Ensure that your OCI KMS Customer-Managed Keys (also known as Master Encryption Keys) are rotated within a period of 365 days in order to follow best practices and meet security and compliance requirements. A Customer-Managed Key (CMK) is an encryption key that you control, used to protect your data in Oracle Cloud Infrastructure (OCI). The key rotation represents the time interval between two consecutive key versions generated by the Key Management Service (KMS) or imported by the customer.
OCI KMS Customer-Managed Keys (CMKs) are powerful encryption credentials that can introduce severe security risks if they are not managed correctly. Because the KMS key management within Oracle Cloud Infrastructure (OCI) represents the user's responsibility, enforcing an optimal key rotation period would significantly reduce the chance that a compromised key could be used without your knowledge to access encrypted data.
Audit
To check the last rotation of your OCI KMS Customer-Managed Keys (CMKs), perform the following operations:
Remediation / Resolution
To ensure that your OCI KMS Customer-Managed Keys (CMKs) are regularly rotated (every 365 days or less), perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Key Management FAQ
- Managing Keys
- Rotating a Key
- Oracle Cloud Infrastructure CLI Documentation
- compartment list
- vault list
- vault get
- key list
- key get
- key-version create