Secrets Management
Secrets Management centrally manages passwords, API keys, tokens and certificates securely and with traceable access.
Secrets Management is the secure administration of passwords, API keys, certificates and tokens needed by applications and systems. The goal is to prevent secrets from being exposed in code or files.
How it works
Secrets are stored in a central vault, such as Azure Key Vault, AWS Secrets Manager or HashiCorp Vault. Applications retrieve them at runtime and authenticate themselves during the process. Access is logged and restricted to only what is necessary. Many secrets can be automatically rotated at regular intervals. Managed identities are an even better solution, as no secret needs to be stored.
A practical example
A developer accidentally uploads a configuration file with a cloud key to a public repository. Automated bots find the key within minutes. They then start expensive computing resources. A repository scan would have detected the key before the upload. Following the incident, the key is revoked and replaced with a managed identity.
What to look out for
- Search repositories for secrets, including their commit history.
- Use scans before every commit and in the CI/CD pipeline.
- Issue secrets with short validity periods and rotate them automatically.
- Restrict which users and applications can access the vault.
- Monitor all access to the vault.
Why it matters
Leaked credentials are among the most common causes of cloud security incidents. Attackers specifically search for them in code repositories, container images and logs. A single discovered key can grant access to an entire environment.
Switzerland and regulation
ISO 27001 requires the secure handling of authentication information and keys. For financial institutions, FINMA (Swiss Financial Market Supervisory Authority) expects the protection of critical credentials. There are no specific technical requirements.
Typical mistakes
Frequently, a leaked secret is removed from the code but not revoked. It remains visible in the repository's history. Another mistake is creating secrets without an expiry date. These secrets can remain valid for years.
How we implement it
We monitor access to your secret vaults and detect key usage from unusual sources. We are happy to discuss architecture questions as part of our Security Consulting.