This idea proposal recommends adopting a 6-month frequency for rotating wallets (credential stores) in Oracle Autonomous AI Lakehouse environments
This measure aims to enhance security, ensure compliance with best practices, and reduce the risk of credential compromise for all business units leveraging these environments.
**Rationale**
1. Security Enhancement: Regular wallet rotation minimizes exposure to potential unauthorized access and mitigates risks associated with credential leaks or misuse.
2. Compliance Alignment: Many industry regulations advocate for periodic credential updates to uphold data protection standards.
3. Operational Integrity: Scheduled rotation ensures that only current, authorized credentials are in use, reducing the likelihood of disruptions due to expired or compromised wallets.
**Implementation Approach**
Scope: All Oracle Autonomous AI Lakehouse environments.
Frequency: Every 6 months, with the rotation schedule coordinated by the required teams.
Process Overview:
1. Inventory and document current wallet usage for all environments.
2. Distribute updated wallets to relevant application teams and update connection configurations.
3. Validate successful integration and connectivity post-rotation.
4. Archive previous wallets securely and document the rotation cycle.
**Benefits**
Reduces risk of credential-related incidents.
Demonstrates proactive security posture to auditors and stakeholders.
Standardizes wallet management practices across business units.
**Risks & Mitigation**
Operational Disruption: Mitigated by automation and advance communication with application teams.
Resource Constraints: Addressed by integrating rotation into routine maintenance windows.