Secret management covers practices and patterns for securely storing, distributing and rotating credentials, keys and certificates in distributed systems. It frames architectural, operational and governance concerns including centralization, access controls and automation. The aim is to reduce leaks, support compliance and ensure reliable handling of secrets…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Secret management protects credentials and keys across their lifecycle, from generation and storage through rotation, use, and revocation.
The practice arose from recognising that passwords, API keys, certificates, and tokens in distributed systems need dedicated protection and operating processes. OWASP’s guidance covers secure storage, access control, rotation, and monitoring.
Treat a secret as a revocable key, not a configuration constant. Generate it with suitable randomness, store it in a dedicated vault, grant access only to the required service, and keep it out of code, logs, and error messages. Plan rotation and revocation before an incident; record access without exposing the secret value itself.
Secrets belong in a protected secret store with encryption and controlled access, not source code or unprotected configuration.
Least privilege, short lifetimes, and separate identities limit who may use a secret and when.
Generation, distribution, rotation, revocation, and disposal are operated as one process.
Secret management reduces account takeover and excessive-access risk in software and operations. A vault alone is insufficient; identity management, rotation, monitoring, and incident procedures must work together.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.