Part I lays the groundwork for understanding cryptographic governance. It explains the basic concepts-certificates, keys, secrets-and how they form the trust fabric that secures modern digital systems. It introduces the idea of lifecycle governance, showing that cryptographic assets must be controlled from creation to destruction. It also explains the regulatory context (DORA, NIS2, ISO 27001, and critical infrastructure norms) and the PDCA framework that underpins compliance.
This part prepares the reader to understand why poor cryptographic governance leads to outages, security incidents and regulatory failures. It sets the foundational language, definitions and responsibilities that the rest of the book builds upon.
Chapter 1 - Why Cryptographic Governance Determines Operational Resilience