OSPS-BR-07 Secure Secrets and Credentials (maturity level 3). Requirement: The project MUST define a policy for managing secrets and credentials used by the project. The policy should include guidelines for storing, accessing, and rotating secrets and credentials. Objective of the control: Ensure that data which can lead to security vulnerabilities or supply chain compromise is not disclosed, compromised, or misused. Recommendation: Document how secrets and credentials are managed and used within the project. This should include details on how secrets are stored (e.g., using a secrets management tool), how access is controlled, and how secrets are rotated or updated. Ensure that sensitive information is not hard-coded in the source code or stored in version control systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.