN — transit VCN with DRG routing to 4 workload VCNs across prod, non-prod, and shared services
FastConnect 10Gbps — private dedicated link from co-location facility to OCI us-east region
Security Zones — maximum security recipe on all production compartments, blocking public IPs on databases and storage
Terraform — 2,847 lines of IaC across 18 modules, deployed via OCI Resource Manager with state locking

“We had failed two previous landing zone security audits on AWS and Azure. The Symhas OCI landing zone passed on first submission with no findings. The difference was that security was the design, not an afterthought.”

— CISO, Global Asset Management Firm

OCI Services Deployed
The Specific Oracle Cloud Services
We Configure for This Capability.
OCI Service
OCI Compartments & IAM

Tenancy governance — compartment hierarchy, IAM policies, dynamic groups, and tag-based access controls.

Compartment hierarchy and naming
IAM policy design and testing
Dynamic group configuration
Tag namespace and governance policy
OCI Service
OCI Virtual Cloud Network

VCN design — hub-and-spoke topology, subnet tiers, DRG routing, and network security groups.

VCN and subnet architecture
DRG and transit routing
Network Security Group rules
Internet and NAT gateway configuration
OCI Service
OCI FastConnect

Private dedicated connectivity — 1Gbps and 10Gbps FastConnect circuits from on-premises or co-location to OCI.

FastConnect partner or colocation circuit
BGP routing configuration
Redundant circuit design
On-premises CPE configuration
OCI Service
OCI Security Zones

Guardrail enforcement — Security Zone recipes blocking insecure configurations on production compartments.

Maximum security recipe configuration
Custom recipe for hybrid requirements
Zone violation alerting
Remediation workflow
OCI Service
OCI Vault

Customer-managed encryption — master encryption keys for all data at rest across compute, storage, and database.

HSM-backed master key creation
Key rotation policy
Data encryption key management
Secret storage for credentials
OCI Service
OCI Resource Manager

Terraform state management — native OCI Terraform execution, state locking, and job history.

Stack configuration from Terraform modules
State file management and locking
Job history and plan review
Drift detection schedule
Why Symhas
OCI Expertise Built from Production Deployments.
Design Approved Before a Single Resource Is Created Symhas presents a complete architecture diagram, IAM policy framework, and network topology for client approval before Terraform is written and before any OCI resource is created. Changes are cheap at design stage. They are expensive after deployment.
100% Terraform — No Click-Ops Every OCI resource created by Symhas is in Terraform. Nothing is created through the OCI console without a corresponding Terraform resource. The landing zone is reproducible, auditable, and driftable from day one.
Security Zones Applied Before Workloads Arrive Security Zones cannot be retroactively applied to compartments with existing resources that violate the recipe. Symhas applies Security Zones to production compartments before the first workload is deployed — so the guardrail is structural, not policy.
Compartment Design That Scales Generic compartment designs (prod/non-prod/shared) break down at enterprise scale. Symhas designs compartment hierarchies that reflect your actual business structure — business unit, geography, and workload — so the governance model scales as you add workloads.
Network Designed for Oracle Fusion Traffic Patterns Oracle Fusion generates specific traffic patterns between application tiers, databases, and integration services. Symhas designs OCI network topology with Oracle Fusion data flows in mind — latency, throughput, and security group rules matched to the application, not a generic 3-tier pattern.
Client Team Owns the IaC at Handover By handover your infrastructure team is trained on the Terraform module library and OCI Resource Manager workflow. Symhas certifies the team to add new workloads independently — using the same IaC patterns established in the landing zone.
Next Step
Tell Us What You Need to Run on OCI.
We Will Design the Foundation It Needs.
A 30-minute OCI architecture assessment with a Symhas cloud architect. We will review your workload requirements, security obligations, and connectivity needs — and design an OCI landing zone that supports them before we price the engagement. No commitment. No pitch deck. An honest conversation about your OCI environment.