Authorize collection scope
Certificate and trust-store discovery
DISC · GOVERNANCE PRODUCT / PLATFORM MODULE
Locate vulnerable public-key cryptography across certificates, traffic, code, devices and trust services.
CUSTOMER PROBLEM
Organizations cannot prioritize PQC migration until they know where public-key cryptography is embedded, who owns it and how long the protected data must remain secure.
PRODUCT-SPECIFIC IMPLEMENTATION FLOW
Network captures, certificate stores, source/dependency scans and structured interviews. Discovery report, asset register and scoped findings with traceable source evidence.
Certificate and trust-store discovery
PCAP and protocol observation
Source, dependency and configuration review
CA/TSA/OCSP/CRL inventory
Ownership and business-service mapping
Evidence-backed remediation backlog
NAMED COMPONENTS AND RESPONSIBILITIES
The descriptions below state concrete technical behaviour rather than generic support language.
Reads approved certificate stores and trust anchors, recording issuer, subject, algorithm, key length, validity and source location for every finding.
Parses authorized PCAP or sensor output to identify TLS, SSH, IPsec and other cryptographic negotiations without claiming visibility beyond the captured traffic.
Inspects dependency manifests, configuration files and selected source locations for cryptographic libraries, providers, hard-coded parameters and protocol settings.
Maps CA, TSA, OCSP and CRL endpoints to the applications and relying parties that depend on them, including ownership and renewal contacts.
Links every cryptographic observation to a business service, system owner, data class and migration dependency so that findings become actionable.
Converts verified findings into a prioritized remediation backlog with evidence references, accountable owners, acceptance criteria and review dates.
Network captures, certificate stores, source/dependency scans and structured interviews.
Collectors run against approved sources; findings are reviewed before entering the governed inventory.
Scheduled collectors and connectors feed the inventory, risk and policy workflows under customer control.
Mobile-ID facilitates refresh, review and reporting while the customer retains ownership and approval authority.
PRODUCT-SPECIFIC BOUNDARIES
These points come from the product profile, not from a shared disclaimer.
NEXT STEP
Review the exact operating model, interfaces and evidence needed for deployment.