8. Credential stored in code, a config file or a script
A credential written into code, a config file, a script or a document is known to everyone who can read that file, and it does not change when people leave.
The rule it applies
The stored-in column reads code, a config file, a script, or a document (a spreadsheet, a wiki, an email or a chat).
A question for the account owner
Can this credential move into a vault, and who has read the file it sits in?
Clauses
3 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.17 Authentication information | every account type |
| NIST SP 800-53 | NIST SP 800-53 IA-5(7) Authenticators: No Embedded Unencrypted Static Authenticators | every account type |
| PCI DSS | PCI DSS 8.6.2 No hard-coded passwords for interactive system accounts | application and system accounts only |
The first clause, set out
ISO/IEC 27001 A.5.17Authentication informationA management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.