后量子密码学的战略准备_第1页
后量子密码学的战略准备_第2页
后量子密码学的战略准备_第3页
后量子密码学的战略准备_第4页
后量子密码学的战略准备_第5页
已阅读5页,还剩40页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

StrategicpreparationforPost-Quantum

Cryptography

Thethreatofquantumcomputing,theimplementationofpost-quantumcryptography(PQC),andstrategiesforasecureandeffectivetransition.

Post-QuantumCybersecurity

Index

Summary 3

Introduction 4

Theroleofcryptographyindataprotectionanddigitalsovereigntyinthepost-quantumera 5

Impactoncurrentcryptography 5

Keyquantumalgorithms:ShorandGrover 6

Thethreatofquantumattack:impactassessmentandstrategicreadiness 6

Whatisquantumcomputing 6

Operationalimplicationsforbusinesses 8

Strategicimplicationsandbusinesssovereigntyinthefaceofquantumcomputing 9

Post-quantumcryptography(PQC)asatechnicalandstrategicanswer 10

PQCtopreservelong-termsecurity 10

StandardizationbyNISTandotherentities 10

Algorithmsselectedforstandardization 11

Significanceofstandardization 11

EUroleandinternationalparticipation 11

Pillarsforaproactiveandgradualtransition 12

Pillar1.Identify:Cryptographicinventoryandriskassessment 13

Pillar2.Protect:Implementationofsolutionsandsafetransition 16

Pillar3.Governance:Implementationandongoingmonitoring 20

Industryusecases 23

Financialsector 23

Conclusionsandrecommendationsforsecuringthedigitalfutureinthequantumera 25

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage2of28

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage3of28

Summary

Cryptographyisessentialfordigitalsecurityandsovereignty.However,thecurrentasymmetriccryptographicsystemswillbevulnerablewithquantumcomputing.Thiscallsforatransition

topost-quantumcryptography(PQC).

Thispaperoutlinestherisks,transitionstrategies,andrecommendedactionstoprotectinformationinthequantumera.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage4of28

Introduction

Digitalsovereigntyiskeytoensuringthe

independenceandcontrolofinfrastructuresanddata.Thisprincipleencompassesoperational,

technologicalanddatamanagementdimensions,andformsthebasisfortheautonomyof

organizationsandstates.

Cryptographyisthetechnologicalbasisof

sovereigntythatprovidesthiscontroland

autonomy.Itensurestheconfidentiality,integrity,andavailabilityofdata,fundamentaltothe

functioningofcompanies,governments,andsocieties.

However,thissecurityparadigmfacesa

significantchangewiththeadvanceofquantumcomputing.TheQ-Daymoment,whenquantumcomputerscancompromisecurrentsystems,

couldcomein10to20years,ifnotsooner.

Althoughthereisnoexactconsensus,andthis

projectiondependsonprogressinquantum

computingandthescalabilityofqubits,this

requirespreparationtoensurethesecurityofdataandcommunicationnetworks.

Post-quantumcryptography(PQC)emergesasatechnicalresponse.Itdevelopsencryption

algorithmsresistanttoattacksbyclassicalandquantumcomputers,basedonmathematical

problemsthatquantumcomputerscannotsolveefficiently.Thisprovidesalevelofsecurity

adaptedtothequantumera.

Theadoptionofpost-quantumcryptographyisbeyondthepurelytechnical.Itisastrategic

decisionwithimplicationsforthesovereigntyofdigitalinfrastructures.Organizations,companies,andgovernmentsensurethattheirdataand

infrastructuresareprotectedagainstpresentandfuturethreatsbyimplementingPQC.Indoingso,theyreaffirmtheirabilitytooperate

independently,maintainingcontrolovertheirdigitalassetsandpreservingtheirsovereignty.

Whatwouldbethe

consequences

ifsomeoneinterceptedandstoredyour

company'smost

sensitivedataand

decrypteditin2030?

Thisdocumentlaysoutacalltoactionfor

organizations,companies,andnationalagencies.ItisurgenttoprepareforthetransitiontoPQC

now.Delayingthisactioncouldhavesignificant

consequences,includingexposureofsensitive

data,disruptionofoperations,andregulatorynon-compliance.

Post-quantumcryptographyisdeployableonconventionalhardwareandsoftware.

Thismakesitpossibletostartthetransitiontodaytoensuretheresilienceandreliabilityofthedigitalinfrastructureinthefuture.

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage5of28

Theroleofcryptographyindataprotectionanddigitalsovereigntyinthepost-quantumera

Encryptionprotectsdatafromunauthorizedaccessandensuresdigitalsovereigntyinstorage,

communications,andcloud.Itpreventssurveillanceorexternalinterference,safeguardingcommunicationsfromgovernments,organizationsormaliciousactors.

RegulationssuchasRGPDinEuroperequireencryptiontoensureuserprivacyandpersonaldata

protection.Inaddition,encryptionprotectscriticalinfrastructuressuchastelecommunications,energyandfinancialservices,safeguardingoperationaldataandcontrolsystems.

Itiscrucialtopreparenowandmigratetonewquantum

cryptographicalgorithmstopreservedataprotectionanddigitalsovereigntyinthelongterm.

Impactoncurrentcryptography

Themostsignificantpotentialimpactofquantumcomputingfromacybersecuritypointofviewisitsabilityto

compromisethesecurityof

manyasymmetric(publickey)cryptographicalgorithms

usedtoday.

•Algorithmsatrisk:RSA,DSA,ECDSAandothersbasedonthedifficultyoflargeintegerfactoringorthediscrete

logarithmproblemarevulnerabletoattackbya

cryptographicallyrelevantquantumcomputer.These

algorithmsarethebasisforthesecurityofprotocolssuchasTLS/SSL(usedin

HTTPS

),SSH,digitalsignaturesandmanypublickeyinfrastructures(PKI).

•Symmetriccryptography(AES,SHA-256):Although

quantumcomputingaffectssymmetriccryptographythroughalgorithmssuchasGrover's,theimpactislesssevere.An

increaseinkeysizewouldberequiredtomaintainan

equivalentlevelofsecurity.Forexample,AES-256offers128bitsofsecurityagainstquantumattacks(accordingto

Grover'salgorithm),whichisequivalenttotheclassicalsecurityofAES-128.Inquantumattacks,AESrequiresanincreaseinkeylengthtomaintainitssecuritylevel.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage6of28

Thethreatofthe'Harvestnow,decryptlater'strategy

MaliciousactorshaveadoptedtheHarvestNow,DecryptLater(HNDL),or'StoreNow,DecryptLater',attackstrategyasalong-termtactic.

HNDLinvolvesthemasscollectionofencrypteddatausingtraditionaltechniquesforstorageanddecryptionwithcryptographicallyrelevantquantumcomputers.Thisaffectsinformationwithalongperiodofconfidentiality,suchasgovernmentsecrets,intellectualpropertyormedical

records,amongothers.

HNDLattacksofmassivecollectionofencrypteddatafromAPT(AdvancedPersistentThreat)groupslinkedtonation-stateshavebeenidentified,includinginterceptionofcommunicationsexploitingvulnerabilitiesinVPNnetworksorTLSchannels,exfiltrationofcloudstorageswithencryptedinformation,ortrafficredirection.

Keyquantumalgorithms:ShorandGrover

•Shor'salgorithm:Thisalgorithm,developedbyPeterShor,isthemainthreattocurrentasymmetriccryptography.Itallowsfactoringlargeintegersinpolynomialtime,asignificantadvanceoverthe

bestclassicalalgorithms.ThisinvalidatesthesecurityofRSAandsimilaralgorithmsandmeansthatdataencryptedtodaywiththeseschemescouldbedecryptedinthefuture.

•Grover'salgorithm:LovGrover'salgorithmexponentiallyreducesthesearchcomplexitytosquareroot,whichmeansthatAES-128wouldprovideonly64bitsofsecurityagainstquantumattacks.Atleast256-bitkeysarerecommendedtomaintainsecurity.

Thethreatofquantumattack:impactassessmentandstrategicreadiness

Whatisquantumcomputing

Quantumcomputingrepresentsadifferentcomputationalparadigmthanclassicalcomputing.Insteadof

bits,whichrepresenta0ora1,itusesqubits.Usingprinciplesofquantummechanicssuchassuperpositionandentanglement,qubitscanrepresent0,1oracombinationofboth.

Thiscapabilityallowsquantumcomputerstoprocessanexponentiallygreatervolumeofinformationthanclassicalcomputersforcertainmathematicalproblems.

Quantumcomputingisnotuniversallysuperiortoclassicalcomputing.Itsadvantageliesinitsabilitytoefficientlyaddressproblemsofhighmathematicalcomplexityindomainssuchasmolecularsimulation,combinatorialoptimizationand,ofparticularrelevancetothispaper,cryptography.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage7of28

TheNationalInstituteofStandardsandTechnology(NIST)recommendsphasingoutRSA-2048andECC-256by2030,withcompleteinvalidationby2035.Aspartofthetransitiontopost-quantumcryptography,NISTurgesorganizationstomigratetoquantum-resistantalgorithmsbeforethosedates.

Imagineagiantmazewheretheexitrepresentsthesolutiontoacomplexproblem,suchasdecipheringacryptographiccode.

Aclassicalcomputerwouldtrytosolvethemazebytryingeachpathonebyone,whichcouldtakeyearsiftherearemillionsofpossiblecombinations.

Incontrast,aquantumcomputercanexploremultiplepathsinparallel,thankstothesuperpositionprinciple.Inaddition,quantumentanglementallowscorrelatingtheresultsofdifferentquantumstates,whichmakesiteasiertofindthecorrectsolutionmoreefficientlyin

certaintypesofproblems.

Thismeansthat,inspecificcasessuchaslargeintegerfactorization(keyinRSA)ordiscretelogarithm

computation(usedinDSA,ECDSA),aquantum

computerrunningShor'salgorithmcouldsolvethemmuchfasterthananyknownclassicalmethod.

However,notallciphersarevulnerable.Algorithmsbasedonpost-quantumcryptographyhavebeendesignedtoresisttheseattacks,evenagainstquantumcomputers.

Althoughquantumcomputerscannotbreakallciphersorsolveallproblemsfaster,theirquantumparallelism

capabilityposesaprofoundchallengetocurrent

digitalsecurity,especiallyforasymmetriccryptography.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage8of28

Operationalimplicationsforbusinesses

Thequantumthreatpresentsasignificant

strategicandoperationalrisktoanyorganization,entityorenterprisethatreliesoncryptographytoprotectitsdataandcommunications.Someoftheimplicationsinclude:

Risksandvulnerabilities

•Riskofdataexposure:Information

encryptedwithalgorithmsvulnerableto

quantumcomputingcouldbedecryptedinthefuture,compromisingsensitivedata,

tradesecrets,intellectualpropertyandconfidentialcommunications.Thisiscriticalfordatawithalong-lifecycle.

•Protectionagainstexternal

interference:Strongencryptioniscriticaltomaintainsovereigntyoverdatain

storageandintransit,especiallyincloudenvironments.Encryptionprotectsagainstsurveillanceandunauthorizedaccessbygovernments,organizationsorcyber

criminals.

Operationalandstrategicchallenges

•Operationaldisruption:Replacing

currentcryptographicsystemsrepresentsanoperationalchallenge.Migrationto

post-quantumcryptographywillrequirecarefulplanning,investmentand

managementtoavoidservicedisruptions.

Keyareasofapplication

•Criticalinfrastructureprotection:Post-quantumencryptionprotectscritical

infrastructuresuchas

telecommunications,energyandfinancialsystems,safeguardingoperationaldataandcontrolsystems.

•Trusteddigitalservices:Organizationscanoffersecureandprivacy-friendly

digitalservicesbycombiningpost-

quantumencryptionwithAIalgorithms,reinforcingtheircommitmenttodigitalsovereignty.

Keyareasofapplication

•Criticalinfrastructureprotection:Post-quantumencryptionprotectscritical

infrastructuresuchas

telecommunications,energyandfinancialsystems,safeguardingoperationaldataandcontrolsystems.

•Trusteddigitalservices:Organizationscanoffersecureandprivacy-friendly

digitalservicesbycombiningpost-

quantumencryptionwithAIalgorithms,reinforcingtheircommitmenttodigitalsovereignty.

•Costofinaction:Delayingpreparationforpost-quantumcryptographycouldresultinhighercostsinthefuture,bothin

remediationofvulnerabilitiesandpotentiallossesfromsecuritybreaches.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage9of28

Strategicimplicationsandbusinesssovereigntyinthefaceofquantumcomputing

Inthecontextofsecuritybasedoncryptographicalgorithms,quantumcomputingpresentsrisksandchallengesthatneedtobeaddressedproactively:

•Commoncryptographicalgorithmswillbecomevulnerable,puttingallprotectedinformationatrisk.Itisessentialto

prioritizethetransitiontopost-quantumcryptography(PQC),whichprotectsdatainthequantumera.

•-ThemigrationtoPQCwillrequire

investmentsintechnologies,software,hardwareand,fundamentally,instafftrainingtoensureasecuretransition.

•Quantumcomputingmustbeintegratedintotheenterpriseriskmanagement

framework,withregularassessmentstoidentifyvulnerabilitiesandmeasure

progresstowardPQCadoption.

•Currentregulatoryrecommendationswillevolvetowardrequirementsforresilient

cryptography,whichdemandsanticipationandpreparationtomitigaterisks.

•Crypto-agilitywillbekeytoadapting

cryptographicsystemsinthefaceofnewthreatsandfuturevulnerabilities.

•Strongcryptographicgovernance,withfullvisibilityofdigitalassets,ensures

regulatorycomplianceandefficientimplementation.

Digitalandtechnologicalsovereigntywillbe

crucialatthestrategicleveltoachievingbusinessobjectives:

•Operationalsovereignty:Necessarytooptimizeefficiency,ensurethesecurityofcommunications,IoT,AI,andcloud

infrastructures.

•Technologysovereignty:Vitalfor

resilienceandindependenceofdigitalinfrastructures,aswellasforregulatorycomplianceandoperationalautonomy.

•AIanddatasovereignty:Protects

nationalinterests,securityandprivacy,

avoidingexternalinfluencesandensuringdecisionsbasedonreliableinformation.

CompaniesshouldprepareinternallyandevaluatevendorsandthirdpartiestoensurethattheirexternaldependenciesdonotcompromisethetransitiontoPQC.PreparingforQ-Day(theday

whenquantumcomputingwillbefullyfunctional)willsignificantlyreducecostsandremediationrisksifacteduponearly.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage10of28

Post-quantumcryptography(PQC)

asatechnicalandstrategicanswer

Post-quantumcryptography(PQC),orquantum

computing-resistant

cryptography,involvesthe

developmentofcryptographicalgorithmsdesignedtoresistattacksbyclassicaland

quantumcomputers.

However,post-quantumcryptographydoesnotrelyonquantum

computers.PQCusesclassicalmathematicalalgorithmson

conventionalhardware,whilequantumcomputingusesQKDforkeyexchangeandQRNGtogeneraterandomnumbers.Thesealgorithmsareconsideredtoberesistanttoattacksbyquantumcomputers.

PQCtopreservelong-termsecurity

PQCisimportantbecauseinformationneedstobeprotectedwithalong-termconfidentialityhorizon.Itisdifficulttopredictwhentherewillbeacryptographicallyrelevantquantumcomputercapableofbreakingcurrentcryptography,buttheconsensusamongexpertsandtheNISTforecastisthatquantumcomputingwillweaken

existingasymmetriccryptographybytheendofthisdecade.

Replacingasymmetriccryptographywithquantum-securecryptographyrequiresproactiveaction.MigrationtoPQCmustbeapriority.

Informationencryptedtodaywithvulnerablealgorithmscouldbedecryptedinthefuturewithsevere

consequencesbecauseofthis.ThetransitiontoPQCisthereforenotjustatechnicalissue,butalong-termriskmanagementstrategy.

StandardizationbyNISTandotherentities

StandardizationiskeytoPQCadoptionandinteroperability.TheUSNationalInstituteofStandardsandTechnology(NIST)hasbeenleadingaprocessofevaluationandstandardizationofPQCalgorithmssince2016.

Thisprocess,structuredinseveralrounds,hasinvolvedtheglobalcryptographiccommunityintheanalysisandevaluationofdozensofproposals.NISThasbeenthemaindriverintheidentificationand

standardizationofPQCalgorithms,throughitsPost-QuantumCryptographyProject.

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage11of28

Algorithmsselectedforstandardization

NISTpublishedthefirstpost-quantum

cryptographyalgorithmsinAugust2024,initiatingprotectionagainstquantumcomputing.These

algorithms,chosenbytheglobalcryptographiccommunityforstandardization,allowustobeginthepost-quantumtransitionnow:

•CRYSTALS-Kyber(KEM):Basedon

latticestructuresandtheLearningWithErrors(LWE)problem,forgeneralkeyencapsulationuse.

•CRYSTALS-Dilithium(Digital

Signature):Alsobasedonlatticestructures,forgeneraldigital

signatureuse.

•FALCON(DigitalSignature):specificallyoptimizedforreducedsignaturesizes

comparedtoDilithium.

•SPHINCS+(DigitalSignature):Asa

hash-baseddigitalsignatureoption,butwithaconsiderablylargersignaturesize.

NISThaspublishedtheselectionofthesefirstalgorithmsforofficialstandardsforquantumcomputing-resistantcryptographyandis

consideringstandardizationofadditionalalgorithms.

Significanceofstandardization

StandardizationofPQCalgorithmsensuresthattheselectedalgorithmshavebeenevaluatedandfacilitatestheintegrationofsystemsand

applications,promotingtheirglobaladoptionbyproviding:

•Trust:theinternationalcryptographiccommunityhasevaluatedtheselectedalgorithms.

•Interoperability:Standardizationenablesinteroperabilitybetweendifferentsystemsandapplications.

•Guidanceforadoption:Providesaclearroadmapfororganizationslookingto

migratetoPQC,enablingthemtoselectalgorithmswithconfidence.

EUroleandinternationalparticipation

Otherorganizations,suchasISOandETSI,arealsoinvolvedinPQCstandardization,ensuringglobaland

coordinatedadoption.TheEuropeanUnionAgencyforCyberSecurity(ENISA)alsoplaysanimportantrole,providingguidanceandrecommendationsonthetransitiontoPQCintheEuropeancontext.

ENISAworkswithNISTandotherinternationalorganizationstopromotetheadoptionofglobalstandardsandbestpracticesinpost-quantumcryptography.ReportsandrecommendationsonPQC,including

algorithmmaturityassessmentsandmigrationguidelines,havebeenpublished.

NIST'sstandardizationofquantumcomputing-resistantcryptographyalgorithmsmarksthebeginningofthetransitiontoPQC.Researchinpost-quantumcryptographycontinuesanditislikelythatnewalgorithmswillbedevelopedandstandardized.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage12of28

Pillarsforaproactiveandgradualtransition

Thetransitiontopost-quantumcryptographyisacomplexprocessthatmustbeapproachedstrategically,inphasesandwithdetailedplanning.Itisnotjustareplacementofalgorithms,butaprogressiveredesignofthesecurityinfrastructuretoensureresiliencetothequantumthreat.

Thestrategyshouldconsiderriskassessment,algorithmselection,phasedimplementationandcontinuousmonitoring,followingthreepillars:Identify,Protect,andGovern.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage13of28

Pillar1.Identify:Cryptographic

inventoryandriskassessment

Riskassessmentisa

continuousanddynamic

processthatshouldbe

integratedintoenterprise

informationsecurity

management.Itshouldcoverthefollowingkeyaspects:

Cryptographicassetinventory

Thefirststepistoidentifyanddocumentallcryptographicassetsintheorganizationtoassesstheirexposuretoquantumthreat.This

includes:

•Cryptographickeys,includingtheirtype,lengthandalgorithm,usedinsystems,applicationsanddevices.

•Digitalcertificatesidentifyingtheirissuer,expirationdate,anddependentsystemsandapplications.

•Cryptographiclibraries,theirversionsandtheapplicationsthatusethem.

•Externaldependenciesandthird-partyservicesthatusevulnerablecryptography.

•Cryptographicprotocolsused,suchasTLS/SSL,SSH,IPsec,etc.,includingtheirversions.

•Contextofusetoknowwhatandwhereitisbeingused.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage14of28

Implementinganautomatedcryptographicinventoryiscriticaltounderstandingthelevelofriskexposureandprioritizingthemigrationprocesstopost-quantumcryptography(PQC).

Itisrecommendedthatspecializedstaticcodeanalysisandkeydiscoverytoolsbeusedtoensureanaccurateandcomprehensiveassessmentofcryptographicassets.

Thisanalysisshouldincludethedetectionofinadequateencryptionpractices,suchastheuseofobsoletecryptographicalgorithms,insecureparametersorkeyswithinsufficientkeylengths.

Riskanalysisandvulnerabilitymanagement

Onceyouhaveacryptographicinventory,thenextstepistoassessrisksandmanagevulnerabilitiesbasedon:

•Dependenciestodeterminewhichsystems,applicationsandbusinessprocessesrelatetoeachcryptographicasset.

•Criticalityaccordingtothetypeofinformationprotectedandtheimpactofitsexposure.

•Vulnerabilitytocurrentattackssuchas'HarvestNow,DecryptLater'andquantumattacks,suchasthoseusingRSAorECCwithinadequatekeylengths.

•PrioritytomigratethemostcriticalassetstoPQCfirstaccordingtotheirrisk,probabilityofoccurrenceandpotentialimpact.

ItiscriticaltointegraterelevantITsources,suchasconfigurationmanagementsystems(CMDB),networklogs,andapplications,toprovidethenecessarycontextfortheidentifiedassets.Thisfacilitatesacorrectcorrelationbetweencryptographicassetsandtheiroperationaldependencies,thusensuringamore

accurateandactionableriskassessment.

AtthisstageitiscriticaltoaligntherelevanceofPQCwiththestrategicobjectivesofthe

enterprise.Planningmustbemeticulous,carefullyprioritizingwhattoaddressfirst,aschangesrequiresignificantimplementationandadaptationtimes.

Post-QuantumCybersecurity

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage15of28

Crypto-agilitystrategyandroadmap

Theriskanalysisculminatesinaninitialtransformationplanthatshould:

•Definearchitecturalprinciplesforsystemsresilienttocryptographicchanges,ensuringtheabilitytoreplacealgorithmsagilely.

•Modernizecryptographicinfrastructuretoensurecompatibilityandreduceoperationalrisks.

•UpgradeservicesandapplicationstointegratewithPQCcryptography.

•Implementprotectionmeasuresfordatainuseandatrest,usingconfidentialcomputingandkeylifecyclemanagementtechnologies.

•Defineadetailedroadmapwithshort-andlong-termobjectives,includingspecificmetricsandtargets.

TelefónicaTechpositionsitselfasa

comprehensivepartner,capableofproviding

expertguidancetohelporganizationsdefineandexecutethistechnologytransformationplan.Weoffersolutionstailoredtothespecificneedsof

eachcompany,withextensiveexperienceinthefieldofcrypto-agilityandadeepunderstandingofthestrategicobjectivesofthebusiness.

Organizations,companies,andpublic

administrationsensurethattheintegrationofpost-quantumcryptography(PQC)iseffective,secureandalignedwithbusinessobjectives,

maximizingthereturnoninvestmentandstrengtheningoperationalresilience.

Theapproachshouldbeprogressive,focusingfirstoncriticalassetsand

ensuringoperationalcontinuityduringthetransition.

STRATEGICPREPARATIONFORPOST-QUANTUMCRYPTOGRAPHYPage16of28

Pillar2.Protect:Implementationofsolutionsandsafetransition

Riskassessmentisa

continuousanddynamic

processthatmustbe

integratedintoacompany'sinformat

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论