Cryptographic Inventory
Understanding what cryptographic systems exist across an organization is the essential first step. This includes identifying where public-key cryptography is used, what algorithms are employed, key sizes, and dependencies on cryptographic libraries and protocols.
- Map all systems using RSA, ECDSA, ECDH, and Diffie-Hellman
- Document key sizes and certificate chains
- Identify cryptographic library and protocol dependencies
- Catalog TLS/SSL implementations and versions