A city discovers dozens of TLS certificates for public portals with no inventory, no owner, and no scheduled rotation. Which cryptographic lifecycle action should the security architect prioritize first?
Select an answer to reveal the explanation.
Short Explanation
Crypto without an inventory is like locking doors and losing the key list—you cannot rotate what you cannot find. Start by cataloging certificates and keys, naming owners, and putting renewals on a calendar. That lifecycle hygiene beats random one-off replacements.
Full Explanation
Cryptographic lifecycle management covers generation, distribution, storage, use, rotation, revocation, and destruction of keys and certificates. Without inventory and ownership, expirations, orphaned keys, and weak algorithms go unnoticed. Establishing an authoritative inventory and rotation process is the foundational control before selective algorithm upgrades or vendor changes.