Skip to content

docs: add credential lifecycle record template#61

Open
Hinotoi-agent wants to merge 1 commit into
OWASP:mainfrom
Hinotoi-agent:docs/credential-secret-lifecycle-record
Open

docs: add credential lifecycle record template#61
Hinotoi-agent wants to merge 1 commit into
OWASP:mainfrom
Hinotoi-agent:docs/credential-secret-lifecycle-record

Conversation

@Hinotoi-agent
Copy link
Copy Markdown
Contributor

Summary

  • Adds an informative Credential and Secret Lifecycle Record Template appendix
  • Links the template from the standard appendix index, Getting Started document map, Scope Enforcement guidance, and Supply Chain Trust guidance
  • Provides YAML and JSON-equivalent examples for tracking credential provenance, scope, access, protection controls, rotation, revocation, retention, disposal, and exceptions

Why

APTS-SE-023 already covers lifecycle governance for credentials and secrets used, encountered, or generated during testing. Related requirements cover discovered credential protection, API authentication, sensitive data handling, retention, and destruction proof. This PR adds a practical evidence artifact that helps operators, customers, and reviewers inspect those lifecycle records consistently without creating a new normative requirement.

Affected sections

  • standard/appendix/Credential_and_Secret_Lifecycle_Record_Template.md
  • standard/README.md
  • standard/Getting_Started.md
  • standard/1_Scope_Enforcement/README.md
  • standard/1_Scope_Enforcement/Implementation_Guide.md
  • standard/7_Supply_Chain_Trust/README.md

Contributing.md checklist

  • No overlapping open issue or PR was found for this specific credential and secret lifecycle record template
  • Affected sections and requirement IDs are listed above
  • Formatting and links were checked locally
  • This contribution is informative/non-normative and does not create or modify APTS requirements
  • Drafted with AI assistance and reviewed for accuracy, consistency with the standard, and style-guide compliance

Validation

  • python3 scripts/validate_markdown_tables.py
  • python3 scripts/check_internal_markdown_links.py
  • python3 scripts/validate_cross_references.py
  • python3 scripts/check_generated_artifacts.py
  • python3 scripts/validate_yaml.py
  • YAML example parsed with PyYAML
  • Touched relative Markdown links verified locally
  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant