Secrets Management is the practice of storing, distributing, and rotating sensitive credentials - database passwords, API keys, OAuth tokens, SSH keys - in a dedicated secure store instead of hardcoding them in application code or configuration files.
A long-term credential pair (access key ID + secret access key) used to authenticate programmatic requests to AWS. Should be replaced with IAM roles wherever possible.
The practice of regularly replacing access keys, passwords, and secrets with new values to limit the window of exposure if a credential is compromised.
Protecting stored data by encrypting it on disk so that it cannot be read without the encryption key, even if the storage media is compromised.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.