Cryptographic Agility — policy and migration
securityv1/01 Views
/02 About
Cryptographic discovery, risk assessment, algorithm negotiation, key lifecycle, hybrid migration, monitoring and rollback without vendor bindings.
Purpose: Cryptographic discovery, risk assessment, algorithm negotiation, key lifecycle, hybrid migration, monitoring and rollback without vendor bindings. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/207/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.
Published by Lattix · 20 elements · 21 relationships · validated on publish
/03 Contents
- Role
- Cryptographic policy owner
- Process
- Inventory cryptographic usage, Assess exposure and algorithm risk
- Data Store
- Cryptographic asset register, Key and certificate events, Crypto agility evidence
- Policy
- Approved cryptographic policy
- Application Component
- Algorithm and protocol negotiation, Cryptographic implementation boundary, Protected communications, Key and certificate issuance, Rotation coordinator, Revocation and expiry distributor, Cryptographic usage telemetry, Noncompliant suite detection, Crypto-incident containment
- Activity
- Identify vulnerable cryptography, Stage classical and post-quantum alternatives, Perform compatibility-controlled rollout, Verify interoperability and rollback