Cryptographic risk indicators

  • Release version: Australia
  • Updated December 19, 2024
  • 1 minute to read
  • Risk indicators highlight cryptographic assets that need attention so you can prioritize remediation and track compliance.

    Cryptographic Asset Compliance evaluates assets against policies and raises a risk indicator when an asset meets a risk condition. Risk indicators are based on policies, and each indicator points to a specific weakness, such as a weak algorithm or a missing owner. For more information, see About Policy as Code Engine policies. For more information about risk detection criteria, see Risk indicator definitions.

    Supported risk indicators

    For certificates:

    • Weak algorithm: Uses a deprecated or quantum-vulnerable algorithm.
    • Trusted CA risk: Issued by an untrusted or unrecognized certificate authority. For more information, see Configure trusted certificate authorities.
    • No owner: Has no assigned owner or responsible party.
    • No environment: Is not classified by environment.
    • No renewal process: Has no defined renewal workflow.

    For AWS KMS keys and Azure Key Vault keys:

    • Weak algorithm: Uses a weak or insufficient algorithm or key size.
    • Not PQC ready: Does not use a post-quantum-safe algorithm.
    • Not rotated (AWS KMS keys): Has not been rotated within the recommended period.
    • Pending deletion (AWS KMS keys): Is scheduled for deletion.
    • Expired (Azure Key Vault keys): Is expired or lacks a proper expiration date.

    Risk levels

    Each asset is assigned an overall risk level, calculated from its active indicators. The available risk levels are:

    • Critical: Severe vulnerabilities requiring immediate attention.
    • High: Significant weaknesses that should be addressed promptly.
    • Medium: Moderate concerns that require monitoring and planning.
    • Protected: Quantum-safe, or no active risk indicators.