Agentic AI-Based Security Orchestration for Oracle Cloud and Multi-Cloud Platforms
DOI:
https://doi.org/10.70917/ijcisim-2026-3759Keywords:
Agentic Artificial Intelligence (Agentic AI), Security Orchestration and Automation Response (SOAR), Oracle Cloud Infrastructure (OCI), Policy-as-Code, Multi-Cloud Security, Zero Trust, Reinforcement Learning, Adversary EmulationAbstract
Agentic AI-Based Security Orchestration for Oracle Cloud and Multi-Cloud Platforms synthesizes decision, action, and governance across heterogeneous environments, presenting evidence-based analysis and formal structure. Security-as-code is the required strategy, where security validation is integrated into the DevOps pipelines and processes. The solution revolves around the deployment of security-as-code and policy-as-code powered by security orchestration and automation response (SOAR) platforms that govern the entire setup across platform-as-a-service (PaaS) and multi-cloud environments. Agentic security orchestration automates the process of security orchestration, enforcement, and compliance checks by connecting decision and action through policy governance. Detection modules provide inputs to the decision side through security monitoring or security information and event management (SIEM) systems, which feed into the learning and adaptation module; the learning output is satisfied via dynamic policies that authorize SOAR actions. This extended version contributes a complete mathematical formulation of the orchestration loop in fifteen numbered equations, four formally specified algorithms covering triage, compliance-gated execution, reinforcement-learning playbook adaptation, and adversary-emulation validation, together with an empirical section grounded in 2025 industry telemetry. The use cases of attack simulations exploiting common vulnerabilities and exposures (CVE) for security validation through red- and blue-team approaches are also discussed. Security-as-code automates the detection and fix of misconfigurations and vulnerabilities across platform-as-a-service (PaaS) with dynamic policy governance across Oracle Cloud Infrastructure (OCI) and multi-cloud platforms. The key pillars of DevSecOps are integrated in the pipeline with a dedicated Adversary Emulation Assessment that maps security controls and automates the implementation of security automation with security-as-code, ground-up, and policy-as-code. The decision module either consumes a Red-Team simulated attack on a pre-existing vulnerability in the application or a Blue-Team hardening test for an already deployed application. The solution connects dynamic policy generation using detection feedback through the Natural Language Processing (NLP)-based Learning and Adaptation module to additional Security Orchestration Automation Response (SOAR) tasks.