Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)
Step 1: quantum-vulnerability diagnosis – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024) INV-CRYPTO: Build and maintain an inventory of cryptographic assets

The organisation aims for an exhaustive list of every use of cryptography in software and hardware, including assets about to enter the organisation, recording algorithm, key length and use so that quantum-vulnerable items and replacements can be identified, and identifying suppliers for assets it does not control (for example in a configuration management database). Discovery covers every service relying on confidentiality, integrity, authenticity or non-repudiation, across three settings: software development (libraries and cryptographic functions used, ideally found with static or dynamic analysis in the development lifecycle and CI/CD pipeline), operational systems and applications (executable assets such as software, firmware, hardware and libraries, and non-executable ones such as tokens, keys, key stores and X.509 certificates) and network traffic across all OSI layers with permitted scanning tools, combined with agent-based detection. A standard machine-readable format such as the CycloneDX Cryptographic Bill of Materials is recommended, tool output is sanity-checked by hand (tools miss key management practice, HSMs and TEEs and links between certificates and key pairs), the inventory is kept up to date continuously, and it is protected as sensitive information because it reveals the organisation's weaknesses.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.9 Inventory of information and other associated assets
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • R-INV R-INV Build a cryptographic inventory with discovery tools across protocols, systems and the development pipeline

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Step 1: quantum-vulnerability diagnosis – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.