CAIQ v4 Control IAM-07 Extractive Review Standard

How to answer 'How are service accounts and machine credentials managed?' on a CAIQ

Reviewer Guidance & Pitfalls

Explain how API keys and machine credentials avoid hardcoding. Cite automated secret management vaults (e.g. AWS Secrets Manager, Vault) and automated key rotation intervals.

Example Answer Passing Enterprise Audit

Compliant Response Template
Service credentials are stored in managed secret vaults, injected at runtime, and rotated every 90 days. Static hardcoded credentials in source code are strictly prohibited and audited via pre-commit hooks (SOC 2, CC6.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.