Contents
Who certifies FIPS 140-2?
the NIST
The Federal Information Processing Standard (FIPS) Publication 140-2 (FIPS PUB 140-2), commonly referred as FIPS 140-2, is a US government computer security standard used to validate cryptographic modules. FIPS 140-2 was created by the NIST and, per the FISMA, is mandatory for US and Canadian government procurements.
What are FIPS levels?
The FIPS certification standard defines four increasing, qualitative levels of security: Level 1: Requires production-grade equipment and externally tested algorithms. Level 2: Adds requirements for physical tamper-evidence and role-based authentication.
What is the difference between FIPS 140-2 Level2 and Level3?
Level 2: Requires physical tamper-evidence and role-based authentication for hardware. Software is required to run on an Operating System (OS) approved to Common Criteria (CC) at Evaluation Assurance Level 2 (EAL2). Level 3: Hardware must feature physical tamper-resistance and identity-based authentication.
Is FIPS 140-2 still valid?
FIPS 140-2 testing is still available until September 21, 2021 (later changed for applications already in progress to April 1, 2022) , creating an overlapping transition period of more than one year.
What are the 4 levels of FIPS?
FIPS 140-2 is a standard which handles cryptographic modules and the ones that organizations use to encrypt data-at-rest and data-in-motion. FIPS 140-2 has 4 levels of security, with level 1 being the least secure, and level 4 being the most secure: FIPS 140-2 Level 1- Level 1 has the simplest requirements.
What are FIPS requirements?
To be FIPS compliant, an organization must adhere to the various data security and computer system standards outlined in the Federal Information Processing Standards (FIPS). FISMA requires United States federal government agencies reduce information technology risk to an acceptable level at a reasonable cost.
How long is FIPS certification?
6-9 months
To become FIPS validated, detailed documentation and source code must be sent to NIST’s testing laboratory, a process which typically takes 6-9 months on average.
What is a FIPS 140-2 certificate?
The Federal Information Processing Standard 140-2 (FIPS 140-2) is an information technology security accreditation program for validating that the cryptographic modules produced by private sector companies meet well-defined security standards.
When does testing of FIPS 140-2 modules end?
Planning Note (3/22/2019): Testing of cryptographic modules against FIPS 140-2 will end on September 22, 2021. See FIPS 140-3 Development for more details.
What is the Federal Information Processing Standard ( FIPS )?
FIPS is based on Section 5131 of the Information Technology Management Reform Act of 1996. It defines the minimum security requirements for cryptographic modules in IT products.
What’s the difference between FIPS certified and FIPS compliant?
FIPS is one such standard. There’s a lot of talk of FIPS amongst cybersecurity vendors, and you’ll hear terms like FIPS certified and FIPS compliant. There’s a distinct difference between the two, and we explain more in this article.
What is the purpose of the FIPS 140-2 security label?
Tamper evident FIPS 140-2 security labels are utilized to deter and detect tampering of modules. Laboratories doing the testing All of the tests under the CMVP are handled by third-party laboratories that are accredited as Cryptographic Module Testing laboratories by the National Voluntary Laboratory Accreditation Program (NVLAP).