Credential management system
A system that stores, issues and rotates secrets such as passwords, keys and certificates, so people and software no longer keep them in memory, in files or in code.
A credential management system takes secrets out of the places they tend to leak from. The secret is held centrally and encrypted, released when an authorised person or process needs it, and changed on a schedule or after use. The ISC2 exam outline lists credential management systems under objective 5.2 and gives the password vault as its example. An enterprise vault can check a privileged credential out to a named administrator, record the use and rotate the credential afterwards, which is why it often supports privileged access management and the handling of service account secrets.
The trade-off is concentration. A vault gathers control, but it gathers risk too: its own sign-in, its encryption keys, its recovery process and its administrators become the target. It therefore needs authentication at least as strong as anything it protects, and its own access review. A browser’s saved-password store is a different control, because it lacks the central authority, recovery and audit trail of an enterprise system.
Exam relevance: a scenario is likely to describe passwords in scripts or shared spreadsheets, or service credentials unchanged for years, and ask for the best improvement. Candidates are expected to see that a vault moves credential risk to the vault rather than removing it.