Ensure that resource tags are used to organize Oracle Cloud Infrastructure (OCI) KMS Vaults, helping to distinguish between different environment stages (e.g., Development, Staging, and Production). In OCI, resource tags are simple key-value pairs that can be assigned to cloud resources to simplify organization, management, and tracking. TrendAI Vision One™ Cloud Risk Management recommends defining environment identification tags using the following tag keys: "Environment", "Env", or "Stage".
excellence
As your Oracle Cloud Infrastructure (OCI) environment becomes increasingly complex, it requires more effective management strategies. Using resource tags for environment identification on OCI KMS Vaults is important because it enables clear organization and isolation (e.g., separating Development, Staging, and Production), simplifies cost allocation and reporting, streamlines automation for environment-specific operations, and ensures proper access control and governance over sensitive encryption keys.
Audit
To determine if your OCI KMS Vaults are using environment identification tags, perform the following operations:
Remediation / Resolution
To implement environment identification tags for your Oracle Cloud Infrastructure (OCI) KMS Vaults, perform the following operations:
References
- Oracle Cloud Infrastructure Documentation
- Resource Tags
- Overview of Tagging
- Overview of Vaults, Key Management, and Secret Management
- Getting a Vault's Details
- Oracle Cloud Infrastructure CLI Documentation
- compartment list
- vault list
- vault get
- vault update