Skip to main content

Prioritize and respond to cryptographic policy violations

Identify the cryptographic policy violations that pose the greatest risk, investigate why each asset failed, and decide whether to remediate or formally accept the finding.

DigiCert​​®​​ Quantum Central creates a violation automatically when an asset matches the criteria of an active policy. Each violation connects one asset to one policy and inherits the policy’s severity. You cannot create violations manually.

Find violations that need attention

From the Quantum Central menu, select Violations.

The summary cards at the top of the page help you understand the scale and urgency of your findings:

  • Total Open shows the number of open violations and the number of distinct affected assets. One asset can violate several policies.

  • Critical & High shows the open violations classified as requiring the most urgent attention.

  • Resolved shows the number of closed violations.

Use the Open and Closed tabs to switch between current findings and historical resolution records.

In the lower part of the page, the violations list shows the affected asset, policy, severity, detection time, current status, and any linked remediation task. Search by violation, asset, or policy, and use the policy and status filters to narrow the results. Export the filtered records for audit or compliance review.

On the Open tab, switch between the following views:

  • List shows each violation separately.

  • By asset groups the open violations affecting the same asset.

Use these capabilities to focus your response:

  • Start with Critical and High violations, but also consider the asset’s business importance, environment, exposure, and expected lifetime.

  • Use By asset to identify assets with multiple violations. Remediating one asset might address several cryptographic issues.

  • Filter by policy to organize work around a particular standard, such as minimum key strength, deprecated TLS configurations, or quantum readiness.

  • Filter by status to separate new findings from those already being assessed or remediated.

  • Review the Task column to identify violations that already have remediation work underway.

Severity is inherited from the policy and cannot be changed on an individual violation. For information about defining severity, see Define cryptographic policies.

Investigate why an asset failed

On the Open tab, select the view icon for a violation to open its details panel.

The panel shows the violation’s severity, current status, associated policy, affected asset, asset type, and first-detected time.

Select View policy evaluation to see which policy conditions the asset failed. For a policy with several parameters or criteria groups, review the complete evaluation before deciding how to respond.

When investigating a violation, consider:

  • Whether the affected asset is still active and within the intended scope of the policy.

  • The security or compliance risk created by the failed conditions.

  • Whether the asset has compensating controls.

  • Whether the asset can be remediated immediately or requires planned work.

  • Whether the asset is already scheduled for replacement or retirement.

Use comments to record your assessment, relevant context, ownership, and decisions. These comments become part of the violation’s audit history.

Quantum Central maintains no more than one open violation for each asset and policy combination. If a later evaluation finds that the asset still fails the policy, the existing violation remains open. If different conditions are now failing, Quantum Central updates the evaluation details instead of creating a duplicate violation.

Choose how to respond

After investigating a violation, record the appropriate response.

Situation

Action

The violation has not been assessed

Leave the status as Open.

More assessment is needed

In the details panel, change the status to In review and add relevant context.

The asset must be fixed

In the details panel, change the status to Remediating. Create a task if the work must be assigned and tracked in a connected system, like Jira.

No remediation will be performed

Document the decision in a comment. Then open the violation’s action menu and select Mark resolved.

The Status dropdown in the details panel includes Open, In review, and Remediating. You can move a violation between these statuses as its circumstances change.

Status communicates triage progress only. It does not determine whether the asset passes the policy or close the violation.

Coordinate remediation

If the underlying asset must be corrected, open the violation’s action menu and select Create task.

Nota

To create remediation tasks, first connect Quantum Central to a supported ticketing system, like Jira. For instructions related to integrations, see Set up Quantum Central integrations.

The task includes context such as the violation’s severity, policy, failed conditions, and affected asset. After the task is created, its link appears with the violation and the task becomes available on the Tracking page.

A violation can have one active remediation task. The task and violation have independent lifecycles:

  • Completing the task in the connected system does not close the violation.

  • Resolving the violation does not complete or close the task in the connected system.

For information about monitoring the task, see Track cryptographic remediation tasks.

Record an accepted risk or other manual decision

When a human decision rather than a technical change should close the violation, add a comment explaining the decision. Then open the violation’s action menu and select Mark resolved.

Use manual resolution for situations such as an accepted risk, a false positive, a nonessential asset, or an asset approaching retirement.

Document the reason, relevant approval, compensating controls, or expected retirement date before resolving the violation.

Manual resolution is final for that violation. Quantum Central does not reverify, reopen, or reclassify the closed record.

Syncing unchanged asset data does not trigger another evaluation. If an asset or policy change triggers a later evaluation and the asset fails the same policy, Quantum Central creates a new violation.

Review resolution history

Use the Closed tab to review completed violation records.

Each closed violation shows how it was resolved in the Resolution field:

  • Automated indicates that Quantum Central verified that the asset passes the policy.

  • Manual indicates that a user marked the violation as resolved.

Closed violations are read-only. You cannot change their status, add comments, or reopen them.

Use the resolution filter to distinguish verified remediation from manual decisions.