Table of Contents

NOD-003e — Protect Sensitive Configuration Values

Go to NOD-003 — Configure a Node

Statement

The DIDO-TE SHALL protect each Sensitive Configuration Value throughout its Lifecycle.

Derived From

Rationale

A Node Configuration may contain Credentials, Cryptographic Material, authentication tokens, personal information, network details, proprietary values, or other Information whose disclosure, alteration, substitution, or misuse may compromise a Node or Test Environment.

Protection applies while a Sensitive Configuration Value is created, obtained, transferred, stored, resolved, applied, used, recorded, retained, and disposed of. The applicable Security Controls depend upon the value’s Classification and the risks associated with unauthorized access or modification.

A protected reference, Identifier, digest, or redacted representation may preserve Evidence and Traceability without exposing the Sensitive Configuration Value.

This requirement governs the protection of Sensitive Configuration Values. It does not require the DIDO-TE to reproduce secret values in Configuration Records, logs, Test Results, or Evidence.

Applies To

Verification

Verification confirms that:

Verification includes:

Referenced By

Delivery Phase

Assign the applicable delivery phase.

Requirement Status

Draft

Statement Reference

Use the following syntax to reference this requirement’s Statement section from another DokuWiki page:

{{section>dido:03-dido-te:99-annexes:annex-c-requirements:03-node-requirements:nod-003-configure-a-node:nod-003e-protect-sensitive-configuration-values#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.