Key Management Procedure
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define how cryptographic keys, API keys, SSH keys, certificates, and other sensitive secrets are created, stored, used, rotated, and revoked.
Key inventory
Each key/secret should have an owner, purpose, system, environment, sensitivity, creation date, rotation requirement, storage location, and revocation procedure.
Storage requirements
Secrets must be stored in approved secret-management systems, encrypted configuration stores, or restricted platform mechanisms. Secrets must not be stored in public repositories, screenshots, chat messages, tickets, or shared documents unless explicitly approved and protected.
Access control
Access to keys must follow least privilege. Shared secrets should be minimized. Administrative keys must be restricted, monitored, and removed when personnel roles change or access is no longer required.
Rotation and revocation
Keys should be rotated periodically, after suspected exposure, after personnel changes, and when systems are decommissioned. Revocation should be documented and validated.
Evidence to maintain
Key inventory, access list, rotation log, revocation record, secret-scan result, and exception approvals.