A sound algorithm can be undermined by its implementation, so the organisation decides how far each application must resist side-channel analysis, fault injection and differential fault analysis (resistance to timing attacks is essential, with constant-time code), leaves implementation to experts, and deploys production-ready implementations that have passed security evaluation, such as FIPS 140 or ISO/IEC 19790 module validation, Common Criteria (ISO/IEC 15408) or the Dutch BSPA, performed by accredited laboratories; reference implementations and the Open Quantum Safe libraries are stand-ins for development, not production. Integrators follow standards and certification developments and published vulnerabilities throughout the product life cycle, consider combining software and hardware solutions, and consider reconfigurable hardware where field updates are needed.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.