Skip to content

Secrets Management

What is Secrets Management?

Tools and practices for securely storing, distributing, and rotating sensitive credentials such as API keys, passwords, and certificates in cloud environments.

Cloud Security

Each of these is named in at least one of the same controls as secrets management. The number is how many controls name both.

What the standards actually require on secrets management

Requirements naming secrets management across 6 standards, quoted from the control text.

Provide secrets to containers at runtime through a managed secrets system rather than environment variables or mounted files in plaintext. Rotate secrets on schedule and revoke them when a workload is decommissioned.

SP800-190-3.20 · Secrets Management at Runtime

Per OWASP DSOMM Build and Deployment + Infrastructure Hardening dimensions: secure the build + deployment + infrastructure stack. Requirements include (a) implement signed builds + artefact integrity + secure pipeline configuration + (b) operate vulnerability...

DSOMM-3 · Build, Deployment, Infrastructure Hardening, and Secrets Management

Secure runtime storage: encryption of data at rest, secrets management, volume access control and persistent-data protection.

CNCF-RT-STORAGE · Runtime Storage Security
ISMAP (Japan)1 control

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign...

NISTSP144-5 · Identity and Access in Cloud, Federation, and Privileged Access

Apply NIST SP 800-146 Chapter 6 PaaS operational recommendations to every PaaS service consumed. Coverage must include (a) application development standards aligned to PaaS-provided languages, runtimes, and libraries, (b) secure software development lifecycle...

NISTSP146-3 · PaaS Operational Recommendations and Application Portability

Questions people ask about secrets management

What is Secrets Management?
Tools and practices for securely storing, distributing, and rotating sensitive credentials such as API keys, passwords, and certificates in cloud environments.
Why is Secrets Management important for compliance?
Secrets Management is a key concept in Cloud Security. Understanding secrets management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Secrets Management?
Secrets Management appears in the requirement text of NIST SP 800-190, OWASP DevSecOps Maturity Model (DSOMM), CNCF Security Technical Advisory Group (TAG), ISMAP (Japan), NIST SP 800-144. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Secrets Management?
Explore our compliance framework pages to see how secrets management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Secrets Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.