14. A secret where a label belongs
A value matching a recognised secret pattern (a password, a key or a token) was in the list. It was not read: it was replaced with "Secret removed" and the line number before anything was shown, and it reaches no export and no saved register. The list itself is somewhere a secret should not be.
The rule it applies
A cell matches a recognised secret pattern: a cloud access key, a private key block, a password, secret or token pair written with an equals sign, or a long run of hexadecimal or mixed-case base64 characters. The cell is replaced before anything renders.
A question for the account owner
Where else has this list been sent, and should that credential now be changed?
Clauses
2 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.17 Authentication information | every account type |
| NIST SP 800-53 | NIST SP 800-53 IA-5 Authenticator Management | every account type |
The first clause, set out
ISO/IEC 27001 A.5.17Authentication informationA management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.