OpenSSF Open Source Project Security Baseline (OSPS Baseline)
BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

OpenSSF Open Source Project Security Baseline (OSPS Baseline) OSPS-BR-07.02: OSPS-BR-07.02 Secure Secrets and Credentials

OSPS-BR-07 Secure Secrets and Credentials (maturity level 3). Requirement: The project MUST define a policy for managing secrets and credentials used by the project. The policy should include guidelines for storing, accessing, and rotating secrets and credentials. Objective of the control: Ensure that data which can lead to security vulnerabilities or supply chain compromise is not disclosed, compromised, or misused. Recommendation: Document how secrets and credentials are managed and used within the project. This should include details on how secrets are stored (e.g., using a secrets management tool), how access is controlled, and how secrets are rotated or updated. Ensure that sensitive information is not hard-coded in the source code or stored in version control systems.

Maintained by Gerard Blokdyk

Other controls in BR: Build and Release – OpenSSF Open Source Project Security Baseline (OSPS Baseline)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.