<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Entropy</title>
	<atom:link href="https://sitdev.corsec.com/tag/entropy/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/entropy/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 03 Oct 2022 19:39:20 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Entropy</title>
	<link>https://sitdev.corsec.com/tag/entropy/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fed Roundup: September 2022</title>
		<link>https://sitdev.corsec.com/fed-sept22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 03 Oct 2022 19:39:20 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[certifications]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[InfoSec]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19561</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.disa.mil/en/NewsandEvents/2022/Caroline-Bean-JESD-executive">Caroline Bean is the new Senior Executive Service at DISA Headquarters</a></span></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-microsoft-windows-server-2022-security-technical-implementation-guide/">Microsoft Windows Server 2022 Security Technical Implementation Guide</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/disa-releases-the-spec-innovations-innoslate-4-x-security-technical-implementation-guide/">SPEC Innovations Innoslate 4.x Security Technical Implementation Guide</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/request-for-comments-disa-releases-draft-windows-11-stig-scap-benchmark-for-review/">Draft Windows 11 Security Technical Implementation Guide Security Content Automation Protocol (SCAP) benchmark</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/disa-releases-stig-viewer-2-17-and-user-guide/">Security Technical Implementation Guide Viewer 2.17 and the STIG Viewer User Guide</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li><span style="color: #0000ff;">NIST’s Cybersecurity for the Internet of Things (IoT) program<br />
<a style="color: #0000ff;" href="https://csrc.nist.gov/publications/detail/nistir/8425/final"><em>Profile of the IoT Core Baseline for Consumer IoT Products</em> (NIST IR 8425)</a><br />
<a style="color: #0000ff;" href="https://csrc.nist.gov/publications/detail/nistir/8431/final"><em>Workshop Summary Report for “Building on the NIST Foundations: Next Steps in IoT Cybersecurity”</em> (NIST IR 8431)</a><br />
</span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2022/proposal-to-convert-fips-198-1-to-a-nist-sp">NIST is reviewing FIPS 198-1 <em>The Keyed-Hash Message Authentication Code (HMAC) to become a SP</em></a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2022/request-additional-pqc-digital-signature-schemes">NIST is requesting additional digital signature proposals to be considered in the Post-Quantum Cryptography (PQC) standardization process</a></span></li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2022/nist-releases-nist-ir-8286c">IR 8286C, <em>Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight</em></a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2022/nist-ir-8427-initial-public-draft">IR 8427, <em>Discussion on the Full Entropy Assumption of the SP 800-90 Series</em></a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2022/third-public-draft-of-nist-sp-800-90c">3rd Draft SP 800-90C, <em>Recommendation for Random Bit Generator (RBG) Constructions</em></a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1279">Protection Profile for General Purpose Operating Systems, Version 4.3</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1277">Collaborative Protection Profile (cPP) Module for Biometrics, Version 1.1</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1278">Protection Profile for Mobile Device Fundamentals, Version 3.3</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: March 2022</title>
		<link>https://sitdev.corsec.com/fed-march22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 31 Mar 2022 15:12:50 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19263</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/DISA-Cybersecurity-Awareness-Campaign">DISA’s Cybersecurity &amp; Analytics Directorate will provide cybersecurity awareness refresher training courses over the next few weeks</a></li>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/EEMSG-enhancements">DISA improves Enterprise Email Security Gateway</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-mongodb-enterprise-advanced-4-x-security-technical-implementation-guide/">MongoDB Enterprise Advanced 4.x STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-motorola-solutions-android-11-security-technical-implementation-guide/">Motorola Solutions Android 11 Security Technical Implementation Guide STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-stig-viewer-1-12-and-user-guide/">STIG Viewer 2.16</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-cci-list-revision-5/">Control Correlation Identifier (CCI) List Revision 5</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-ibm-aspera-platform-4-2-security-technical-implementation-guide/">IBM Aspera Platform 4.2 Security Technical Implementation Guide STIG</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2022/nist-publishes-sp-800-204c">SP 800-204C, &#8220;Implementation of DevSecOps for a Microservices-based Application with Service Mesh&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-releases-sp-800-172a">SP 800-172A, &#8220;Assessment Procedures for Enhanced Security Requirements&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/sp-1800-10-cybersecurity-for-manufacturing-sector">SP 1800-10 &#8220;Protecting Information and System Integrity in Industrial Control System Environments: Cybersecurity for the Manufacturing Sector&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/proposal-to-revise-sp-800-38a">Revision of SP 800-38A</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1270">Virtual Private Network (VPN) Client, Version 2.4 and VPN Gateways, Version 1.2</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: February 2022</title>
		<link>https://sitdev.corsec.com/fed-feb22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 02 Mar 2022 15:59:12 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CCRA]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Entropy Testing]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19242</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/MajGenYeeRetirement">Army Maj. Gen. Garrett Yee is retiring</a></li>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/TechNetCyberApril2022">2022 AFCEA TechNet Cyber Symposium iis set for April</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/disa-releases-ubuntu-v20-04-scap-security-technical-implementation-guide-benchmark/">Automated benchmark for the Ubuntu v20.04 SCAP STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-draft-oracle-linux-8-stig-scap-benchmark-for-review/">Draft Oracle Linux 8 STIG SCAP benchmark</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-updated-dod-annex-for-mdfpp-v3-2/">DoD Annex for Mobile Device Fundamental Protection Profile (MDFPP) V3.2</a></li>
<li><a href="https://public.cyber.mil/announcement/group-policy-objects-gpos-have-been-updated-for-january-2022/">Group Policy Objects (GPOs) have been updated for January 2022</a></li>
<li><a href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-samsung-android-12-with-knox-3-x-security-technical-implementation-guide/">Samsung Android 12 with Knox 3.x STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-apple-macos-12-security-technical-implementation-guide/">Apple macOS 12 STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-vmware-vsphere-6-7-v1r2-security-technical-implementation-guide/">VMware vSphere 6.7, Version 1 Release 2 STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-has-released-updates-to-the-srg-stig-library-compilations-9/">Updates to the SRG/STIG Library Compilations</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2021/draft-pd-manufacturing-sector-cybersecurity">Draft project description, &#8220;Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/second-draft-nistir-8270-available-for-comment">2nd Draft NISTIR 8270, &#8220;Introduction to Cybersecurity for Commercial Satellite Operations&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/rfi-evaluating-and-improving-nist-cyber-resources">NIST has released an RFI to assist in improving cybersecurity resources such as the CSF and CSCRM</a></li>
<li><a href="https://csrc.nist.gov/News/2022/draft-nist-sp-800-219-available-for-comment">Draft SP 800-219, &#8220;Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/second-drafts-of-nist-sp-800-140cd-rev-1-available">2nd Draft NIST SP 800-140C/D Rev. 1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nistir-8286b-prioritizing-cybersecurity-risk-erm">NISTIR 8286B, &#8220;Prioritizing Cybersecurity Risk for Enterprise Risk Management&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-publishes-sp-800-218-ssdf-v11">SP 800-218 has updated the Secure Software Development Framework (SSDF) to v1.1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nccoe-releases-sp-1800-32">SP 1800-32, &#8220;Securing Distributed Energy Resources: An Example of Industrial Internet of Things Cybersecurity&#8221;</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/MMO/PP/PP_GPCP_v1.0.pdf.">Protection Profile for General Purpose Computing Platforms (GPCP), Version 1.0.</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2019 FIPS Implementation Guidance Updates</title>
		<link>https://sitdev.corsec.com/2019-fips-ig/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 18 Dec 2019 18:09:57 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Revalidation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=18337</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>The National Institute of Standards and Technology (NIST), the agency that governs FIPS 140-2 validations in the United States, periodically releases updates and revisions to the Implementation Guidance (IG) used to evaluate products against FIPS 140-2 requirements. Earlier this month, NIST released a number of new revisions.</p>
<h5><strong>The latest December changes include updates to:</strong></h5>
<ul>
<li>Revalidation Requirements</li>
<li>Instructions for Validation Information Formatting</li>
<li>Limiting the Use of FIPS 186-2</li>
<li>Acceptable Algorithms for Protecting Stored Keys and CSPs</li>
<li>Entropy Estimation and Compliance with SP 800-90B</li>
<li>Continuous Random Number Generator Tests</li>
<li>Pair-Wise Consistency Self-Test When Generating a Key Pair</li>
<li>Use of non-NIST-Recommended Asymmetric Key Sizes and Elliptic Curves</li>
<li>Key/IV Pair Uniqueness Requirements from SP 800-38D</li>
<li>Use of Truncated HMAC</li>
<li>Approved Modulus Sizes for RSA Digital Signature and Other Approved Public Key Algorithms</li>
<li>CAVP Requirements for Vendor Affirmation to SP 800-56A Rev3 and the Transition from the Validation to the Earlier Versions of This Standard</li>
<li>Acceptable Key Establishment Protocols</li>
<li>Assurance of the Validity of a Public Key for Key Establishment</li>
<li>Requirements for Vendor Affirmation to SP 800-133</li>
<li>Elliptic Curves and the MODP Groups in Support of Industry Protocols</li>
</ul>
<h5><strong>Previous IG updates from this year included:<br />
</strong></h5>
<ul>
<li><em>October</em>: Operational Equivalency Testing for HW Modules</li>
<li><em>August</em>: Limiting the Use of FIPS 186-2, Revalidation Requirements, Known Answer Tests for Cryptographic Algorithms, Key Agreement Methods, and Requirements for Vendor Affirmation of SP 800-56C</li>
<li><em>May</em>: Entropy Estimation and Compliance, Instructions for Validation Information Formatting, Entropy Caveats, and Entropy Assessment</li>
<li><em>February</em>: Enforcement of the Trusted Path by applying cryptographic protection</li>
</ul>
<p>The current Implementation Guidance for FIPS PUB 140-2 and the Cryptographic Module Validation Program can be found <a href="https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips140-2/FIPS1402IG.pdf"><span style="color: #3366ff;">here</span></a>.</p>
</div>
</div>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="p2"><strong><span class="s2">About FIPS 140-2</span></strong></h5>
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a> </span>is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2. Product vendors are required to complete validation testing of FIPS-approved and NIST-recommended cryptographic algorithms and their individual components.</span></p>
<p><span class="s1">FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency. </span><span class="s1">FIPS is mandated by law in the U.S. and very strictly enforced in Canada, it is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>About Corsec Security, Inc.</strong></h5>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <a href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
</div></div></div></div><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Corsec Collaborates with NIAP on Labgram #106</title>
		<link>https://sitdev.corsec.com/labgram106/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 15 Nov 2017 19:58:34 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=12332</guid>

					<description><![CDATA[In September, Corsec uncovered a policy change that would affect a number of Common Criteria evaluations following this NIAP announcement: “Per published NIST notifications, all non-56B-compliant key transport schemes will be disallowed in the U.S. government ... <p class="read-more-container"><a title="Corsec Collaborates with NIAP on Labgram #106" class="read-more button" href="https://sitdev.corsec.com/labgram106/#more-12332" aria-label="More on Corsec Collaborates with NIAP on Labgram #106">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>In September, Corsec uncovered a policy change that would affect a number of Common Criteria evaluations following this NIAP announcement: <em>“Per published NIST notifications, all non-56B-compliant key transport schemes will be disallowed in the U.S. government after 2017.”</em></p>
<p>Corsec immediately began to engage with NIAP, our customer base, our network of testing labs, and contacts within various standards certifying bodies; seeking clarification on the announcement (referred to as “Labgram #106” and “Valgram #126”) to determine the impact it would have on our customers and to the industry as a whole.</p>
<p>Corsec recognized that there were inherent issues with the policy, and presented these concerns to NIAP. After weeks of collaboration, NIAP agreed to rescind the Labgram and on October 31, they made the following official announcement: <em>“NIAP has decided that Labgram #106 will be archived and no part of it will be enforced.”</em></p>
<p>As a result, Transport Layer Security (TLS) cipher suites with RSA key agreement/key transport will continue to be accepted for use within National Security Systems for the foreseeable future (the full text of NIAP’s announcement can be found <a href="https://sitdev.niap-ccevs.org/Announcements/announcements.cfm">here</a>). This announcement did provide valuable insight into NIAP’s thoughts regarding the use of TLS in National Security Systems. Corsec believes that NIAP will revisit this issue, potentially after updates to NIST Special Publication 800-56 are completed.</p>
<p>Corsec continuously monitors all industry announcements to ensure that our customers remain informed and advised on all policy and standards changes. If you have concerns about how changes in the industry may affect your existing certification or future certification strategy, please <a href="https://sitdev.corsec.com/company/contact-us/">Contact Corsec</a> for more information.</p>
<p>You can also stay up to date on news and updates to standards, certifications, and requirements by <a href="http://marketing.corsec.com/Subscribe-Email.html">subscribing</a> to our emails and newsletter, as well as following us on social media:</p>
<p>&nbsp;</p>
<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>  <a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />  </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Entropy Testing: Tips for Meeting Requirements</title>
		<link>https://sitdev.corsec.com/entropy-testing/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 16 Jan 2014 21:17:41 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Entropy Testing]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6425</guid>

					<description><![CDATA[In the second post of our two-part series, we continue our discussion with panelists from Computer Sciences Corporation: Lachlan Turner, Jason Cunningham, and Maureen Barry. Continuing where we left off with last week’s post, we’ll dive deeper into entropy and answer some of the many questions now arising...]]></description>
										<content:encoded><![CDATA[<p>In the second post of our two-part series, we continue our discussion with panelists from Computer Sciences Corporation: Lachlan Turner, Jason Cunningham, and Maureen Barry. Continuing where we left off with <a href="http://corsec.com/entropy-testing-for-fips-and-common-criteria-what-you-need-to-know/" target="_blank" rel="noopener noreferrer">last week’s post</a>, we’ll dive deeper into entropy and answer some of the many questions now arising about new requirements, entropy testing and tools and how all of this might affect your upcoming FIPS or Common Criteria evaluations.</p>
<h4><strong>What do vendors have to do to meet the entropy testing requirements?</strong></h4>
<p>Vendors must prove to the testing laboratories that their entropy source conforms to the requirements in NIST’s <a href="http://csrc.nist.gov/publications/drafts/800-90/draft-sp800-90b.pdf" target="_blank" rel="noopener noreferrer">Special Publication 800-90B</a>. In general terms, this requires:</p>
<ul>
<li>Identification and specifications of the entropy source</li>
<li>Identification of whether the entropy is independent and identically distributed (IID) or non-IID</li>
<li>Justification as to the randomness of the entropy</li>
<li>Subjecting a sampling of the entropy to statistical testing</li>
<li>Proof that adequate health tests are implemented</li>
</ul>
<p>If vendors are using third-party modules for their products, it’s best to choose those where access to information about sources of entropy is available. If a module has already been chosen, start a discussion with the third-party provider on how to best approach the entropy testing process. The key is that in the design process, vendors should look for solutions where they can get entropy that is as random as possible.</p>
<p>While nothing is guaranteed at this stage, our experience has shown that when accurately demonstrated, NIST generally accepts the justification of sufficient entropy stemming from the character device /dev/random, available in the Linux-based pseudo-random number generator (PRNG). The counterpart in that Linux-based PRNG, /dev/urandom, however, is not currently allowed by NIST due to its non-blocking characteristic.</p>
<h4><strong>Is there a way for product vendors to perform entropy testing on their sources before they enter into evaluation?</strong></h4>
<p>Unfortunately, there is really no way to know if a vendor will pass entropy testing at this stage. The most that can be done is to present arguments to a certification body, but because this is such a new area, there is no way to know for certain that an argument will stand up and something will pass.</p>
<p>There are test tools available that are helpful, and running a sample entropy output through one of these test tools can certainly give an indication of the sufficiency of the entropy source. A vendor can independently perform its own entropy testing against the NIST publication SP 800-90B—this is the gold standard right now. (The applicable concepts required to gauge whether the entropy source is sufficient are all outlined in that publication.) Vendors may, however, need some consulting help from a Cryptographic Security Testing laboratory for that. Engaging with a consultant early on may also help identify any red flags that could hold up the process (for example, the use of dev/urandom).</p>
<h4><strong>What tools can be used for entropy testing specifically?</strong></h4>
<p>No officially sanctioned tool exists for entropy testing. As it stands, the Cryptographic Security Testing laboratories are responsible for measuring entropy samples using their own methods and tools. Several third parties have created their own tools for entropy testing. Some tools are available in the public domain, and incorporate some or all of the NIST SP 800-90B requirements.</p>
<p>For instance, the Python testing tool is available upon request from CAVP to labs and vendors for entropy testing. It is a fairly primitive program, but can be useful and at some point there will be a GUI interface for it.</p>
<p>At this point in time, the Common Criteria schemes do not rely on the entropy testing tools, and including output in the Entropy Assessment Report is entirely optional.  Our experience indicates that CSEC (Canada) and NIAP (U.S.) are more interested in an explanation that the input to the entropy source (i.e. noise source) contains sufficient entropy itself to justify the encryption strength of the resulting keys that the TOE will generate. Any use of the tools would have to focus on the noise source data, which is problematic. Measuring the output of the entropy source, after post-processing of the entropy has occurred, does not appear to be acceptable.</p>
<h4><strong>How do you deal with third-party entropy sources if the vendor does not have access to all internal technical details?</strong></h4>
<h4>It’s possible that a vendor may not have the source code or design information regarding the entropy source. Typically, if the entropy source is a True Random Number Generator (TRNG) such as one might find on certain processors, there may be sufficient specifications from the manufacturer detailing the product, such that the requirements of NIST SP 800-90B could be addressed.</h4>
<h4><strong>Are vendors required to use a hardware noise source for entropy generation to be FIPS 140-2 validated or CC validated against a NIAP PP?</strong></h4>
<p>The use of a hardware noise source isn’t a requirement, but it is highly recommended. The entropy source identified by the vendor will be tested per the requirements of NIST SP 800-90 (as well as any supplemental FIPS or CC programmatic guidance), and an entropy testing verdict will be rendered.</p>
<p>Entropy that is found to fail the mathematical testing outlined in NIST SP 800-90, or entropy sources that contain inadequate health testing, will be considered insufficient by the laboratory.</p>
<p>While not required, there are some benefits to using hardware noise sources. There are commonly available hardware-based entropy sources that are built in to some CPUs (for example, Intel’s Ivy Bridge processors). These hardware-based solutions have been found to produce quality entropy very quickly, so are ideal for use in systems where the entropy pool can become quickly depleted.</p>
<h4><strong>How long is the process of evaluating entropy adding to evaluations?</strong></h4>
<p>For FIPS, the CMVP requires a report containing justifications, so it can add about a week of lab time onto the process — this includes all the components involved: source code review and writing the entropy justification. On the vendor end, there is then additional time. Because this is fairly new guidance, we can’t always estimate what CMVP will require. Labs are providing the information we believe we’re being asked for, but we’ll have a better feel for what is truly required in the future.</p>
<p>For Common Criteria in the U.S., there has been a starting gate implemented requiring that the entropy source be evaluated and approved prior to a vendor actually starting a CC evaluation. Turnaround times will likely improve, however the impact here is potentially quite large – for now one should assume a two-month to three-month delay waiting for entropy review. Because it’s so new, we’ve only just had our first submission approved in Canada, which fortunately occurs in parallel with the rest of the evaluation and therefore has less of an impact.</p>
<h4><strong>Panel members from Computer Sciences Corporation (CSC) are:</strong></h4>
<p>Lachlan Turner is the Technical Director of <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC’s</a> Security Testing and Certification Labs with over 10 years of experience in cyber security specializing in Common Criteria. Lachlan served as a member of the Common Criteria Interpretations Management Board (CCIMB) and has held roles as certifier, evaluator and consultant across multiple schemes – Australia/New Zealand, Canada, USA, Malaysia and Italy. Lachlan provides technical leadership to CSC’s four accredited CC labs and is passionate about helping vendors through the evaluation process to achieve their business goals and gain maximum value from their security assurance investments.</p>
<p>Jason Cunningham leads the FIPS 140-2 program at <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC</a> and has over 10 years of experience in IT security. Throughout his career, Jason has been involved in numerous security related projects covering a wide range of technologies.</p>
<p>Maureen Barry is the Deputy Director for <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC’s</a> Security Testing and Certification Labs (STCL) and primarily manages the Canadian laboratory.  She is also a Global Product Manager responsible for developing, managing, and executing the Cybersecurity Offering program for STCL across four countries: Canada, USA, Australia and Germany.  She has almost 10 years of experience in Common Criteria in addition to over 10 years of experience in IT.</p>
<p>Corsec Lead Engineer Darryl Johnson was also a member of the panel discussing entropy testing and contributed to the writing of this post.</p>
<p>For help with your FIPS 140-2 or Common Criteria evaluation, or if you have questions about entropy testing and how it might affect your next evaluation, <a href="http://sitdev.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Entropy for FIPS and Common Criteria: What Is It?</title>
		<link>https://sitdev.corsec.com/entropy/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 09 Jan 2014 21:20:19 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Entropy]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6428</guid>

					<description><![CDATA[In the world of cryptography, data is only safe as long as the keys used to protect that data are kept secure. While, on one hand, this means that keys must be protected against unauthorized access, it also means that keys must be created in a way that makes them difficult for an attacker to guess. To produce cryptographically strong...]]></description>
										<content:encoded><![CDATA[<p>In the world of cryptography, data is only safe as long as the keys used to protect that data are kept secure.  While, on one hand, this means that keys must be protected against unauthorized access, it also means that keys must be created in a way that makes them difficult for an attacker to guess.  To produce cryptographically strong keys, cryptographic modules use random number generators, or RNGs, which in turn rely on random data as input.  This random input data is called entropy, and is the foundation of a secure cryptographic module.</p>
<p>I had the opportunity to discuss entropy with the great group over at Computer Sciences Corporation (CSC). The panelist included Lachlan Turner, Jason Cunningham, and Maureen Barry. In our first of a two-part series, our panel answers some questions to offer insight into what you need to know about entropy and how it could affect your Common Criteria or FIPS evaluation.</p>
<h4><strong>What does entropy mean?</strong></h4>
<p>The term entropy loosely translates to, “The degree of disorder or randomness in a system.” This is how we describe entropy in computing, although the term is also used in thermodynamics. For our purposes, however, it is the random data collected from electronic sources, for use in computing applications.</p>
<p>Entropy is a measure of randomness often expressed and measured by bits. The more entropy you have feeding into a given value, the more random that value will be.</p>
<h4><strong>Why is entropy receiving so much attention when programs are already testing cryptographic algorithms?</strong></h4>
<p>The self-tests implemented to test cryptographic algorithms are considered to be a health check, which ensures that they can mathematically and procedurally operate as they were intended to. This concept is different from that of entropy testing.</p>
<p>Most modern day cryptographic implementations rely on the use of sufficiently random data in order to ensure a high degree of secrecy when establishing shared secrets, or creating the data required to generate cryptographic keys. The <i>random number generators</i> that typically rely on this input to be random can only produce sufficiently random numbers if the input they require also contains a high degree of randomness. The entropy serves as that high degree of randomness.</p>
<p>When it comes to entropy, an old saying applies. “You will get out of it, what you put into it.” Since the quality and quantity of entropy is the foundation of cryptography, it’s vitally important that entropy be considered as part of the testing process.</p>
<h4><strong>What challenges do vendors face when trying to measure their product’s entropy?</strong></h4>
<p>The information coming from NIAP, CMVP, and the other validation program bodies is that vendors have to understand what sources contribute to their product’s overall entropy and how many bits of entropy are contributed by each source.  That can be quite difficult. Quite often the crypto modules that are used in products are created by third parties, and vendors don’t really know what happens “under the hood.”</p>
<p>Another challenge comes from the need to measure the entropy at the appropriate point in the overall process.  Many systems will take a value produced from entropy sources and “condition” it before using it as input to the random number generator.  However, testers want to see entropy measurements performed on the pure, pre-conditioning value, but these values cannot always be captured.</p>
<h4><strong>What are the requirements for entropy in Common Criteria and FIPS evaluations?</strong></h4>
<p>Thus far, the entropy requirements for CC and FIPS have only been loosely defined through draft publications. That is not to say, however, that there isn’t a framework in place. The Computer Security Division at NIST has completed a publication that encompasses the testing of entropy. It is anticipated that the concepts in the publication will soon form the basis of all future entropy testing for FIPS 140-2 (and possibly Common Criteria).</p>
<p>From a Common Criteria perspective, there is an NIAP-approved Protection Profile (PP) and within that PP is an annex with an entropy profile. From a practical standpoint, a vendor has to describe the entropy; that is, the vendor needs to document what entropy source is actually producing random data. Examples could be ring oscillators, keyboard key presses, noisy diodes, mouse movement, or disk input/output operations. The requirements are to describe what the sources are and then describe what is done with those random event values (i.e., what is done to condition them), and what is the interaction between the entropy source and the crypto module. There are also requirements around health testing.</p>
<p>In the end, vendors are required to provide a justification (supported either by test data or mathematical models) that demonstrates how many bits of entropy are being generated.  That justification must include a good argument for why it’s sufficient. This justification area is currently evolving and is a bit grey.</p>
<p>For FIPS, things are very similar to Common Criteria. The CMVP released guidance that says any type of analysis that provides information regarding sufficiency of a crypto module’s entropy will be considered — they understand that there is no perfect way to quantify it.  Statistical analyses can be conducted or source code can be analyzed to mathematically support a vendor’s claim that their entropy is sufficient for generating random numbers. NIST doesn’t really come right out and call it entropy. This process is part and parcel to the strength of the key generation method. They want to know everything that happens before the data goes to an approved RNG.</p>
<p>There is quite a bit of confusion right now about entropy — hopefully, we can clear a bit of it up. In our next post, we’ll dive a bit further into entropy testing, touching on what vendors need to do to meet the entropy requirements, what entropy testing tools are available, and how much time entropy testing is adding to evaluations.</p>
<h4><strong>Panel members from Computer Sciences Corporation (CSC) are:</strong></h4>
<p>Lachlan Turner is the Technical Director of <a href="http://sitdev.csc.com/" target="_blank" rel="noopener noreferrer">CSC’s</a> Security Testing and Certification Labs with over 10 years of experience in cyber security specializing in Common Criteria. Lachlan served as a member of the Common Criteria Interpretations Management Board (CCIMB) and has held roles as certifier, evaluator and consultant across multiple schemes – Australia/New Zealand, Canada, USA, Malaysia and Italy. Lachlan provides technical leadership to CSC’s four accredited CC labs and is passionate about helping vendors through the evaluation process to achieve their business goals and gain maximum value from their security assurance investments.</p>
<p>Jason Cunningham leads the FIPS 140-2 program at <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC</a> and has over 10 years of experience in IT security. Throughout his career, Jason has been involved in numerous security related projects covering a wide range of technologies.</p>
<p>Maureen Barry is the Deputy Director for CSC’s Security Testing and Certification Labs (STCL) and primarily manages the Canadian laboratory.  She is also a Global Product Manager responsible for developing, managing, and executing the Cybersecurity Offering program for STCL across four countries: Canada, USA, Australia and Germany.  She has almost 10 years of experience in Common Criteria in addition to over 10 years of experience in IT.</p>
<p>Corsec Lead Engineer Darryl Johnson was also a member of the panel discussing entropy testing and contributed to the writing of this post.</p>
<p>For help with your FIPS 140-2 or Common Criteria evaluation or for additional questions about entropy testing and how it might affect your next certification, <a href="http://sitdev.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Last Details on ICMC 2013 and What to Look for Next Year</title>
		<link>https://sitdev.corsec.com/the-last-details-on-icmc-2013-and-what-to-look-for-next-year-2/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 14 Nov 2013 23:40:31 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Events]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6452</guid>

					<description><![CDATA[Is it too late to talk about the International Cryptographic Modules Conference (ICMC)? Well, it really depends on how you look at it. If you were looking for a timely recap of the conference, then yes, I guess it is. But if you missed any of the details, this might be your last chance to catch up. And planning has just begun for next year’s conference...]]></description>
										<content:encoded><![CDATA[<p>Is it too late to talk about the International Cryptographic Modules Conference (ICMC)? Well, it really depends on how you look at it. If you were looking for a timely recap of the conference, then yes, I guess it is. But if you missed any of the details, this might be your last chance to catch up. And planning has just begun for next year’s conference, so here’s a chance to get early details of what might be coming up in the future!</p>
<p>ICMC was held September 24 – 26<sup>th</sup> this year in Gaithersburg, MD. The first day contained pre-conference workshop sessions that offered introductions to FIPS 140-2, side-channel analysis and testing, and discussions about cryptography in a mobile world. The second and third day offered two tracks: the certification program track and the technical track. I’m just going to discuss the conference as a whole and where I believe and hope it is going.  If you would like to know more about the presentations, there are already several fantastic recounts of the each workshop and the extremely qualified presenters. Information can also be found on the <a href="http://icmc-2013.org/wp/" target="_blank">conference website</a>.</p>
<p>Unsure of what to expect for a first-time conference, especially one that sounded so technical, I was pleasantly surprised to see the number of representatives from both government (including NIST and CSEC) and private industry (including Blue Coat, McAfee, Symantec, and Cisco).  Attendees hailed from across the globe, including the U.S., Canada, the U.K., France, Japan, and Korea.</p>
<p>The Certification Programs Track, focused on FIPS 140-2 and CMVP validation program requirements and related topics. The technical track dug more into the nitty-gritty of cryptography, including fault injection and key management.  Presentations ranged from extremely technical, such as the discussions on entropy or Test Vector Leakage Assessments, to the non-technical, “Everything You Wanted To Know About Labs, But Where Afraid To Ask” panel session.  Each track was equally attended and offered energetic discussion.  There really were some great presentations. We even received an update on FIPS 140-3. More on that in a later blog post.</p>
<p>A great deal of the credit for such a positive conference experience goes to the host. Atsec Information Security, and Program Chair Fiona Pattinson in particular, did a fantastic job with hosting this conference. Fiona and her team set the informal tone early and kept it relaxed yet on schedule, throughout. It ran smoothly and was intimate, informative, and enjoyable. It was three days of getting together with some of the best minds in cryptography to discuss (and at times disagree about) the subject attendees are passionate about.  You know you’ve attended a good conference when you leave thinking about next year.</p>
<p>As I mentioned, planning for ICMC 2014 is already taking place. Early in October, a survey was sent to the more than 120 registrants from ICMC 2013. Questions soliciting feedback on the sessions and conference location were asked to determine what worked and what could be improved upon for next year. The results were collected and Fiona and a group of 12 others (including myself) have begun a series of conference calls to discuss the who, when, and where of next year’s conference. The committee meets via these calls every two weeks and will continue to do so leading up to the event. The first meeting was held last Friday to discuss the survey results, selecting a location for next year’s conference, dates, and schedule. Although there has been only one meeting, if that one meeting is any indication, ICMC 2014 will be an even bigger success than the inaugural conference.</p>
<p>To find out more about FIPS 140-2, follow Corsec on <a href="https://twitter.com/CorsecSecurity" target="_blank">Twitter</a>, <a href="http://sitdev.linkedin.com/company/80343" target="_blank">LinkedIn</a>, or subscribe to our <a href="http://sitdev.corsec.com/blog/" target="_blank">blog</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>But the Rules are Changing!</title>
		<link>https://sitdev.corsec.com/but-the-rules-are-changing/</link>
					<comments>https://sitdev.corsec.com/but-the-rules-are-changing/#respond</comments>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 25 Jul 2013 15:39:37 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[UC APL]]></category>
		<guid isPermaLink="false">http://sitdev.corsec.com/?p=1785</guid>

					<description><![CDATA[According to the ancient Greek philosopher Heraclitus, “There is nothing permanent except change.” As anyone following security certifications lately can tell you, there is a lot of truth in this statement. We have entered another ... <p class="read-more-container"><a title="But the Rules are Changing!" class="read-more button" href="https://sitdev.corsec.com/but-the-rules-are-changing/#more-1785" aria-label="More on But the Rules are Changing!">Read more</a></p>]]></description>
										<content:encoded><![CDATA[<p>According to the ancient Greek philosopher Heraclitus, “There is nothing permanent except change.” As anyone following security certifications lately can tell you, there is a lot of truth in this statement. We have entered another period of profound change in security certifications. Putting these changes in the proper context is essential if you wish to position your product or company properly in the marketplace.</p>
<p>Many of the changes that are going on programmatically are just not relevant to the macro decisions that product vendors need to make for certification. While these changes might impact these decisions slightly, the main business drivers for certification do not change very quickly. As certification insiders, we tend to focus on the new and interesting things in our industry. If you are waiting for the change to stop before making a decision on certification, you will be waiting a long time indeed. In fact, many of your competitors will have leapfrogged you by completing their certifications while you are paralyzed with inaction.</p>
<p><strong>The Common Criteria community</strong> is currently undergoing significant change. There are new Protection Profiles, new Technical Communities, new guidance from several schemes on what types of evaluations are acceptable, new requirements for entropy for certain evaluations. These changes are causing a lot of confusion. However, these “changes” are being made more rapidly than most product purchasers even understand them. Furthermore, some of these changes have been announced, rescinded, and a new change announced all in less time than a product could have gone through the certification process! However, through all of this, product vendors are successfully achieving certification of their products and meeting their customers’ needs.</p>
<p><strong>The Cryptographic Module Validation Program</strong>, also known as <a title="FIPS 140-2 FAQ" href="http://sitdev.corsec.com/fips-services/fips-140-2-faq/" target="_blank" rel="noopener noreferrer"><strong>FIPS 140-2</strong></a>, is also undergoing change. The new <a title="FIPS 140-2 or FIPS 140-3; which way should I go?" href="http://sitdev.corsec.com/2012/12/fips-140-2-or-fips-140-3-which-way-should-i-go/" target="_blank" rel="noopener noreferrer"><strong>FIPS 140-3</strong></a> standard is still in development. Recent implementation guidance can seem to change the rules for many product types.&nbsp; Navigating a path through these changes can be difficult at times. However, product purchasers still require validated products, and product vendors who navigate this process are rewarded with more opportunities to sell their products.</p>
<p><strong>The <a title="Highlights from Corsec’s UC APL Webinar: A Glimpse Into What You Missed" href="http://sitdev.corsec.com/2013/04/highlights-from-corsecs-uc-apl-webinar-a-glimpse-into-what-you-missed/" target="_blank" rel="noopener noreferrer">DoDIN APL</a></strong> process has probably undergone the least amount of change from a programmatic standpoint as far as my customers are concerned, but the most significant change from a sales applicability standpoint. More and more procurements are requiring products to be listed on the DoDIN APL. Understanding this and being aware of the trends for purchasing requirements is important in making a business decision around pursuing a product listing on the DoDIN APL.</p>
<p>After more than 15 years in the certification business, I have seen several periods of change similar to the one we are in now. As another great philosopher, Yogi Berra, once said “It&#8217;s déjà vu all over again.” Businesses that embrace change and navigate it skillfully have historically done well in this marketplace. Businesses that are paralyzed by change are often still waiting for the change to settle down while their competitors are successfully selling their already validated products.</p>
<p>Change is constant. Let Corsec help you through the today’s changes in the certification industry so that you can realize the true revenue potential in your products. <a href="http://sitdev.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">Find out</a> how we can help.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://sitdev.corsec.com/but-the-rules-are-changing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-06-13 00:18:08 by W3 Total Cache
-->