Skip to main content
When Automated Scanners Miss Your Cryptographic AssetsTechnical Security Controls
3 min readFor External Auditors and Assessors

When Automated Scanners Miss Your Cryptographic Assets

The Hidden Challenge

Your team might think automated cryptographic discovery tools can provide a complete inventory of your cryptographic assets. However, a compliance team recently discovered that relying solely on these tools can leave significant gaps. They found entire legacy systems and custom-built implementations missing from their automated scans. This oversight forced them to rebuild their migration roadmap, extend timelines, and renegotiate budgets. While no breach occurred, the incident highlighted a critical issue: assuming complete visibility when your inventory is incomplete.

Timeline of Events

Initial Phase: The team deployed automated tools to generate a cryptographic bill of materials (CBOM). Leadership approved a migration plan based on this inventory.

Migration Begins: The focus was on external systems and data-in-transit encryption. Automated tools were used extensively here.

Discovery of Gaps: Engineers found operational technology systems, legacy platforms, and custom implementations that weren't in the original inventory. These systems were beyond the reach of automated scanners.

Remediation: The team conducted manual discovery, updated the CBOM, revised the roadmap, and implemented a continuous discovery process combining automation with expert review.

Identifying Control Failures

The issue wasn't with the tools but with the asset management scope and validation. The team assumed the automated output was complete without identifying blind spots or validating the inventory.

Key Failures:

  • No baseline for cryptographic asset types: The team didn't identify systems using cryptography before deploying tools. Legacy systems and custom implementations weren't flagged as blind spots.

  • No expert review of automated output: The CBOM was accepted without expert validation. No one questioned what the scanner might miss.

  • No continuous discovery process: CBOM generation was treated as a one-time task. Continuous discovery and inventory updates were neglected.

  • No risk management for incomplete data: Assumptions and limitations weren't documented. The migration plan was built on incomplete visibility.

Standards and Requirements

ISO/IEC 27001:2022 Annex A Control 5.9

This control mandates identifying and maintaining an inventory of assets associated with information processing. For cryptographic assets, this includes:

  • Identifying systems and data flows using cryptography
  • Maintaining an up-to-date inventory
  • Defining ownership and classification

Automation isn't required, but completeness is. Missing legacy systems or custom implementations means non-compliance.

ISO/IEC 27001:2022 Annex A Control 8.24

This control requires rules for cryptography use, including key management. Knowing where cryptography is deployed is essential for compliance.

SOC 2 Common Criteria CC6.1

This criterion focuses on restricting access to system resources. Cryptographic controls often serve this purpose. A complete inventory is necessary to assert coverage.

SOC 2 Common Criteria CC7.2

This criterion requires monitoring system components. Without a validated inventory, monitoring scope is incomplete, raising questions during audits.

Actionable Steps for Your Team

1. Catalog Cryptographic Asset Types

Before using scanning tools, document systems using cryptography: external applications, internal APIs, databases, legacy platforms, OT systems, and custom tools. This helps evaluate tool effectiveness.

Action: Create a taxonomy of cryptographic assets. Note which require manual documentation.

2. Treat Automated CBOM as a Draft

Automated tools lack judgment. Have experts review the output for missing elements and custom implementations.

Action: Implement a review step with experts to validate CBOM output. Document blind spots and assumptions.

3. Implement Continuous Discovery

Your inventory changes with system updates. A static CBOM quickly becomes outdated.

Action: Schedule regular CBOM updates. Integrate discovery with change management to capture new deployments.

4. Document Blind Spots in Risk Management

If legacy systems or OT environments aren't covered by scanners, document these gaps and manage them.

Action: Maintain a risk register for inventory gaps. Document risks, mitigation strategies, and timelines.

5. Prioritize Automation for External Assets

Automated tools are most effective on systems with network exposure. Start with external assets and encrypted data flows.

Action: Segment your CBOM program. Use automation for external systems, manual discovery for others.

6. Align CBOM with Audit Scope

For SOC 2 or ISO/IEC 27001 compliance, ensure your inventory covers audit scope systems. Work with auditors to define necessary assets and completeness criteria.

Action: Confirm audit scope with assessors and demonstrate inventory completeness for those systems.

Automation provides scale, but not completeness. Reliable CBOMs require combining automated discovery with expert review, documenting blind spots, and treating cryptographic inventory as an ongoing control.

You Might Also Like