NIST for Gov
Reports that check a Drupal site against NIST SP 800-53 Rev. 5 controls. Built for government and regulated sites. Every report only reads: nothing on the site is changed.
Secrets left visible (IA-5(7), SC-28)
Lists API keys, passwords and tokens stored in plain text, and never shows a value in full (length and last four characters only).
- High: in exportable configuration and committed to the sync directory, so it's in version control. Remove it and rotate it. IA-5(7).
- Medium: in exportable configuration, including Key module keys that use the
configprovider. The next export commits it. IA-5(7). - Low: in State. Not exported, but every database backup holds it. SC-28.
Each row says how to fix it: a settings.php override from an environment variable, or the Key module with the environment or file provider. Also available as drush nist:secrets, which exits non-zero while a secret is committed, so CI can stop on it. A Status report entry warns while one is committed.
The controls, from NIST SP 800-53 Rev. 5 (doi.org/10.6028/NIST.SP.800-53r5): IA-5(7) No Embedded Unencrypted Static Authenticators ("Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage."), and SC-28 Protection of Information at Rest.
Coming from Drupal Cleanup?
This report used to be part of Drupal Cleanup. Installing NIST for Gov takes over its settings. The old address redirects, and drush cleanup:secrets still works.
Requirements
Drupal 10.3 or 11. No other modules.
Related sites
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.
Activity
Releases
| Version | Type | Core | Release date | |
|---|---|---|---|---|
| 1.0.x-dev | Dev | 10–11 | Oct 3, 2026 |