Organizations should create a cryptographic inventory showing how they use cryptography in IT and OT, using discovery tools to find quantum-vulnerable algorithms in network protocols; in assets on end-user systems and servers, including applications and their libraries and the mechanisms for software and firmware updates; and in cryptographic code or dependencies in the continuous integration and delivery pipeline. Because discovery tools may miss cryptography embedded inside products, organizations should ask vendors for lists of the embedded cryptography in their products. Systems that create and validate digital signatures, including for software and firmware updates, are quantum-vulnerable assets.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.