Oracle EPM Cloud Service Accounts, epmautomate, and Auditor Concerns Around Password Rotation
We have a couple of non-user/service accounts in our Oracle EPM Cloud applications that are used for:
- Running scheduled jobs through epmautomate
- Running EPM Agent services for integrations and data loads
These accounts currently have administrative roles because of the privileges required to execute the automated processes.
Our external auditors have raised concerns that these service accounts represent a security risk because their passwords are not rotated as frequently as normal user accounts. The challenge is that changing these passwords requires operational effort, such as:
- Updating EPM Agent configuration files
- Recreating encrypted credential files referenced by epmautomate commands
- Testing and revalidating existing production automations
Tagged:
0