π‘οΈ Oracle IAM DB Credentials are not rotated every 90 daysπ’
- Contextual name: π‘οΈ DB Credentials are not rotated every 90 daysπ’
- ID:
/ce/ca/oracle/iam/db-credentials-are-not-rotated-every-90-days - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Statsβ
not available
Logicβ
- π§ prod.logic.yamlπ’
Descriptionβ
Descriptionβ
This policy identifies Oracle IAM DB Credentials that have not been rotated within 90 days. IAM database passwords allow authorized IAM users to authenticate to supported Oracle databases, such as Autonomous Database, and are separate from OCI Console passwords.
Rationaleβ
Long-lived IAM database passwords increase the exposure window for credential theft, accidental disclosure, and misuse. Rotating these passwords at least every 90 days limits how long a compromised password can be used and supports a predictable credential lifecycle for database access.
Impactβ
Rotating an IAM database password can disrupt users, applications, or database clients that still depend on the old password. Create a replacement password, update every dependent database client, and confirm access before deleting the stale password.
Auditβ
This policy flags an Oracle IAM DB Credential as
INCOMPLIANTif theTime Createdfield is older than 90 days.
Remediationβ
Remediationβ
Rotate Stale IAM Database Passwordsβ
Create a replacement IAM database password for the affected user, update every dependent database client or access path, and delete the stale password after confirming that it is no longer required.
From OCI Consoleβ
- Open Identity & Security.
- Select Domains.
- Open the affected identity domain.
- Open Users and select the affected user.
- Open Database Passwords.
- Create a replacement database password.
- Update dependent database clients and connection configurations to use the replacement password.
- Confirm that database authentication succeeds with the replacement password.
- Delete database passwords older than 90 days after confirming they are no longer used.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Oracle v3.1.0 β πΌ 1.11 Ensure user IAM Database Passwords rotate within 90 days - Level 1 (Manual) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Credential Lifecycle Management | 36 | no data |