HSM key management metadata

Identifies hsm key management metadata patterns in security and access control contexts. Detects potential exposure of sensitive security information in Australian systems.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
structural regex with domain-specific anchors and constrained context replaces phrase-only marker.
Detection quality
Mixed
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth), NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
Frameworks
CIS Controls, DISP, ISO 27001, NIST CSF, PCI-DSS, SOC 2
Data categories
credentials, security
Scope
wide
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:hsm\s+key\s+management|hardware\s+security\s+module|key\s+rotation|key\s+lifecycle|cryptographic\s+key|key\s+custodian|key\s+ceremony|key\s+escrow|master\s+key)\b

Corroborative evidence keywords

hsm key management metadata, hsm, key, management, metadata, credentials, keys, secrets

Proximity: 300 characters

Should match

Should not match

Known false positives