Skip to main content

Define discovery scope and sources of truth

Trust Architecture Playbook: Baseline pillar

Practical source-of-truth hierarchy

When pulling certificate data from multiple sources there can be conflicting results, not as a failure of the process, but as an expected byproduct of comprehensive discovery. The key is having a defined hierarchy, so your team isn't wasting time debating which source to trust.

Establish a consistent precedence order and apply it uniformly. A reliable starting point is to trust issuing CA records first, followed by platform connectors, network scans, system scans, and CT monitoring as a final layer. Higher-fidelity sources rank higher — a connector talking directly to a platform knows more than a network scanner inferring from a handshake. That ordering cuts through the noise and keeps triage fast when something needs immediate attention.

Suggerimento

Best practice

Do not depend on any single discovery method, require coverage from at least two complementary sources.