<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>federal regulation Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/federal-regulation-zh-hans/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/federal-regulation-zh-hans/?lang=zh-hans</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 07 Feb 2022 19:52:46 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>federal regulation Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/federal-regulation-zh-hans/?lang=zh-hans</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>FIPS 140-3 APPROVED</title>
		<link>https://sitdev.corsec.com/fips-140-3-approved/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 01 May 2019 15:52:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/fips-140-3-approved/</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>A <a id="" href="https://www.federalregister.gov/documents/2019/05/01/2019-08817/announcing-issuance-of-federal-information-processing-standard-fips-140-3-security-requirements-for" target="_blank" rel="noopener noreferrer">Federal Register Notice</a> has been issued for the &#8220;Federal Information Processing Standard (<span style="color: #008000;"><a id="" style="color: #008000;" title="FIPS 140" href="https://csrc.nist.gov/publications/detail/fips/140/3/final" target="_blank" rel="noopener noreferrer">FIPS</a></span>) 140-3, Security Requirements for Cryptographic Modules&#8221;.</p>
<p>Having now been signed by the U.S. Commerce Secretary, it is official, FIPS 140-3 has been approved!</p>
<p style="padding-left: 40px;"><em>&#8220;This notice announces the Secretary of Commerce&#8217;s issuance of Federal Information Processing Standard (FIPS) 140-3, Security Requirements for Cryptographic Modules. <span style="color: #008000;">FIPS 140-3</span> includes references to two existing international standards: International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 19790:2012(E) Information technology — Security techniques — Security requirements for cryptographic modules, and ISO/IEC 24759:2017(E) Information technology — Security techniques — Test requirements for cryptographic modules. As permitted by those standards, NIST Special Publication (SP) series 800-140 will specify updates, replacements, or additions to the currently-cited ISO/IEC standard, as necessary. Those new SP 800-140 documents (currently under development) will consolidate implementation guidance and administrative guidance, and will be made available for public review and comment.&#8221;</em></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Key Dates:</strong></p>
<p>Companies actively working on or planning a FIPS validation will inevitably face decisions around which standard to work towards. The following dates will be critical for those projects:</p>
<ul>
<li><span style="color: #339966;">Draft For Comments: Complete</span></li>
<li><span style="color: #339966;">Effective Date: Complete</span></li>
<li><span style="color: #339966;">Publication of the Standard: Complete</span></li>
<li><span style="color: #339966;">Supporting Documents for FIPS 140-2 &amp; the CMVP Released: Complete</span></li>
<li>New Testing Begins: 9/22/20</li>
<li>140-3 Mandated &amp; The Last Day for 140-2 Submissions: 9/22/21 (This means Labs must submit their Lab reports to CMVP by this date)</li>
</ul>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Documentation:</b></p>
<p>CMVP wants to minimize the content in the series of NIST SP 800-140 documents because they hope to be as close to the international standard as possible. These are the documents that we believe will replace the existing FIPS 140-2 DTR, Appendices, and Annexes:</p>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140/final">NIST SP 800-140</a></span> – <em>FIPS 140-3 Derived Test Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140a/final">NIST SP 800-140A</a></span> – <em>CMVP Documentation Requirements</em></li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-140b/final"><span style="color: #3366ff;">NIST SP 800-140B</span></a> – <em>CMVP Security Policy Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140c/final">NIST SP 800-140C</a> </span>– <em>CMVP Approved Security Functions</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140d/final">NIST SP 800-140D</a> </span>– <em>CMVP Approved Sensitive Security Parameter Generation and Establishment Methods</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140e/final">NIST SP 800-140E</a></span> – <em>CMVP Approved Authentication Mechanisms</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140f/final">NIST SP 800-140F</a></span> – <em>CMVP Approved Non-Invasive Attack Mitigation Test Metrics</em></li>
</ul>
<p>A notable omission from the new SP 800-140 series is any reference document for Approved Protection Profiles from Common Criteria (a CC-certified operating system was required for software validations at level 2 and above).</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Early Review and Analysis:</b></p>
<p>This release has been a long time coming. We still expect additional updates and changes to come, but Corsec has reviewed the public documents and found the following areas to be of interest:</p>
<ul>
<li>Rather than encompassing the module requirements directly, FIPS 140-3 references ISO/IEC 19790:2012. The testing for these requirements will be in accordance with ISO/IEC 24759:2017</li>
<li>This version of FIPS 140-3 retains the 4 levels of validation</li>
<li>The sections in FIPS 140-3 are now as follows:
<ol>
<li>Cryptographic Module Specification</li>
<li>Cryptographic Module Interfaces</li>
<li>Roles, Services, And Authentication</li>
<li>Software/Firmware Security</li>
<li>Operating Environment</li>
<li>Physical Security</li>
<li>Non-Invasive Security</li>
<li>Sensitive Security Parameter Management*</li>
<li>Self-Tests</li>
<li>Life-Cycle Assurance</li>
<li>Mitigation of Other Attacks</li>
</ol>
</li>
</ul>
<p style="padding-left: 80px;"><strong>*</strong>Sensitive Security Parameters is a new category &#8211; SSPs include both CSPs and PSPs (Public Security Parameters)</p>
<p style="padding-left: 80px;"><strong>**</strong>Finite State Model was removed but may have been absorbed into section 11</p>
<p style="padding-left: 80px;"><strong>***</strong>EMI/EMC was removed. There was no mention of EMI/EMC in the draft ISO 24759 either</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Moving Forward:</strong></p>
<ol>
<li>Get Ahead: Be the first to complete the new standard (<span style="color: #008000;"><a style="color: #008000;" href="https://csrc.nist.gov/publications/detail/fips/140/3/final">FIPS 140-3</a></span>)</li>
<li>Revalidate Early: Avoid the new requirements prior to the mandated transition date and add 5 years to your current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> validation</li>
<li>Plan Accordingly &#8211; Products being evaluated against FIPS 140-2 during testing transition may face problems completing their certification under old requirements.</li>
</ol>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec participates in numerous committees, technical working groups, certification leadership positions, and industry events. As more information develops, we will deliver updates. Stay informed on all the program details, requirements, and timelines associated with FIPS 140-3 – <a href="https://ww3.corsec.com/subscribe">Subscribe</a></p>
<p>For more information on the current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> program, requirements, and process &#8211; <a href="https://sitdev.corsec.com/fips-140-2/">visit here</a>.</p>
<p>For any questions on how this will affect current or future FIPS projects, <a href="https://sitdev.corsec.com/contact-us/">contact Corsec</a>!</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 22:48:15 by W3 Total Cache
-->