Tutorials/Key Management Procedure

Key Management Procedure

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

Define how cryptographic keys, API keys, SSH keys, certificates, and other sensitive secrets are created, stored, used, rotated, and revoked.

Key inventory

Each key/secret should have an owner, purpose, system, environment, sensitivity, creation date, rotation requirement, storage location, and revocation procedure.

Storage requirements

Secrets must be stored in approved secret-management systems, encrypted configuration stores, or restricted platform mechanisms. Secrets must not be stored in public repositories, screenshots, chat messages, tickets, or shared documents unless explicitly approved and protected.

Access control

Access to keys must follow least privilege. Shared secrets should be minimized. Administrative keys must be restricted, monitored, and removed when personnel roles change or access is no longer required.

Rotation and revocation

Keys should be rotated periodically, after suspected exposure, after personnel changes, and when systems are decommissioned. Revocation should be documented and validated.

Evidence to maintain

Key inventory, access list, rotation log, revocation record, secret-scan result, and exception approvals.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.