Password vault

A system that stores passwords and other secrets encrypted and releases them only to authorised users or software; enterprise vaults can also check out, log and rotate privileged credentials.

A password vault stores passwords and other secrets in encrypted form and releases them only to an authenticated, authorised user or process. The ISC2 exam outline gives it as the example of a credential management system under objective 5.2. Vaults range from a personal password manager to an enterprise vault holding shared, privileged and service account credentials. An enterprise vault can check a credential out to a named person, record the use, and rotate the password afterwards, so that nobody needs to keep a standing copy.

A vault concentrates risk as well as control. Its own sign-in, its encryption keys, its recovery process and its administrators become the target, so it needs authentication at least as strong as anything it protects, plus its own access review. A browser’s saved passwords are not the same control as an enterprise vault, because authority, recovery and audit differ. Vaulting is one form of credential management system and a core part of privileged access management.

Exam relevance: a scenario is likely to describe shared administrator passwords kept in a spreadsheet, or service credentials written into scripts. Candidates are expected to recognise a vault with check-out, logging and rotation as the fitting control, and to remember that the vault then needs strong authentication and a planned break-glass route of its own.