Domain 13: Security Reliability

Secrets, Certificates, Vulnerability Scanning

Security Bot | Governance | Max 30 Points

0-6
Ad-hoc
7-12
Foundational
13-18
Standardized
19-24
Advanced
25-30
Optimized

Scoring Criteria by Level

LevelCriteria
1Secrets in code; manual cert management; no scanning
2Basic secrets vault; some cert automation; ad-hoc scans
3Secrets rotated; cert auto-renewal; regular scanning
4Zero-trust principles; scanning in CI; short-lived creds
5Dynamic secrets; continuous compliance; automated remediation

Assessment Questions

#QuestionMax
1How do you manage secrets?6
2How are certificates managed?6
3How do you scan for vulnerabilities?6
4How often do you rotate credentials?6
5How do you handle security incidents?6

Focus Areas

  • Secrets: Vault, rotation, no hardcoding
  • Certs: Auto-renewal, short expiry
  • Scanning: SAST, DAST, dependency scanning
  • Zero Trust: Verify explicitly, least privilege

Anti-Patterns (Red Flags)

  • Secrets in source control
  • Long-lived credentials
  • Manual certificate renewals
  • No vulnerability scanning
  • Security as afterthought

Evidence Checklist

  • Secrets vault in use (HashiCorp, AWS SM)
  • Certificates auto-renew (cert-manager)
  • Vulnerability scanning in CI/CD
  • Credential rotation policy documented
  • Security incident runbook exists

Related Domains

DomainRelationship
Release EngSecurity gates in CI/CD
DRSecure backup storage
DocumentationSecurity runbooks needed

Security as Reliability

Secure systems are reliable systems.