Algorithms & protocols
Algorithms, parameters and protocols used for encryption, signatures, hashing, authentication and key establishment.
You cannot govern, prioritise or migrate cryptography you do not know exists.
Discovery creates a reliable view of where cryptography is used, what it protects and who depends on it. The goal is not an inventory for its own sake, but evidence that supports risk decisions and controlled change.
Last reviewed: August 2026
Cryptography can be embedded in application code, libraries, TLS endpoints, APIs, identity platforms, databases, cloud services, network appliances, HSMs, certificates, signing services and third-party products. Different teams may own each layer.
When an algorithm is deprecated or a migration becomes necessary, fragmented visibility becomes a delivery risk. Discovery should make it possible to identify affected services quickly enough to assess exposure, assign ownership and plan change.
Algorithms, parameters and protocols used for encryption, signatures, hashing, authentication and key establishment.
Purpose, owner, lifecycle state, expiry and trust relationships — never secret key material itself.
Libraries, SDKs, firmware, HSMs, embedded components and products that provide or constrain cryptographic capability.
Applications, devices, infrastructure and business services implementing or depending on each mechanism.
Information protected, sensitivity, required protection lifetime and relevant long-term exposure.
Technical owner, service owner, external provider and other parties that can implement or constrain change.
Inventory question
Not only “Where do we use RSA?” but “Which critical services depend on it, what does it protect, who owns it, and what constrains replacement?”
A useful inventory has defined ownership, scope, refresh triggers and quality expectations. New findings are reconciled with known systems rather than accumulating as disconnected scan output.
Risk management should be able to trace a material cryptographic finding to a service, security purpose, owner and treatment path. Unknown ownership or unexplained coverage gaps should be visible as evidence gaps.
The target is not perfect visibility on day one. It is sufficiently reliable visibility to answer material risk and migration questions before urgency removes the organisation's options.
Quantum readiness requires organisations to identify quantum-vulnerable public-key cryptography and understand where replacement will be required.
Discovery is therefore migration infrastructure: without it, prioritisation and credible transition planning are largely guesswork.
Educational synthesis. Consult primary sources for normative and implementation-specific requirements.