Mental model
Cisco objective 4.8 says “Describe application security issues related to secret protection, encryption (storage and transport), and data handling”. Three overlapping topics; each is a chapter in a real book, but you need the one-page version.
1. Secret protection
What is a secret
Anything that proves identity or permission: API keys, passwords, database connection strings, SSH private keys, signing keys, access tokens.
How secrets leak
- Hardcoded in source code, then pushed to Git. Bots scan GitHub for leaked tokens within minutes.
- Logged by accident (“about to call API with token=eyJhbGci…”). Logs end up in SIEM / S3 / vendor support cases.
- Shared in Slack, email, Jira tickets.
- In an image baked into a Docker image or AMI.
- Dumped in config files on disk with world-readable permissions.
Where secrets belong
| Where | Good for |
|---|---|
Environment variables ($MERAKI_API_KEY) injected by the OS or orchestrator | Container deployments, CI/CD |
.env file in .gitignore | Local dev. Never commit. |
| Secret manager (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, Cisco Vault via NSO) | Production, multi-service |
| Secrets Store CSI driver | Kubernetes workloads |
Three rules
- Never commit a secret to a repo. Add
.env,*.pem,*.keyto.gitignorefrom day one. - Rotate on any suspicion of leak. Treat the compromised secret as burned.
- Use the shortest-lived credential your workflow allows (OAuth2 tokens over API keys when possible).
2. Encryption
Two scopes:
In transit
Any data moving over a network must be encrypted. Modern baseline: TLS 1.2+ on every API, every management interface, every backup copy.
- HTTPS instead of HTTP.
- SSH instead of Telnet.
- NETCONF (over SSH) instead of SNMP v1/v2c (plain-text).
- SNMPv3 if you must do SNMP.
At rest
Data sitting on disk must be encrypted too.
- Full-disk encryption on servers (dm-crypt / LUKS, BitLocker, FileVault).
- Database-level encryption (TDE in Oracle/SQL Server/Postgres).
- Object storage: enable server-side encryption on your S3 / GCS buckets.
- Backups: encrypted before leaving the source.
Keys
Encryption is only as strong as key management. Keys live in an HSM (hardware security module) or a cloud KMS (AWS KMS, Azure Key Vault, GCP KMS). Rotate keys periodically.
3. Data handling
Beyond “encrypt everything” there are practical day-to-day habits.
Minimise
Only collect data you actually need. Fewer fields → smaller breach impact. The record you never collected is the one that cannot leak.
Mask / redact
Logs are indexed, shared, and shipped off-box. Mask or redact sensitive fields BEFORE they are logged:
log.info(f"API call to {url} with token={token[:4]}***")
Not:
log.info(f"API call to {url} with token={token}")
Separate
Keep PII (personally identifiable info) in a dedicated table/service with stricter access. Everything else can be less protected.
Delete
Have a retention policy. “Keep forever” is a liability. GDPR, CCPA, and sector regulations (HIPAA, PCI-DSS) impose maximum retention periods.
Validate on input
Reject or sanitise untrusted input at the earliest possible layer. See OWASP top threats for XSS, SQLi, CSRF.
Common anti-patterns to call out in a code review
- Secret in
requirements.txt,settings.py,terraform.tfvars. - Hardcoded TLS verify=False to “make it work” (ignores every cert error, including attacker’s).
- Logging HTTP request/response bodies without redaction.
- Email of PII in Jira tickets or Slack.
- Backups copied to a bucket with no encryption and world-read.
- Shared service account with everyone’s password written on a sticky note.
FAQ
What if my team uses a shared vault spreadsheet? Replace with a proper secret manager this quarter. Even a free-tier HashiCorp Vault or Bitwarden is miles better than a shared doc.
Is ‘rotate every 90 days’ still recommended for passwords? For human user passwords, NIST 800-63B says no — only rotate on evidence of compromise. For machine credentials and API keys, periodic rotation (quarterly) is still standard.
My cert expired and now TLS fails. Should I verify=False to buy time? No. Renew the cert. verify=False in production disables the entire security story.
What does “encryption at rest” mean for a Cisco switch? The running config on the switch is in memory; copies on flash can be encrypted (depends on model). Backup configs stored on a central server must be encrypted there.
