Migration Planning / Management Tools Audit
§5What this is for: Audit your discovery, assessment, configuration, and enforcement tooling stack — feeds the Information Repository per CSWP.39 §5.
What a good answer looks like: You know which of your own tools would have to change before a single production key does.
Worked example: Rate your coverage — None, Manual, Partial or Automated — for each of the seven categories from Asset Management (CMDB / SBOM pipeline) to Zero-Trust Enforcement: the gap list, ordered by importance, says which tool has to change before a production key does.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Rate coverage None, Manual, Partial or Automated for the seven tool categories from crypto scanners to zero-trust enforcement: the gap list, ordered by importance, says which tool has to change before a production key does.
- GRC / Risk & Compliance
- Enter the systems covered by each category and the coverage level: the export records the management-tools gap the CSWP.39 §5 step 3 audit requires, with the ordering already applied.
CSWP.39 §5 step 3 (Identify Gaps) requires auditing the Management Tools layer — the discovery, assessment, configuration, and enforcement tooling that keeps your crypto inventory and risk data current. Without these tools, your Risk Analysis Engine operates on incomplete, manually maintained data. Rate your current coverage for each tool category, then review the gap recommendations.
Detect algorithms, key lengths, cert details across source code and network traffic.
Deploy a crypto scanner (e.g., Keyfactor Discovery, Venafi TLC, or open-source cryptoscan) in passive mode against at least one production network segment.
CVE feeds, crypto library EoL tracking, CMVP historical-cert alerts.
Subscribe to the NIST CMVP change-notice feed and NVD API for crypto CVEs. Create a weekly triage task.
SBOM generation, CBOM enrichment, and CMDB feeds that keep the crypto asset inventory current.
Generate a CycloneDX SBOM for your top 5 critical applications using Syft or cdxgen.
Crypto policy-as-code enforcement and certificate-lifecycle management — pushing approved algorithms and cert renewals to systems automatically.
Adopt a certificate-lifecycle management (CLM) tool (e.g., Venafi, Keyfactor Command, HashiCorp Vault PKI) for at least one critical CA chain.
Crypto-drift events, cipher-suite anomalies, protocol-version alerts in real time.
Configure TLS handshake logging on at least your public-facing load balancers; route to your SIEM.
Policy engines that block disallowed cipher suites at the network layer; mTLS enforcement.
Define a crypto policy baseline (minimum TLS 1.2, approved cipher suites); document it in Governance.
Classify data assets by sensitivity to drive inventory prioritisation.
Manually classify your top-10 data repositories by sensitivity (public / internal / confidential / restricted).
How this is scored: each tool's coverage level (None 0 → Automated 3) is multiplied by its importance to a PQC migration, summed, and divided by the maximum possible weighted total. It is a weighted average, not a plain one — the four foundational tools (crypto scanners, vulnerability management, asset management, configuration management) each count three times as much as data classification. Systems-coverage percentages are yours to enter; nothing seeds them, because a count of detected products says nothing about how much of your estate they reach.
Management Tools Audit — Export
Save this audit to your Command Center under the Management Tools zone, or export as markdown / PDF / DOCX for sharing.
- NIST NVD — National Vulnerability Database
- CISA KEV — Known Exploited Vulnerabilities
- CISA — PQC Migration Framework
- OPA — Open Policy Agent (policy-as-code)
- Carnegie Mellon CyLab (Americas)
- UC Berkeley BQIC (Americas)
- Ruhr University Bochum Cryptography (EMEA)
- Max Planck Institute Security and Privacy (EMEA)
- Brno University of Technology (EMEA)
- Duke University Quantum Center (Americas)
Try it
Rate a category "None". Where does it land in the output?
Next step
Next in Migration Planning: Crypto BOM (CBOM) BuilderCrypto BOM (CBOM) Builder is the next Migration Planning tool in the Command Center.