🔒 Quantum-Ready: Securing the Future 🚀 - Navigating Post-Quantum Cryptography Challenges with CISA, NSA, and NIST 🌐
The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the National Institute of Standards and Technology (NIST) collaborated to create a factsheet addressing the potential impacts of quantum capabilities on organizations, particularly those supporting Critical Infrastructure.
The document emphasizes the importance of early planning for migration to post-quantum cryptographic standards and the development of a Quantum-Readiness Roadmap.
NIST aims to release the first set of post-quantum cryptographic standards in 2024 to guard against the threat of cryptanalytically-relevant quantum computers that could compromise current public-key systems.
The advisory stresses the need for organizations to initiate preparations by crafting quantum-readiness roadmaps, conducting inventories, applying risk assessments, and engaging with vendors.
The early planning is deemed essential due to the possibility of cyber threat actors targeting data today that may require protection in the future. The migration involves updating or replacing cryptographic products, protocols, and services that rely on vulnerable public key algorithms with quantum-resistant alternatives, such as Rivest-Shamir-Adleman (RSA), Elliptic Curve Diffie-Hellman (ECDH), and Elliptic Curve Digital Signature Algorithm (ECDSA).
Organizations are encouraged to proactively collaborate with vendors, implement thoughtful measures, and reduce risks posed by potential cryptanalytically-relevant quantum computers.
Source: https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF