ENlighten operates a platform that manages more than 28,800 solar power plants across Korea. Generation forecasting, asset monitoring and energy trading all run on Google Cloud, which makes a service account key less of a minor secret and more of a door into the systems that read and act on national generation data. The company was preparing for ISMS certification while winning enterprise customers who bring their own security requirements. Several years of fast development had left GCP service keys sitting in repositories, internal documents and collaboration tools, and the certification work needed an accounting of where they were.
Cremit scanned the development and collaboration environments together and returned the GCP service keys that had ended up outside the places meant to hold them. The team rotated them. Each key came back with the repository or document it was found in, which is the form the audit question takes as well: not whether the company manages cloud credentials, but how it knows where they are.
As we prepared for ISMS certification, Cremit helped us identify Google Cloud service keys we didn't even know were exposed. Securing these credentials not only reduced our risk but gave us the documented evidence we needed for the audit.
The scan turned up a substantial number of Google Cloud service keys that had built up across the stack over several years. All of them were rotated. The scan record then went into the ISMS submission. Credential management is one of the controls an audit asks a company to demonstrate rather than assert, and a dated scan across every repository and document is that demonstration.