---
title: KMS master encryption keys should be rotated at least annually
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > KMS master encryption keys should be
  rotated at least annually
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# KMS master encryption keys should be rotated at least annually
 
## Description{% #description %}

Oracle Cloud Infrastructure KMS master encryption keys should be rotated at least annually. Evaluate rotation against the creation time of the newest enabled cryptographic key version, not the logical key container's created timestamp, because the container timestamp does not update when the underlying key material is rotated. The rule skips disabled or transitional logical keys until they become enabled and fails when rotation cannot be established for an enabled key.

## Remediation{% #remediation %}

See [Rotating a Key](https://docs.oracle.com/iaas/Content/KeyManagement/Tasks/managingkeys_topic-To_rotate_a_master_encryption_key.htm) for Oracle's Console, CLI, and API procedures.
