information-security9 min read

Quantum Computing Implications for Security

Understand how quantum computing will affect information security and cryptography. Forward-looking CISA exam preparation topic.

CISAPractice|

Quantum Computing and Information Security

Quantum computing represents a fundamental shift in computing capability that has profound implications for information security. For CISA candidates, understanding quantum computing's impact on security is important because organizations must begin preparing now for a future where current cryptographic protections may be vulnerable.

How Quantum Computing Differs

Quantum computers use quantum mechanical phenomena to process information in ways that classical computers cannot:

  • Qubits: Unlike classical bits that are either 0 or 1, quantum bits (qubits) can exist in multiple states simultaneously through a property called superposition. This enables quantum computers to explore many solutions in parallel.
  • Entanglement: Qubits can be entangled, meaning the state of one qubit is correlated with the state of another. This enables certain calculations to be performed exponentially faster than on classical computers.
  • Quantum advantage: For specific types of problems, quantum computers can provide solutions dramatically faster than classical computers. This includes certain optimization problems, simulation tasks, and critically for security, breaking certain cryptographic algorithms.

Impact on Cryptography

Quantum computing threatens several widely used cryptographic systems:

  • RSA and ECC: Shor's algorithm, when run on a sufficiently powerful quantum computer, can factor large numbers and solve discrete logarithm problems efficiently. This would break RSA and elliptic curve cryptography (ECC), which underpin most current public key infrastructure.
  • Symmetric encryption: Grover's algorithm provides a quadratic speedup for brute-force searches, effectively halving the security strength of symmetric encryption. AES-256 would provide roughly 128-bit security against quantum attacks, which is still considered adequate.
  • Hash functions: Quantum computing reduces the security of hash functions but does not completely break them. Larger hash outputs may be needed to maintain security margins.

The Harvest Now, Decrypt Later Threat

A significant concern is that adversaries may be collecting encrypted data today with the intention of decrypting it when quantum computers become available. This "harvest now, decrypt later" strategy means that data with long-term confidentiality requirements is already at risk, even before quantum computers exist.

Post-Quantum Cryptography

Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist quantum attacks. NIST has been leading a standardization process for PQC algorithms based on mathematical problems that quantum computers cannot efficiently solve, such as lattice-based problems, hash-based signatures, code-based cryptography, and multivariate polynomial equations.

Preparing for the Quantum Transition

Organizations should begin preparing for the quantum transition by conducting a cryptographic inventory to identify where vulnerable algorithms are used, prioritizing systems that protect long-lived sensitive data, developing a migration roadmap for transitioning to quantum-resistant algorithms, implementing crypto-agility so systems can switch algorithms without major redesign, and monitoring developments in both quantum computing capability and post-quantum cryptography standards.

Audit Implications

IS auditors should evaluate whether the organization has assessed its exposure to quantum threats, whether a cryptographic inventory exists, whether plans are in place for transitioning to quantum-resistant cryptography, and whether data with long-term confidentiality requirements receives appropriate protection.

CISA Exam Relevance

While quantum computing is an emerging topic, CISA candidates should understand the basic threat it poses to current cryptography and the concept of post-quantum cryptography. Questions may address the auditor's role in evaluating organizational preparedness for quantum threats.

Related Tags

Information SecurityQuantum ComputingCISA ExamCryptographyPost-Quantum

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free