{"id":1246,"date":"2026-09-14T11:40:22","date_gmt":"2026-09-14T11:40:22","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1246"},"modified":"2026-09-14T11:40:22","modified_gmt":"2026-09-14T11:40:22","slug":"secrets-management","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/secrets-management\/","title":{"rendered":"Secrets Management"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SECRETS MANAGEMENT\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A leaked secret is not a bug you fix. It is a working credential somebody else now holds, and deleting the line of code changes nothing.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Secrets management is how an organisation creates, stores, distributes, rotates and revokes the credentials that systems use to authenticate to each other. API keys, database passwords, private keys and tokens all qualify. The discipline exists because these values are needed by running code, which makes storing them safely genuinely awkward, and because a single exposed one is frequently the whole breach.<\/p>\n<\/div>\n\n<p>Most secrets management ends after the first two stages, and the risk concentrates in the three that follow.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What secrets management covers<\/a><\/li>\n    <li><a href=\"#leak\">Where secrets leak<\/a><\/li>\n    <li><a href=\"#lifecycle\">The five secrets management stages<\/a><\/li>\n    <li><a href=\"#rotate\">Rotate, do not delete<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What secrets management covers<\/h2>\n\n<p>Secrets management covers more than the values a developer would name if asked.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Type<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>API keys and tokens<\/td><td>Often long lived and broadly scoped, so one key can reach far more of a third-party service than the feature that needed it<\/td><\/tr>\n    <tr><td>Database credentials<\/td><td>Direct access to production data, usually bypassing every application-layer control you built<\/td><\/tr>\n    <tr><td>Cloud access keys<\/td><td>The highest-value target. A key with broad permissions is equivalent to an administrator account<\/td><\/tr>\n    <tr><td>Private keys and certificates<\/td><td>Allow an attacker to impersonate your service or decrypt intercepted traffic<\/td><\/tr>\n    <tr><td>Encryption keys<\/td><td>Storing the key beside the encrypted data makes the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption<\/a> decorative<\/td><\/tr>\n    <tr><td>Webhook and connection URLs<\/td><td>Frequently overlooked because they look like configuration rather than credentials, while carrying an embedded token<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"leak\" class=\"c-sage\">Where secrets leak<\/h2>\n\n<p>Secrets management fails at the edges rather than in the obvious places.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Location<\/th><th>How it happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Source code<\/td><td>Hard-coded during development and never removed. Public repositories are scanned continuously by automated tooling<\/td><\/tr>\n    <tr><td>Commit history<\/td><td>Removed from the current file but still present in an earlier commit, which most people believe counts as deleted<\/td><\/tr>\n    <tr><td>Container images<\/td><td>Baked in at build time and readable by anyone who can pull the image, including from earlier layers<\/td><\/tr>\n    <tr><td>Pipeline configuration<\/td><td>Sitting in build files or printed by a verbose step into logs that are retained and widely readable<\/td><\/tr>\n    <tr><td>Application logs and errors<\/td><td>A connection string in a stack trace, forwarded to a monitoring service and stored for months<\/td><\/tr>\n    <tr><td>Chat and tickets<\/td><td>Pasted into a message or attached to a ticket during troubleshooting, then indexed and searchable forever<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The last three surprise people. A team can enforce clean repositories and still leak credentials daily through a logging pipeline or a support thread.<\/p>\n\n<h2 id=\"lifecycle\" class=\"c-plum\">The five secrets management stages<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Five stages of secrets management: create, store, distribute, rotate and revoke, with rotation highlighted as the stage most teams skip.\">\n  <defs><marker id=\"sm\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"24\" width=\"132\" height=\"58\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"80\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Create<\/text>\n  <text x=\"80\" y=\"67\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#0f1538\">Scoped narrowly<\/text>\n  <line x1=\"150\" y1=\"53\" x2=\"168\" y2=\"53\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#sm)\"\/>\n\n  <rect x=\"174\" y=\"24\" width=\"132\" height=\"58\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"240\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Store<\/text>\n  <text x=\"240\" y=\"67\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#0f1538\">Encrypted, central<\/text>\n  <line x1=\"310\" y1=\"53\" x2=\"328\" y2=\"53\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#sm)\"\/>\n\n  <rect x=\"334\" y=\"24\" width=\"132\" height=\"58\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"400\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Distribute<\/text>\n  <text x=\"400\" y=\"67\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#0f1538\">At run time only<\/text>\n  <line x1=\"470\" y1=\"53\" x2=\"488\" y2=\"53\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#sm)\"\/>\n\n  <rect x=\"494\" y=\"24\" width=\"122\" height=\"58\" rx=\"12\" fill=\"#efe4f0\" stroke=\"#6b4576\" stroke-width=\"2\"\/>\n  <text x=\"555\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Rotate<\/text>\n  <text x=\"555\" y=\"67\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#6b4576\">On a schedule<\/text>\n  <line x1=\"620\" y1=\"53\" x2=\"638\" y2=\"53\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#sm)\"\/>\n\n  <rect x=\"644\" y=\"24\" width=\"102\" height=\"58\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"695\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Revoke<\/text>\n  <text x=\"695\" y=\"67\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"9.5\" fill=\"#0f1538\">When done<\/text>\n\n  <rect x=\"14\" y=\"98\" width=\"732\" height=\"60\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Rotation is the stage almost everyone skips.<\/text>\n  <text x=\"380\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">It is the only stage that limits how long an undetected leak stays useful to whoever found it.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Stage<\/th><th>What good looks like<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Create<\/td><td>Scoped to the narrowest permission the task needs, and issued per service rather than shared across several<\/td><\/tr>\n    <tr><td>Store<\/td><td>In a dedicated encrypted store with access control and an audit trail, not in environment files copied between laptops<\/td><\/tr>\n    <tr><td>Distribute<\/td><td>Injected at run time from that store, so the value never enters the repository, the image or the pipeline configuration<\/td><\/tr>\n    <tr><td>Rotate<\/td><td>Automatically and on a schedule, which caps the useful life of anything that leaked without your knowledge<\/td><\/tr>\n    <tr><td>Revoke<\/td><td>Immediately when a service is decommissioned or a person leaves, with someone able to confirm it actually happened<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Short-lived credentials beat careful storage<\/p>\n  <p>The strongest version of secrets management is needing less secrets management. Credentials generated on demand and valid for minutes are worth far less to an attacker than a key issued at launch and still valid two years later, because the window to use them barely exists. Where a cloud provider or platform can issue temporary credentials to a workload directly, that removes the secret from the equation rather than protecting it, which is a better outcome than any vault provides.<\/p>\n<\/div>\n\n<h2 id=\"rotate\" class=\"c-sky\">Rotate, do not delete<\/h2>\n\n<p>This is the secrets management rule that saves the most damage, and the one most often got wrong under pressure.<\/p>\n\n<p>When a secret is found somewhere it should not be, the instinct is to remove it and commit the fix. That resolves nothing. The credential still works, and the exposed copy persists in places you do not control.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Where the old value survives<\/th><th>Why removal does not reach it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Commit history<\/td><td>Every earlier commit still contains it, and rewriting history does not affect clones anyone already made<\/td><\/tr>\n    <tr><td>Forks and mirrors<\/td><td>Copies exist outside your account entirely, and you cannot edit them<\/td><\/tr>\n    <tr><td>Caches and archives<\/td><td>Search engines, code indexes and archive services may hold a snapshot taken before the fix<\/td><\/tr>\n    <tr><td>Build artefacts<\/td><td>Images and packages already published still carry the original value inside them<\/td><\/tr>\n    <tr><td>Automated collection<\/td><td>Public repositories are scanned continuously. A key pushed publicly should be treated as captured within minutes<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The correct sequence is to rotate first so the exposed value stops working, then check logs for any use of it, then clean up the code. Treat the old credential as compromised regardless of how briefly it was visible.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto does not sell a secrets vault, and a dedicated store is the right tool for that part of secrets management. What the platform addresses is the two things that decide whether a leaked secret becomes an incident: how much it can reach, and how quickly its use is noticed.<\/p>\n\n<p>Scope is handled through identity. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Identity and access management<\/a> keeps service permissions narrow so a captured key reaches one function rather than an account, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">privileged access management<\/a> governs the credentials worth the most, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">zero trust access<\/a> means a stolen credential alone does not reach infrastructure that requires a managed device. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> flags over-permissioned roles and keys that were never scoped down after launch.<\/p>\n\n<p>Detection is the second half. Because identity, cloud and application events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a>, a credential suddenly used from an unfamiliar location or calling operations it has never called reads as a pattern rather than a normal authenticated request. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> also surfaces exposed credentials in applications and infrastructure during testing. Together with documented rotation, that satisfies what <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> expect around credential handling, and PCI is explicit about it.<\/p>\n\n<p>The practical read for a small team is that secrets management is worth doing properly at the storage layer, and worth assuming will fail anyway. Both halves are cheaper than the incident.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Shrink what a leaked key can reach<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Narrow identity scope, zero trust access to infrastructure, cloud posture on over-permissioned roles, and credential misuse visible in one SIEM.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is secrets management?<\/summary>\n  <p>The practice of creating, storing, distributing, rotating and revoking the credentials that systems use to authenticate to each other, including API keys, database passwords, tokens and private keys.<\/p>\n<\/details>\n\n<details>\n  <summary>What should you do when a secret is committed to a repository?<\/summary>\n  <p>Rotate it first so the exposed value stops working, then review logs for any use of it, then clean the code. Deleting the line does not help, because the value remains in history, in forks and in anything already cloned.<\/p>\n<\/details>\n\n<details>\n  <summary>Is secrets management just environment variables?<\/summary>\n  <p>Environment variables are better than hard-coding, and not sufficient on their own. Environment files get copied between machines, committed by accident and printed into logs by verbose error handling. They also provide no audit trail and no rotation.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should secrets be rotated?<\/summary>\n  <p>Frequently enough that an undetected leak expires before it is useful, and automatically, because manual rotation stops happening within a few months. The stronger approach is short-lived credentials issued on demand, which reduces the number of standing secrets to rotate at all.<\/p>\n<\/details>\n\n<details>\n  <summary>Is secrets management required for compliance?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> is explicit about credential handling and rotation. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> address it through access control and key management expectations rather than naming a tool.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/application-security\/\">Application Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cloud-security\/\">Cloud Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">PAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A leaked secret is not a bug you fix. It is a working credential somebody else now holds, and deleting\u2026<\/p>\n","protected":false},"author":8,"featured_media":1247,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[642],"class_list":["post-1246","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-secrets-management"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1246"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1246\/revisions"}],"predecessor-version":[{"id":1248,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1246\/revisions\/1248"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1247"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}