Skip to main content
    DevOps
    Way of Working
    1. Home
    2. Capabilities
    3. Code Secrets Rotation

    Secrets Rotation Enforcement

    Acceleration
    Phase: code
    CFR
    LT

    Quick Reference

    Phase
    code
    Epic
    Secure Code & Advanced Review
    Milestone
    Acceleration
    Target
    >= 90% secrets rotated within 90 days
    Implementation Time
    Part of Secure Code & Advanced Review epic: 4 weeks (30 hours per capability avg)

    What & Why

    Definition

    >= 90% of secrets (API keys, tokens) auto-rotated every 90 days with expiration monitoring and alerts.

    Business Value

    Detects security vulnerabilities 10x earlier (development vs production) and reduces critical security findings by 80% through shift-left security scanning Achieving >= 90% secrets rotated within 90 days is a key milestone toward this goal.

    Context

    This capability is part of the Acceleration milestone's focus on scale automation, embed compliance, improve speed & reliability. Essential for teams targeting CFR, LT improvements.

    Success Criteria

    Target

    >= 90% secrets rotated within 90 days

    Measurement

    Secret age tracking from secret manager

    Evidence

    • Secret rotation policy
    • Rotation logs
    • Expiration alerts

    In Practice

    Real-World Implementation

    Teams store secrets in AWS Secrets Manager/Vault with 90-day rotation policy. Alerts trigger 14 days before expiration.

    Concrete Example

    API key 'payment-gateway-prod' created Oct 1. Rotation policy triggers alert Dec 17 (14d before 90d). Engineer rotates Dec 20. New key active.

    Implementation Guide

    Prerequisites

    Secrets Detection
    >= 95% commits scanned for secrets

    Implementation Steps

    Follow the measurement approach: Secret age tracking from secret manager

    For detailed step-by-step guidance, refer to the Secure Code & Advanced Review Implementation Kit.

    Resources

    Implementation Kit

    Secure Code & Advanced Review Kit

    Templates

    Browse all templates

    Related Resources

    View learning paths

    Related Capabilities

    Prerequisites

    Implement these first

    Secrets Detection

    Complementary

    Often adopted together, from the Secure Code & Advanced Review epic

    Secure Coding Training Enforcement
    Advanced SAST Integration
    Dependency Security Policy
    Supply Chain Verification

    Troubleshooting & FAQs

    Common Issues

    Issue: Target metric not improving

    Solution: Verify measurement is accurate, check if prerequisites are fully implemented, review evidence artifacts for completeness

    Issue: Team resistance to adoption

    Solution: Start with pilot team, demonstrate value with metrics, provide training and support during transition

    Issue: Inconsistent implementation across teams

    Solution: Create shared templates and guidelines, establish regular sync meetings, use automation to enforce standards

    Frequently Asked Questions

    Can we implement this before completing prerequisites?

    While possible, it's not recommended. Prerequisites ensure foundational practices are in place, making this capability more effective and easier to adopt.

    How long does implementation typically take?

    Most capabilities can be implemented within 90 days when tackled as part of the Acceleration milestone. Individual timelines vary based on team size and existing practices.

    DevOps
    Way of Working

    DevOps practices for the entire delivery lifecycle

    © 2019-2026 devopswow.com. Created by Burhan Öcüt

    PartnersAboutPrivacyTermsCookies