<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Certification ROI Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/certification-roi/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/certification-roi/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 11 Mar 2024 19:44:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Certification ROI Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/certification-roi/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Teradici Achieves IUT Listing</title>
		<link>https://sitdev.corsec.com/teradici-iut/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 21 Feb 2020 20:35:45 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=18491</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, <span style="color: #3366ff;"><a style="color: #3366ff;" href="http://www.teradici.com">Teradici Corporation</a></span>, for achieving the Implementation Under Test (IUT) phase of the Federal Information Processing Standard 140-2 (<span class="s1" style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span>) validation process for their PCoIP Zero Client product.</p>
<p>To see Teradici&#8217;s full announcement, please visit this <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.teradici.com/resource-center/latest-news/2020/02/21/teradici-pcoip-zero-client-reaches-implementation-under-test-phase-of-nist-s-fips-140-2-government-validation">link</a></span>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About FIPS 140-2</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS, which is mandated by law in the U.S. and very strictly enforced in Canada, is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About </strong><strong>Teradici Corporation</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Teradici is the creator of the PCoIP® remoting protocol technology and Cloud Access Software. The company’s core mission is seamless and secure delivery of workstations and applications for end users. Teradici PCoIP technology and Cloud Access Software offer the most secure remoting solutions for public, private, and multicloud environments, enabling visualization of even the most graphics-intensive applications. The company’s solutions are deployed by Fortune 500 enterprises, government agencies, and service providers around the world.</p>
<p>For further information, please visit <a href="http://www.teradici.com/">www.teradici.com</a></p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <a href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe">Subscribe</a></p>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Certes CFNC Achieves Common Criteria</title>
		<link>https://sitdev.corsec.com/certes-cnfc-cc/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 15 Apr 2019 16:06:59 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Customers]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17790</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Certes Networks, Inc. (Certes), for completing the <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) certification process on their CryptoFlow Net Creator (CFNC) with CEP.</p>
<p>To achieve this milestone, Certes partnered with Corsec, completing the certification under the Italian scheme at an EAL4+. For more information on the validation and to find additional details on the CFNC certification, visit the <a href="https://www.commoncriteriaportal.org/products/">CC Certified Products List</a>.</p>
<p>Their completion of the <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> certification process demonstrates their commitment to strong levels of security, including a government backed product offering and a dedication to providing customers and end users with the most scrutinized and highly tested security solutions.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About Common Criteria</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p class="p1"><span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) is an internationally recognized set of guidelines (ISO 15408), which define a common framework for evaluating security features and capabilities of Information Technology security products. The standard consists of several predetermined evaluation assurance levels, each one more stringent than the last. Common Criteria allows vendors to have their products tested against a chosen level by an independent third-party testing laboratory. The Common Criteria Mutual Recognition Agreement (CCRA) is a pact, which was designed to allow all evaluations up to an evaluation assurance level (EAL) 2, to be recognized by all participating countries, regardless of where the evaluation was completed. There are currently 30 countries involved in the CCRA, including the United States and Canada, with others that follow unofficially such as the EU.</p>
<p class="p1">The U.S. government mandates Common Criteria certification of security products for federal purchases. The National Information Assurance Acquisition Policy, NSTISSP No. 11, requires agencies to purchase only those commercial security products that have met specified third-party assurance requirements and have been tested by an accredited national laboratory.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper"></div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>About the Certes CFNC and CEP</strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>CryptoFlow Net Solutions enable you to set automatic traffic protection policies on any standards-based network, including LAN, WAN, WiFi, Internet, SDN/NFV and others.</p>
<p>CryptoFlow Net Creator is the management solution providing centralized policy definition and control over all CryptoFlow Net Enforcers. CryptoFlow Net Creator enables all keys for all network protection to be generated and managed from one central point of control. It is a web-based GUI that configures and monitors the Certes Enforcement Points (CEP) encryption appliances, stores and deploys policies (or rules), and provides key management and auditing capabilities. CEPs are purpose-built encryption appliances that provide multi-layer data protection and application segmentation.</p>
<h5><strong>About Corsec Security, Inc.</strong></h5>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <a href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HPE Smart Array Gen10 P-Class RAID Controllers</title>
		<link>https://sitdev.corsec.com/hpe-raid-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 14 Mar 2019 20:49:29 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17811</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec would like to congratulate the entire HPE Smart Array team on completing the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process. The completion of the certification process not only opens the doors to new and exciting markets for HPE, but also demonstrates their fervent commitment to product security.</p>
<p>To achieve this milestone, HPE partnered with Corsec, completing the validation at a Level 1 as seen in certificate #<span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3397">3397</a></span>. For more information on the validation and to find additional details on the security policy, visit <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3397">NIST’s validated modules site</a></span>.</p>
<p>Their completion of the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process demonstrates their commitment to strong levels of security, including a government backed product offering and a dedication to providing customers and end users with the most scrutinized and highly tested security solutions.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p class="p2" style="text-align: left;"><strong><span class="s2">About FIPS 140-2</span></strong></p>
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS, which is mandated by law in the U.S. and very strictly enforced in Canada, is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>About Corsec Security, Inc.</strong></p>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span></strong>, <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED ROUNDUP: FEBRUARY 2019</title>
		<link>https://sitdev.corsec.com/fed-feb19/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 26 Feb 2019 16:09:41 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16953</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: left;"><span style="color: #000000;"><strong><a style="color: #000000;" href="http://sitdev.disa.mil/newsandevents">DISA’s February News</a></strong></span></h5>
<ul>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/Adobe_data_impact_level_4"><span style="color: #0000ff;">DISA grants Provisional Authorization (PA) with conditions to the Adobe Experience Manager for Managed Services (AEMMS) at data Impact Level 4</span></a></li>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/Cloud_Services_data_impact_level_5"><span style="color: #0000ff;">DISA grants Provisional Authorization (PA) with conditions to PTC Cloud Services at data Impact Level 5</span></a></li>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/5_JRSS_concerns_addressed"><span style="color: #0000ff;">DISA addresses 5 mission partner concerns regarding Joint Regional Security Stacks (JRSS)</span></a></li>
</ul>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST’s February News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #0000ff;"><span style="color: #0000ff;">None</span></span></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2019/stateful-hbs-request-for-public-comments"><span style="color: #0000ff;"><span style="color: #0000ff;">Requests for Public Comments on &#8220;Stateful Hash-Based Signatures (HBS)&#8221;</span></span></a></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2019/draft-nist-sp-800-205-available-for-comment">Draft NIST Special Publication 800-205, &#8220;Attribute Considerations for Access Control Systems&#8221;</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2019/NIST-Updates-SP-800-162">Updates to Special Publication 800-162, &#8220;Guide to Attribute Based Access Control (ABAC) Definition and Considerations&#8221;</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/publications/detail/sp/800-177/rev-1/final">Special Publication 800-177, Rev. 1, &#8220;Trustworthy Email&#8221;</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s February News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><span style="color: #0000ff;">None</span></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<p><a href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm"><span style="color: #0000ff;">The Full Drive Encryption (FDE) international Technical Community (iTC) has published the following:</span></a></p>
<ul>
<li><span style="color: #0000ff;">FDE Encryption Engine (EE) Collaborative Protection Profile (cPP) v2.0</span></li>
<li><span style="color: #0000ff;">FDE EE Supporting Document (SD) v2.0</span></li>
<li><span style="color: #0000ff;">FDE Authorization Acquisition (AA) cPP v2.0</span></li>
<li><span style="color: #0000ff;">FDE AA SD v2.0</span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Virtual Instruments Completes Common Criteria Certification for FED &#038; Regulated Industries</title>
		<link>https://sitdev.corsec.com/vi-cc/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 08 Feb 2019 16:35:07 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Customers]]></category>
		<category><![CDATA[CCRA]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16912</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p class="p1"><span class="s1">Corsec would like to congratulate our partner Virtual Instruments, </span>a leader in hybrid infrastructure management that delivers solutions that help customers ensure their applications and infrastructure perform better together, on announcing that its VirtualWisdom Platform Appliance v5.7 has completed the Common Criteria certification process.</p>
<p>The <a href="https://www.virtana.com/products/virtualwisdom/">VirtualWisdom Platform Appliance</a> is a is an IPM appliance that holistically monitors, analyzes and optimizes the health, utilization, capacity and performance of IT infrastructure within the context of the application; the completion of the Common Criteria certification under the NIAP approved collaborative Protection Profile for Network Devices (NDcPP) gives governments and end users confidence that the VirtualWisdom Platform Appliance has passed strenuous documentation and testing requirements.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>About Common Criteria</strong></h5>
<p class="p1">Common Criteria is an internationally recognized set of guidelines (ISO 15408), which define a common framework for evaluating security features and capabilities of Information Technology security products. The standard consists of several predetermined evaluation assurance levels, each one more stringent than the last. Common Criteria allows vendors to have their products tested against a chosen level by an independent third-party testing laboratory. The Common Criteria Mutual Recognition Agreement (CCRA) is a pact, which was designed to allow all evaluations up to an evaluation assurance level (EAL) 2, to be recognized by all participating countries, regardless of where the evaluation was completed. There are currently 28 countries involved in the CCRA, including the United States and Canada, with others that follow unofficially such as the EU.</p>
<p class="p1">The U.S. government mandates Common Criteria certification of security products for federal purchases. The National Information Assurance Acquisition Policy, NSTISSP No. 11, requires agencies to purchase only those commercial security products that have met specified third-party assurance requirements and have been tested by an accredited national laboratory.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>About Virtual Instruments</strong></h5>
<p>Virtual Instruments is an exciting, high-growth Silicon Valley technology company.  Since their founding in 2008, they have been focused on delivering unparalleled value to our customers through a combination of innovative technology and high-value services. The VirtualWisdom platform provides comprehensive visibility into the performance, health and utilization of the IT infrastructure, empowering customers to guarantee the performance of their mission-critical applications across physical, virtual and cloud computing environments.</p>
<p>For further information, please visit <a href="http://virtualinstruments.com">virtualinstruments.com</a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>About Corsec Security, Inc.</strong></h5>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED IT Spending: Reviewing 2018 &#038; Gauging 2019</title>
		<link>https://sitdev.corsec.com/2018-review/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 12 Oct 2018 17:48:11 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[federal spending]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[IT spending]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16659</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>2018 FEDERAL YEAR IN REVIEW</strong></h4>
<p>2018 was a stellar year for companies doing business with U.S. Federal Agencies. Over <strong>$95.6 billion dollars</strong> were allocated towards the procurement of secured IT products and solutions across Civilian, DoD, and the IC agencies.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>2018 DoD IT Spend |</b> $35.7 billion</h5>
<p>$42.5 billion originally allocated &#8211; not all spending has been recorded*</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>2018 Civilian IT Spend |</b> $45.5 billion</h5>
<p>$53.1 billion originally allocated &#8211; not all spending has been recorded*</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Top 5 Agencies</b>: Predicted % of Total Spend*</h5>
<p>DoD: ~44.4%<br />
HHS: ~14.5%<br />
DHS: ~7.1%<br />
Treasury: ~4.5%<br />
VA: ~4.3%</p>
<p>*Data based on 2018 White House and OMB projected and released findings.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Modernization</b>: Improving the U.S. Critical Infrastructure</h5>
<p>According to the President and OMB&#8217;s release on Information Technology, &#8220;The Administration will work to modernize and improve government operations and service delivery by building modern citizen-facing digital services, buying more like a business, improving cybersecurity, investing in improved data analytics, and generating greater cost efficiencies.&#8221;</p>
<p>This further emphasizes the President&#8217;s focus on improving the homeland&#8217;s IT support system. In May of 2017, he signed an <a href="https://sitdev.corsec.com/cybersecurity-executive-order/">Executive Order</a> to modernize and strengthen our technology infrastructure.</p>
<p>Additional information on the current status of the modernization effort can be found <a href="https://sitdev.corsec.com/federal-modernization/">here</a>.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>2019 FEDERAL OUTLOOK</strong></h4>
<p>The President of the U.S. recently signed the Department of Defense Appropriations Bill that provides over <strong>$674 billion dollars</strong> to fund military operations in 2019.</p>
<p>This is a $19.8-billion increase from the FY 2018.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Estimated 2019 DoD IT Spend |</b> $46.4 billion</h5>
<p>According to the Physical 2019 request, $36.4 billion will be allocated towards unclassified IT, $10 billion to classified, and $8.6 billion to cyberspace activities</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Estimated 2019 Civilian IT Spend |</b> $45.8 billion**</h5>
<p>This is a decrease from previous years, although the previous IT budget included grants made by Federal agencies to state and local governments for IT systems used to administer Federal benefits.</p>
<p>The FY 2019 budget includes funding and investments to support 3 main functions: 1.) mission delivery; 2.) IT infrastructure, IT security, and IT management; and 3.) administrative services and support systems.</p>
<p>**Data based on 2019 White House and OMB projected release.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>Connect With Us</strong></h4>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
</div>
<p style="text-align: center;">###</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.linkedin.com/in/jake-nelson-63601bb">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Just When You Thought It Was Safe To Shut Down Your Computer</title>
		<link>https://sitdev.corsec.com/just-when-you-thought-it-was-safe-to-shut-down-your-computer/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 25 Sep 2018 17:27:58 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[device security]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16213</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Although Cold Boot Attacks are considered to be somewhat of an antiquated method, largely due to the need for an attacker to have physical access to the machine, they still represent a threat to unprotected systems.</p>
<p>By definition, a Cold Boot Attack is a type of side channel attack in which an attacker with physical access to a computer is able to retrieve encryption keys from a running operating system after using a cold reboot to restart the machine. Known since 2008, these attacks target data memory remanences, sometimes containing sensitive and personal information, on a CPU&#8217;s RAM which can linger anywhere from a few seconds to a few minutes after power has been removed. By utilizing a removable disk, attackers are able to upload sensitive data and viola, you have a security breach.</p>
<p>Many modern systems have security countermeasures to prevent these types of attacks; by memory scrambling or encrypting RAM the ability to steal encryption keys is essentially eliminated, but a new threat could threaten most modern computers according to experts.</p>
<p>Researchers from F-Secure, a Finnish company, have found new methods to disable current cold boot attack firmware security measures. This attack still requires the physical access that previous cold boot attacks utilized, but the threat is still present. The company is positioned to release additional information on their findings at upcoming events and conferences.</p>
<p>In the meantime, companies looking to protect their data can look to modernize security functionality of their systems by following guidelines and requirements laid out within <a href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a>. The FIPS <a href="https://sitdev.corsec.com/fips-140-2/#theplayers">requirements for level 3</a> require, in addition to all security measures from level 1 and 2, identity-based authentication, physical security mechanisms for tamper detection and tamper response, and zeroization of keys to destroy this type of data. Implementing these changes helps to prevent cold boot attacks from ever occurring.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 style="text-align: left;"><strong>About Corsec Security, Inc.</strong></h5>
<p style="text-align: left;">For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><a href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>, <a href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a> (CC) and the <a href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 style="text-align: left;"><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p style="text-align: left;">Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
<div class="wpb_text_column wpb_content_element "></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HPE Smart Array &#038; Smart HBA Solutions Complete FIPS 140-2</title>
		<link>https://sitdev.corsec.com/hpe-fips-smart-array-hba/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 29 Jun 2018 18:34:27 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17780</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec would like to congratulate the entire HPE Smart Array team on completing the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process on the HPE Smart Array Gen9 P-Class RAID Controllers and HPE Gen9 Smart HBA H-Class Adapter.</p>
<p>Their completion of the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process demonstrates their commitment to strong levels of security, including a government backed product offering and a dedication to providing customers and end users with the most scrutinized and highly tested security solutions.</p>
<p>To achieve this milestone, HPE partnered with Corsec, completing the validation at a Level 1 as seen in certificate #<span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3206">3206</a></span>. For more information on the validation and to find additional details on the security policy, visit <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3397"><span style="color: #3366ff;">NIST’s validated modules site</span></a>.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a></span>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p class="p2" style="text-align: left;"><strong><span class="s2">About FIPS 140-2</span></strong></p>
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS, which is mandated by law in the U.S. and very strictly enforced in Canada, is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>About Corsec Security, Inc.</strong></p>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span></strong>, <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/uc-apl/"><strong>DoD’s APL</strong></a></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IoT Expansion Opens The Door to Vulnerabilities</title>
		<link>https://sitdev.corsec.com/iot-expansion-opens-door-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 11 Apr 2018 20:30:25 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=14205</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>The IoT expansion has been innovative, immersive, and impressive; revolutionizing modern day interactions and connectivity.</p>
<p>To meet this demand, companies are deploying products at rapid speed, while lowering prices to promote user adoption; leaving many in the security sector concerned about user data protection and proper product security hardening.</p>
<p>To address these concerns, The UK is taking a proactive approach, outlining a 13-point Code of Practice for manufactures, service providers, mobile application developers, and retailers to follow related to the IoT space &#8211; <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/686089/Secure_by_Design_Report_.pdf">“Secure by Design: Improving the Cyber Security of Consumer Internet of Things Report”</a>.</p>
<p>This concept may be new to the growing IoT space, but it is already the status quo for many products in Regulated Industries, as well as heavily mandated by Federal Governments around the globe. Their requirements for certifications like <a href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a>, <a href="https://sitdev.corsec.com/common-criteria/">Common Criteria</a>, and the <a href="https://sitdev.corsec.com/dodin-apl/">DoD’s APL </a>address these concerns; ensuring products protect sensitive data and implement proper security architecture frameworks prior to deployment and network integration.</p>
<p>For companies looking to analyze their current security strategy and implement sound product security certification practices, there is help. Corsec Security is the global leader in providing assistance in security certifications and product security hardening. With the largest staff of experts in the industry and a comprehensive end-to-end solution that includes assessment audits, documentation, testing, enterprise lab services, and strategic product roadmap planning, Corsec has helped secure more than <a href="https://sitdev.corsec.com/global-clients/">400 unique products</a> for hundreds of organizations on five continents over the last 20 years.</p>
<p>This guidance helps companies address security requirements for healthcare, financial services, critical infrastructure, national and international markets, and now IoT. Not only do they secure products, but also foster public trust and reap rewards for security investments, enabling you to overcome competitors in a market valued at over $3.5 trillion.</p>
<p>More on <a href="https://sitdev.corsec.com/turnkey-solution/#designengineering">Product Security Hardening</a></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong><a href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
<h5><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>
<hr />
<h5></h5>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS 140-2: Covering the Basics</title>
		<link>https://sitdev.corsec.com/fips-140-2-basics/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 15 Dec 2017 16:36:17 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=10964</guid>

					<description><![CDATA[What is FIPS 140-2? The Federal Information Processing Standard 140-2 (FIPS 140-2) is a U.S. and Canadian co-sponsored security standard for hardware, software, and firmware solutions. All products sold into the U.S. federal government are ... <p class="read-more-container"><a title="FIPS 140-2: Covering the Basics" class="read-more button" href="https://sitdev.corsec.com/fips-140-2-basics/#more-10964" aria-label="More on FIPS 140-2: Covering the Basics">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;"><strong>What is FIPS 140-2?</strong></span></p>
<p>The Federal Information Processing Standard 140-2 (<span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span>) is a U.S. and Canadian co-sponsored security standard for hardware, software, and firmware solutions.</p>
<p>All products sold into the U.S. federal government are required by law to complete FIPS 140-2 validation if they use cryptography in security systems that process Sensitive But Unclassified (SBU) information.</p>
<p><span style="color: #000000;"><strong>What are the different Levels of FIPS 140-2?</strong></span></p>
<p>There are four increasing, qualitative security levels for FIPS 140-2. Each one focuses on eleven functional areas of product security related to secure design and implementation. At each level, greater amounts of evidence and engineering are required of the vendor in order to show compliance with the standard. The eleven functional areas that must be addressed are:</p>
<ol>
<li>Cryptographic Module Specification</li>
<li>Module Ports and Interfaces</li>
<li>Roles, Services, and Authentication</li>
<li>Finite State Model</li>
<li>Physical Security</li>
<li>Operational Environment</li>
<li>Cryptographic Key Management</li>
<li>Electromagnetic Interference / Electromagnetic Compatibility (EMI/EMC)</li>
<li>Self-Tests</li>
<li>Design Assurance</li>
<li>Mitigation of Other Attacks</li>
</ol>
<p>In order to complete the validation process, all eleven sections must be addressed. The level at which you decide to validate your product will depend upon your objectives, customer requirements, and competitive landscape.</p>
<p><span style="color: #000000;"><strong>What sort of end users and customers are interested in FIPS 140-2?</strong></span></p>
<p>All end users looking for a high degree of security, assurance, and dependability within their security systems will seek products possessing a FIPS 140-2 validation. This is not only a product benefit, but mandated by industries and governments around the globe. Section 5131 of the Information Technology Management Reform Act of 1996 mandated the use of FIPS-validated products by all U.S. federal agencies.</p>
<p>Although FIPS is a U.S. and Canadian sponsored standard, it has been heavily adopted by foreign governments (including the European Union, South America, and Asia) and regulated industries (including the intelligence community, financial services, health care, critical infrastructure, the automotive industry, and the Internet of Things (IoT)) around the globe.</p>
<p><span style="color: #000000;"><strong>What is the relationship between NIST, FIPS 140-2, and Corsec?</strong></span></p>
<p>There are three key players in the FIPS 140-2 validation process:</p>
<ul>
<li>The National Institute of Standards and Technology’s (NIST) <a href="http://csrc.nist.gov/groups/STM/cmvp/">Cryptographic Module Validation Program</a> (CMVP), which sets information security mandates for products containing cryptography, and is ultimately responsible for issuing certificates;</li>
<li>Third-party laboratories, which are accredited by NVLAP, test products to ensure they adhere to FIPS 140-2 standards; and,</li>
<li>IT product vendors, who must ensure their products conform to the standard, and submit documentation to a third-party lab for testing.</li>
</ul>
<p>Corsec is a comprehensive product security company that helps vendors go through the hurdles of achieving their FIPS validation. We advocate on behalf of our partners to communicate directly with NIST and the labs to get their product through each stage of the FIPS process.</p>
<p><span style="color: #000000;"><strong>What other certifications should vendors be aware of?</strong></span></p>
<p>Depending on your organization’s market goals and objectives, there are a number of certifications and validations that a vendor should investigate:</p>
<p><span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/">Common Criteria</a></span> is an internationally recognized set of guidelines (ISO 15408), which define a common framework for evaluating security features and capabilities of Information Technology (IT) security products. Once completed, it provides assurance to buyers that the process of specification, implementation and evaluation for any certified computer security solution was conducted in a thorough and standard manner. Completing your Common Criteria evaluation allows you to sell your solutions to the U.S. Federal Government, International Governments, and other highly regulated industries around the globe. It is not only required for access to government markets, but also serves as a competitive differentiator.</p>
<p>The <span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/dodin-apl/">DoDIN APL</a></span> (Department of Defense Information Network Approved Products List) was created in 2011 by the Department of Defense to identify solutions that were trusted to address government security concerns. The DoDIN APL represents the agency’s master list of products available for purchase that are secure, trusted, and approved for deployment within the DoD’s technology infrastructure. Only those products listed will be considered for procurement by DoD contracting departments. It has been referred to by many names including: the UC APL (Unified Capabilities Approved Products List), JITC Testing, STIG testing, and others.</p>
<p><span style="color: #000000;"><strong>What is the process to complete FIPS 140-2 validation? How long does it take? Do you look at source code?</strong></span></p>
<p>There are five major stages that need to be addressed in order to complete a FIPS 140-2 validation:<span style="color: #3366ff;"> <u>Certification Strategy</u>, <u>Product Security Hardening</u>, <u>Documentation</u>, <u>Laboratory and Algorithm Testing</u></span>, and <span style="color: #3366ff;"><u>Government Review</u></span>. At each stage, there are a number of deliverables that need to be accomplished, all helping to streamline your project and ensure a smooth transition from one stage to the next. <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://sitdev.corsec.com/turnkey-solution/">View a complete list</a></span> of all the stages, deliverables, and key takeaways for your FIPS validation.</p>
<p>With a sound strategy, expert guidance, and FIPS experience, you can expect to complete your FIPS validation in around 12 to 14 months. This validation will remain valid for up to five years. Of course, every product is different and every company has varying levels of experience with the process, therefore the process <strong><u>could</u></strong> take much longer if not done correctly.</p>
<p>Source code is just one of the many things that is reviewed during your FIPS validation. That is why it is so important to work with a partner that protects your Intellectual Property (IP) and takes security seriously. Make sure to visit your partner’s site and evaluate the security measures they implement to ensure that your project and IP are safe. <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://sitdev.corsec.com/wp-content/uploads/Prospective-Client-Questionnaire.pdf">This guide</a></span> covers key questions you should ask of your partners to ensure your assets are protected.</p>
<p><span style="color: #000000;"><strong>How do software updates interplay with FIPS 140-2?</strong></span></p>
<p>The FIPS evaluation process is intended to review a product as it exists at a single point in time. Thus, the validation (and associated certificate) is specific to the software version or hardware model that underwent the testing. Any updates to that version or changes to that model will represent a different entity than what was tested; thus, it is not covered by the validation.</p>
<p>One of the primary goals of the <span style="color: #0000ff;">Certification Strategy stage </span>of the process is to determine a validation approach that will minimize these sorts of issues. With proper planning, selection of the correct boundaries and levels, and knowledge of the available validation maintenance options, strategies can be created that will maximize the life of <span style="text-decoration: line-through;">a</span> validation.</p>
<p><span style="color: #000000;"><strong>What sort of challenges or roadblocks are typically presented in a FIPS 140-2 validation?</strong></span></p>
<p>With any large endeavor, there are certain areas that present risk and could potentially derail your validation. Developing a strategy upfront will help to mitigate those risks down the road. With nearly twenty years of experience, Corsec has identified the common roadblocks at each of the five stages in the process:</p>
<p><span style="color: #3366ff;"><u>Certification Strategy</u>:</span> Lack of organizational alignment will hinder your ability to get your validation moving quickly and keep it on track throughout the lifecycle of the project. Additionally, you must have market intelligence on your competition and customer requirements prior to developing your strategy; otherwise you could take a path that limits ROI.</p>
<p><span style="color: #3366ff;"><u>Product Security Hardening</u>:</span> Limited experience and expertise with the FIPS requirements will hinder you from a design engineering perspective. The product must comply with requirements in all eleven sections in order to complete the process. Without this expertise, it will be difficult to design, develop, and test a product that will pass muster.</p>
<p><span style="color: #3366ff;"><u>Documentation</u>:</span> Both the government and labs, have very specific methods of preferred formatting for the submission documentation. If not done correctly, you could produce thousands of pages that actually makes the lab’s job more difficult, and ill-timed re-work could significantly delay your project, as well as your ability to begin seeing any ROI.</p>
<p><span style="color: #3366ff;"><u>Laboratory and Algorithm Testing</u>: </span>The lab will request certificates which you must produce from testing your algorithms. These test results are often fraught with challenges and misunderstanding. Having a system to run lab test vector files will expedite the process significantly.</p>
<p><span style="color: #3366ff;"><u>Government Revie</u><u>w</u>:</span> Knowledge on the standard will help avoid re-work/duplicative efforts when the government comes back with questions. Defense of your documentation and testing will help to prevent unneeded work that could be avoided with proper advocacy.</p>
<p><span style="color: #000000;"><strong>If someone wants to get validated, are there things they should start doing right away?</strong></span></p>
<p>The earlier you can prepare, the better. If you are currently developing your product, take time to bring someone in that knows the FIPS requirements to ensure the design and implementation of the solution meets <strong>all</strong> eleven requirements. If you have already developed your solution, perform a gap analysis to determine the delta between where you are and where you need to be in order to meet them. This should be the first step any organization takes, whether it is internally performed or assessed through a partner.</p>
<p><span style="color: #000000;"><strong>How is “FIPS-validated” different from “FIPS-compliant” or &#8220;FIPS-Inside&#8221;?</strong></span></p>
<p>There is a substantial difference between having your product achieve FIPS 140-2 validation and claiming your product is FIPS 140-2 compliant.</p>
<p>“FIPS-compliant” or &#8220;FIPS-Inside&#8221; is a self-designated term, but has no associated requirements or minimum criteria. Further, it has absolutely no government backing. Vendors may use this term in reference to a product that uses FIPS-Approved algorithms or libraries, but has not actually gone through the necessary steps to verify and test that the product is using them in a FIPS-Approved manner. It does not hold any weight nor can you claim you have completed FIPS 140-2 Validation.</p>
<p>“FIPS-validated” asserts that your specific solution has gone through the rigor of the entire FIPS 140-2 process, resulting in the award of a certificate of your own issued by NIST. Further, this means that your product has been tested by an independent third-party laboratory and will meet the legal requirements passed by Congress, as well as the procurement requirements for the U.S. government and other industries, including: healthcare, financial services, and critical infrastructure. Corsec has developed a <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/FIPS-Inside-Whitepaper.html">white-paper</a></span> to explore this topic further.</p>
<p><span style="color: #000000;"><strong>Additional Information:</strong></span></p>
<p><span style="color: #0000ff;"><a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span> to Corsec emails and get updates on security certifications and validations, product security guidance,  InfoSec news, and additional information on how to complete FED and Regulated Industry requirements for security standards and compliance.</p>
<p>Follow us on Social Media for real time updates and share insights on the industry: <span style="color: #0000ff;"><a href="https://twitter.com/CorsecSecurity">Twitter</a></span>, <span style="color: #0000ff;"><a href="https://sitdev.linkedin.com/company/corsec-security/">LinkedIn</a></span>, and <span style="color: #0000ff;"><a href="https://sitdev.facebook.com/CorsecInc/">Facebook</a></span></p>
<p>Check out our <span style="color: #0000ff;"><a href="https://sitdev.corsec.com/resources/">Resources &amp; FAQ Page</a></span> for even more information and assets to help you with product security and certifications.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 22:51:34 by W3 Total Cache
-->