Search / finos-ccc/ccc.secmgmt.cp / v2026.06-rc3

Release · v2026.06-rc3

FINOS-CCC/CCC.SecMgmt.CP Capability Catalog

FINOS-CCC/CCC.SecMgmt.CP

Capabilities for Secret Management technologies, as defined by the FINOS Common Cloud Controls project.

Published by FINOS Common Cloud Controls

Install

OCI v1.1
$grcli unpack --repository finos-ccc/ccc.secmgmt.cp --tag v2026.06-rc3
Coordinate
oci.grc.store/finos-ccc/ccc.secmgmt.cp:v2026.06-rc3
Manifest digest
sha256:dcc9e2f23e765da869695bc30ec2a2b6fc68078eddb37a2dceed00ab3e49b6ec

Provenance

1 layer
Digest Media type Size
09a4dec26a59… application/vnd.gemara.artifact.v1+yaml 4.3 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "v1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "CCC.SecMgmt.CP",
            "type": "CapabilityCatalog"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "finos-ccc/ccc.secmgmt.cp",
            "tag": "v2026.06-rc3"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/common-cloud-controls",
          "GITHUB_RUN_ATTEMPT": "2",
          "GITHUB_RUN_ID": "26768391088",
          "GITHUB_SHA": "24594e28430c12318cacffe7fdda6a3ea272d975",
          "GITHUB_WORKFLOW": "Batch Release All Catalogs",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "artifacts/crypto/secrets/capabilities.yaml",
            "uri": "file://artifacts/crypto/secrets/capabilities.yaml",
            "digest": {
              "sha256": "09a4dec26a597d3c7c3783149dbeb32f15a583a5fd2a49899b2161f97d26dfb4"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/common-cloud-controls@24594e28430c12318cacffe7fdda6a3ea272d975",
            "digest": {
              "gitCommit": "24594e28430c12318cacffe7fdda6a3ea272d975"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/common-cloud-controls/actions/runs/26768391088",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26768391088-2",
          "startedOn": "2026-06-01T16:43:59.153276518Z",
          "finishedOn": "2026-06-01T16:43:59.272478225Z"
        },
        "byproducts": [
          {
            "name": "capabilities.yaml",
            "digest": {
              "sha256": "09a4dec26a597d3c7c3783149dbeb32f15a583a5fd2a49899b2161f97d26dfb4"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "capabilities.yaml",
      "type": "CapabilityCatalog",
      "id": "CCC.SecMgmt.CP",
      "role": "artifact"
    }
  ]
}

CCC Secret Management Capabilities

Capabilities for Secret Management technologies, as defined by the FINOS Common Cloud Controls project.

ID
CCC.SecMgmt.CP
Version
v2026.06-rc3
Gemara version
v1.2.0
Author
FINOS Common Cloud Controls

Encryption

The Encryption group covers entries related to protecting data confidentiality and integrity through cryptographic mechanisms. This includes encryption in transit and at rest, key management, and certificate lifecycle management.

  1. CCC.SecMgmt.CP01 Secret Storage

    Provides secure storage for sensitive data such as API keys, passwords, certificates, and other secrets.

  2. CCC.SecMgmt.CP02 Secret Creation - Plaintext

    Ability to create new secrets as basic string data for storing sensitive data such as API keys and database credentials.

  3. CCC.SecMgmt.CP03 Secret Creation - JSON Objects

    Ability to create new secrets as complex JSON objects with multiple fields for storing sensitive data.

  4. CCC.SecMgmt.CP04 Secret Creation - Binary Data

    Ability to create new secrets as binary data for storing certificates and private keys.

  5. CCC.SecMgmt.CP05 Update Secrets

    Ability to update a secret value or description after creation.

  6. CCC.SecMgmt.CP08 Secret Replication Policies

    Allows configuration of secret replication policies to control replication of secrets, supporting compliance with data residency requirements.

  7. CCC.SecMgmt.CP09 Secure Secret Retrieval

    Offers a secure API and SDK access for retrieving secrets, ensuring that secrets are transmitted securely to authorized clients.

Access Control

The Access Control group covers entries related to authentication, authorization, and trust perimeter enforcement. This includes multi-factor authentication, least privilege access, network access rules, and prevention of unauthorized access or reconnaissance.

  1. CCC.SecMgmt.CP06 Soft Delete Secrets

    Prevent secrets from being deleted immediately. Soft deletion makes secrets inaccessible and schedules them for deletion after a recovery window.

  2. CCC.SecMgmt.CP07 Automatic Secret Rotation

    Supports automatic rotation of secrets based on a defined schedule or triggers to enhance security.