Frequently Asked Questions
This FAQ section provides answers to common questions about the BigFix Quantum Risk Analyzer scanner, its compliance with federal mandates, and how it helps organizations prepare for the post-quantum cryptography era.
Compliance & Requirements
How does the BigFix Quantum Risk Analyzer scanner meet the OMB inventory requirements?
OMB Memorandum M-23-02 "Migrating to Post-Quantum Cryptography" directs federal agencies to 1) maintain annual inventories of quantum vulnerable cryptographic algorithms and 2) engage with NIST to coordinate efforts. In response to this memorandum, NIST issued the NIST 1800-38 series on Cryptographic Discovery and Interoperability Testing with practical guidance and specific reporting requirements.
NIST 1800-38B: Preparation for Considering the Implementation and Adoption of Quantum Safe Cryptography
- The scanner module discovers keystore and cryptographic cipher information associated with all tools listed by NIST, plus others
- Coverage includes: Executables, Application binaries, Cryptographic libraries, Java archives, Non-executables, Keystores: PKCS#12, Java Keystores, OpenPGP Keys, X.509 Certificates, OpenSSH Keys, PKCS#1 and PKCS#8
What laws and policies are related to the mandate to establish a cryptographic inventory?
- 05/12/2021: Executive Order 14028 Improving the Nation's Cybersecurity: Established a timeline for supporting TLS 1.3 and identifying product categories for PQC capable tools.
- 04/18/2022: H.R. 7535 Quantum Computing Cybersecurity Preparedness Act: Requires federal agencies to prepare for the post-quantum era by evaluating and transitioning to quantum-resistant cryptography.
- 05/04/2022: NSM 10 Promoting United States Leadership in Quantum Computing: Directs specific actions for agencies to begin to migrate vulnerable computer systems to quantum resistant information systems. Each agency is responsible for discovering, documenting, and maintaining a comprehensive inventory of devices and applications vulnerable to decryption by quantum computers.
- 11/18/2022: M-23-02 Migrating to Post-Quantum Cryptography: Directed agencies to inventory cryptographic systems annually and laid out concrete steps toward being quantum ready.
Is a cryptographic inventory only a government requirement or should commercial enterprises establish cryptographic inventory and risk assessment?
While government mandates and requirements target federal agencies, all enterprises with sensitive information are vulnerable. Organizations that are serious about protecting their data must start planning for post-quantum cryptography, and the first step is to understand what standards are currently in place. The BigFix Quantum Risk Analyzer scanner can help all organizations - federal and commercial - to easily generate a comprehensive inventory of cryptographic systems and identify weak ciphers and vulnerabilities.
- Government agencies
- Defense contractors
- Commercial enterprises
- Critical infrastructure providers
- Defense Industrial Base (DIB)
Does the BigFix Quantum Risk Analyzer scanner meet all the requirements established by OMB, NIST, CISA, and others?
The BigFix Quantum Risk Analyzer scanner is designed to comprehensively address federal cryptographic inventory and assessment requirements.
- OMB M-23-02 Compliance
- NIST 1800-38B Alignment
- NSM 10 Requirements
- CISA Cybersecurity Guidance
Technical Capabilities
How does the BigFix Quantum Risk Analyzer scanner work?
The scanner is a discovery and risk classification solution based on the fast-moving and daunting cryptographic space. It parses the complexity of algorithms and their implementations into discrete components, analyzing each step in the process, pinpointing the most urgent risks.
Why is it important to use an endpoint-centric cryptographic inventory toolset vs a network-only scanner?
Network-only monitoring solutions cannot effectively track enterprise-wide operations because they do not detect cryptographic operations that occur locally on endpoints. Without endpoint visibility, organizations only see encrypted data traversing the network, missing crucial information about the encryption process and implementation.
Critical Insight: On-device discovery captures both cryptography in use, and just as important: cryptography available for use. Bad ciphers must be found and removed from the system. Once they are used on the network, it is often too late to stop the negative impact.
Does the scanner provide both endpoint and network device cryptographic inventory?
Yes. The scanner's lightweight endpoint scripts deliver network-based information, but also continuous visibility regardless of location, ensuring that organizations maintain oversight of their cryptographic assets and operations.
What datasets does the scanner deliver?
| Category | Dataset | Description |
|---|---|---|
| General | Host OS Info | Device Guard, Trusted Platform Module (TPM), UEFI Settings |
| Quantum Readiness | PQC Client TLS Protocols | Data Protocols Used to Originate a Client Session |
| PQC Discovered Cipher | Method to Transform Plaintext to Cipher Text | |
| PQC Listening Port Certificate | Attributes of Application Certificates | |
| PQC System Certificates | Certificates Used to Verify Secure Connections | |
| Network Data | Network PQC Discovered Ciphers | TLS Cipher Data in Network Packets |
| Non-TLS Protocol Discovery | Protocols such as SSH, S/MIME and VPNs | |
| Network PQC Listening Port Certificate | Certificate Data in Network Packets |
Integration & Deployment
How does the scanner provide visualization of the cryptographic inventory?
BigFix Quantum Risk Analyzer includes BigFix Web Reports for inventory and risk assessment, and pre-built dashboards for Splunk and Elastic integrations.
Can BigFix Quantum Risk Analyzer also perform remediation and migration to new quantum-resistant algorithms?
Yes. Because BigFix Quantum Risk Analyzer is integrated within BigFix itself, you can use and create content to remediate and migrate to quantum-resistant algorithms.
Does the scanner work with Splunk and Elastic?
Yes. The scanner integrates seamlessly with both Splunk and Elastic platforms. Pre-built dashboard content packs are available for both platforms. Note that you need to bring your own license (BYOL) for these platforms.
Does the scanner support other big data platforms, business intelligence tools, or SIEMs?
Yes. The scanner supports a wide range of enterprise platforms including:
SIEM Platforms:
- IBM QRadar
- LogRhythm
- Splunk Enterprise
Data Platforms:
- Elasticsearch
- Amazon OpenSearch
- Datadog
- Snowflake
Does the scanner work with any providers of quantum-resistant algorithms and solutions?
Yes. The scanner offers integrations with companies like SafeLogic and Qrypt to provide end-to-end cryptographic solutions.