---
格式版本: 2
标题: "OCI Block Storage Adds Ransomware-Resilient Backup Protection | cloud-infrastructure"
原文链接: "https://blogs.oracle.com/cloud-infrastructure/oci-block-storage-adds-ransomware-backup"
发布日期: "2026-08-11"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "August 11, 2026 3 minute read"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 5
发布时间严格候选数量: 1
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-12T21:46:59+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-12T21:43:00+08:00"
入库时间: "2026-08-12T13:46:59.285Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://blogs.oracle.com/?page=news"
匹配关键词:
  []
相关厂家:
  - "Oracle"
相关专家:
  []
内容类型: "网页"
抓取工具: "CDP Render"
清洗工具: "CDP Text + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 35
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为OCI块存储备份保护功能，与超节点/AI Rack/机柜级AI基础设施完全无关，仅来源权威性和正文完整度得分。"
AI质检模型: "tx-deepseek-v4-flash"
AI质检时间: "2026-08-12T21:47:56+08:00"
AI主题相关性: 0
AI来源权威性: 15
AI新颖性: 5
AI技术细节: 5
AI商业部署信号: 0
AI完整性: 10
采集批次: "2026年8月12日20点58分23秒"
采集批次ID: "20260812-205823-234"
去重键: "https://blogs.oracle.com/cloud-infrastructure/oci-block-storage-adds-ransomware-backup"
---

OCI Block Storage now supports immutable backups, helping protect backups from premature deletion and retention-period changes for the duration of the retention policy. These capabilities can help organizations strengthen ransomware resilience and support compliance efforts.

Cyberattacks are a critical business risk that can disrupt operations, compromise sensitive data, erode customer trust, and create legal or financial consequences. Protecting recovery data is just as important as protecting production workloads, especially during security incidents, accidental deletion, regulatory inquiries, and other situations where backups must remain securely preserved.

![screenshot of block volume backup in OCI console](https://blogs.oracle.com/cloud-infrastructure/wp-content/uploads/sites/83/2026/08/image-11.png)

“Create block volume backup” in the OCI Console. Similar updates available for Boot Volume backups and Volume Group backups.

## At a glance:

OCI Block Storage now offers flexible backup protection options that support operational recovery, governance, and regulatory compliance. Whether you need long-term retention, protection against accidental deletion, immutable backups, or indefinite preservation for legal matters, you can choose the protection level that best fits your requirements.

- **Endurance:** Long-term backup retention from one day to 200 years.
- **Governance:** Delete prevention with administrative flexibility.
- **Compliance:** Retention Lock with enforceable backup immutability.
- **Legal Hold:** Indefinite retention of backups for investigations and litigation.

## Endurance: long-term retention

Long-term retention lets you preserve backups for a defined period ranging from one day to 200 years. You can configure the retention period and update the backup’s encryption key while preserving data until the configured expiration date. This flexibility helps organizations align backup retention with operational requirements.

Use long-term retention when a backup must remain available for an extended but known period and administrative flexibility is still required.

## Governance: delete prevention

Delete prevention helps protect backups from accidental or intentional manual deletion while allowing authorized administrators with the appropriate IAM permissions to enable or disable the protection when operationally necessary.

While enabled, delete prevention prevents manual deletion until the retention period expires, helping reduce the risk of data loss from human error or malicious activity. If a backup has a defined retention period, it remains protected from manual deletion but is automatically deleted when that period expires. Delete prevention does not stop scheduled expiration.

## Compliance: Retention Lock

Retention Lock provides immutable backup protection for organizations with strict retention, governance, or regulatory requirements. Once enabled, Retention Lock cannot be disabled, the backup cannot be deleted before the retention period expires, and its encryption key cannot be changed. The retention period can be extended but not shortened.

For example, a backup locked for 90 days cannot later be changed to 30 days to make it eligible for earlier deletion, but the retention period can be extended beyond 90 days.

Use Retention Lock for backup immutability, compliance efforts, audits, or business continuity requirements. Important: enabling Retention Lock is **irreversible**. Validate the retention period and encryption-key strategy before enabling it.

## Legal hold: indefinite protection

Indefinite hold preserves an existing backup until an authorized user removes the hold. It overrides any existing retention period and prevents the backup from being deleted or updated, making it appropriate for litigation, security investigations, regulatory inquiries, audits, and other situations without a known end date.

## Get started

Open Block Storage in the OCI Console and go to Block Volume Backups or Boot Volume Backups. Select the backup you want to protect, then configure the retention and protection settings that match your recovery, governance, or compliance needs. You can also manage these capabilities using the OCI command line interface (CLI), API, or software development kits (SDKs).
