Skip to main content

πŸ›‘οΈ Oracle IAM DB Credentials are not rotated every 90 days🟒

  • Contextual name: πŸ›‘οΈ DB Credentials are not rotated every 90 days🟒
  • ID: /ce/ca/oracle/iam/db-credentials-are-not-rotated-every-90-days
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Stats​

not available

Logic​

Description​

Open File

Description​

This policy identifies Oracle IAM DB Credentials that have not been rotated within 90 days. IAM database passwords allow authorized IAM users to authenticate to supported Oracle databases, such as Autonomous Database, and are separate from OCI Console passwords.

Rationale​

Long-lived IAM database passwords increase the exposure window for credential theft, accidental disclosure, and misuse. Rotating these passwords at least every 90 days limits how long a compromised password can be used and supports a predictable credential lifecycle for database access.

Impact​

Rotating an IAM database password can disrupt users, applications, or database clients that still depend on the old password. Create a replacement password, update every dependent database client, and confirm access before deleting the stale password.

Audit​

This policy flags an Oracle IAM DB Credential as INCOMPLIANT if the Time Created field is older than 90 days.

Remediation​

Open File

Remediation​

Rotate Stale IAM Database Passwords​

Create a replacement IAM database password for the affected user, update every dependent database client or access path, and delete the stale password after confirming that it is no longer required.

From OCI Console​
  1. Open Identity & Security.
  2. Select Domains.
  3. Open the affected identity domain.
  4. Open Users and select the affected user.
  5. Open Database Passwords.
  6. Create a replacement database password.
  7. Update dependent database clients and connection configurations to use the replacement password.
  8. Confirm that database authentication succeeds with the replacement password.
  9. Delete database passwords older than 90 days after confirming they are no longer used.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό CIS Oracle v3.1.0 β†’ πŸ’Ό 1.11 Ensure user IAM Database Passwords rotate within 90 days - Level 1 (Manual)1no data
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Credential Lifecycle Management36no data