<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>federal regulation Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/federal-regulation/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/federal-regulation/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 11 Mar 2024 19:44:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>federal regulation Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/federal-regulation/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fed Roundup: July 2022</title>
		<link>https://sitdev.corsec.com/fed-july22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 02 Aug 2022 13:54:46 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[ISO 15408]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19508</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li>The DISA Fourth Estate Network Optimization program office began migrating the Defense POW/MIA Accounting Agency from its legacy information technology network to the newly modernized IT network, DODNet</li>
<li>Marine Corps Col. Jared C. Voneida takes command of the Defense Information Systems Agency Pacific Regional Field Command</li>
<li>U.S. Army Col. Diane E. Klein takes command of the Defense Information Systems Agency Europe Field Command</li>
<li>Air Force Chief Master Sgt. David P. Klink retires</li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">Application STIGs and SRGs</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=mobility">Mobility STIGs and SRGs</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=network-perimeter-wireless">Network STIGs and SRGs</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems">Operating System STIGs and SRGs</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=supplemental-automation-content">Supplemental Automation Content</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=sunset">Sunset STIGs and SRGs</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://cyber.mil/stigs/downloads/?_dl_facet_stigs=scap">Benchmarks</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/disa-releases-suse-linux-enterprise-server-15-stig-with-ansible/">SUSE Linux Enterprise Server 15 Security Technical Implementation Guide with Ansible</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-microsoft-windows-11-security-technical-implementation-guide/">Microsoft Windows 11 Security Technical Implementation Guide</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://public.cyber.mil/announcement/gpo-update-2/">Group Policy Objects (GPOs) have been updated</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>Four Post-Quantum Cryptography candidates have been announced for standardization, as well as additional candidates for a fourth round of analysis</li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li>Draft 800-221A, Information and Communications Technology (ICT) Risk Outcomes: Integrating ICT Risk Management Programs with the Enterprise Risk Portfolio</li>
<li>Draft SP 800-221, Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio</li>
<li>Draft SP 800-66r2 (Revision 2), Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule:  A Cybersecurity Resource Guide</li>
<li>Draft Project Description, Software Supply Chain and DevOps Security Practices: Implementing a Risk-Based Approach to DevSecOps</li>
<li>Internal Report 8235, &#8220;Security Guidance for First Responder Mobile and Wearable Devices.&#8221;</li>
<li>SP 800-171, -171A, -172, and -172A</li>
<li>SP 800-53 Rev. 5</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/Ref/Tracked/OT_ProgressRpt2022.Q1.php">1st Quarter Progress Report</a></li>
<li><a href="https://www.niap-ccevs.org/Announcements/Announcements.cfm#ann1275">Technical Community (TC) for the update of the Redaction PP-Module V1.0</a></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fed Roundup: June 2022</title>
		<link>https://sitdev.corsec.com/fed-june22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 29 Jun 2022 20:20:56 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CCRA]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19453</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><a href="https://www.disa.mil/NewsandEvents/2022/CMSgt-Klink-Retirement">Air Force Chief Master Sgt. David P. Klink retires</a></li>
<li><a href="https://www.disa.mil/NewsandEvents/2022/4NEO">New computer equipment and upgrades coming fo the Fourth Estate Network Optimization Program Office</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/the-defense-information-systems-agency-has-issued-a-pre-release-version-of-the-stig-applicability-guide-for-linux-and-windows/">Pre-release version of the STIG Applicability Guide for Linux &amp; Windows</a></li>
<li><a href="https://public.cyber.mil/announcement/release-of-scc-5-5/">SCC 5.5</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-mozilla-firefox-v6r1-security-technical-implementation-guide-benchmarks/">Mozilla Firefox Security Technical Implementation Guide (STIG) for Linux and Windows</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2022/initial-public-draft-nist-ir-8323r1-comment">Draft NIST IR 8323r1, Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-releases-new-guidance-and-resources-on-macos">SP 800-219, Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)</a></li>
<li><a href="https://csrc.nist.gov/News/2022/submit-comments-on-final-draft-nist-sp-1800-34">Draft NIST SP 1800-34, Validating the Integrity of Computing Devices</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-iot-cybersecurity-program-releases-new-docume">NIST Internet of Things Cybersecurity Program Releases</a></li>
<li><a href="https://csrc.nist.gov/News/2022/ordered-t-way-combinations-for-testing-state-based">NIST Cybersecurity White Paper 26, Ordered t-way Combinations for Testing State-based Systems</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-ir-8286d-available-for-public-comment">Draft NIST IR 8286D, Using Business Impact Analysis to Inform Risk Prioritization and Response</a></li>
<li><a href="https://csrc.nist.gov/News/2022/public-comments-requested-on-fips-180-4-shs">Comments Requested for FIPS 180-4, Secure Hash Standard (SHS), 2015</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-releases-draft-ir-8409">NIST IR 8409 Initial Public Draft, Measuring the Common Vulnerability Scoring System Base Score Equation</a></li>
<li><a href="https://csrc.nist.gov/News/2022/proposal-to-withdraw-sp-800-107-rev-1">Withdraw of SP 800-107 Rev. 1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/engineering-trustworthy-secure-systems-final-draft">Draft SP 800-160 Volume 1, Engineering Trustworthy Secure Systems</a></li>
<li><a href="https://csrc.nist.gov/News/2022/open-for-public-comment-sp-1800-35-vol-a">Draft SP 1800-35 Vol A Implementing a Zero Trust Architecture</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li>None</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED Roundup: April 2020</title>
		<link>https://sitdev.corsec.com/fed-april20/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 04 May 2020 15:33:24 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=18601</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.disa.mil/NewsandEvents/2020/DISA-DOD-response-COVID-19">DISA provides connectivity to DoD COVID Response Unit</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2020/draft-white-paper-on-iot-device-characterization">Draft NIST Cybersecurity White Paper on &#8220;Methodology for Characterizing Network Behavior of Internet of Things Devices&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2020/nist-releases-draft-sp-800-210-for-comment">Draft SP 800-210, &#8220;General Access Control Guidance for Cloud Systems&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/mitigating-risk-of-software-vulns-ssdf">NIST Cybersecurity White Paper on &#8220;Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2020/draft-wp-on-hardware-enabled-security-for-servers">Draft NIST Cybersecurity White Paper on &#8220;Hardware-Enabled Security for Server Platforms&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2020/nist-publishes-nistir-8011-vol-4">NISTIR 8011 volume 4: &#8220;Automation Support for Security Control Assessments: Software Vulnerability Management&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2020/nistir-8294-symposium-on-cybersecurity-of-evse">NISTIR 8294, &#8220;Symposium on Federally Funded Research on Cybersecurity of Electric Vehicle Supply Equipment (EVSE)&#8221;</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li>NIAP operations have been temporarily suspended due to COVID-19, if you need support on your current or future <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/">Common Criteria</a></span> certification, please <a href="mailto:jnelson@corsec.com">contact Corsec</a> for options moving forward.</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://ww3.corsec.com/subscribe">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Algorithm Testing &#038; Automation: The Change from CAVS to ACVTS</title>
		<link>https://sitdev.corsec.com/algorithm-automation/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 25 Oct 2019 16:10:41 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ACVTS]]></category>
		<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CAVS]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NVLAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=18290</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>The National Institute of Standards and Technology (NIST) has announced that the Cryptographic Module Validation Program (CMVP) and the Cryptographic Algorithm Validation Program (CAVP) will soon be transitioning to an automated process for algorithm testing.</p>
<p>NIST&#8217;s announcement states that use of the current Cryptographic Algorithm Validation System (CAVS) and issuance of algorithm validations from that system will end at midnight on 6/30/20. Replacing the manual process is the new and updated Automated Cryptographic Validation Test System (ACVTS).</p>
<p>ACVTS testing has begun but is not yet mandatory unless the implementation has an Approved algorithm that the ACVTS Prod server supports and that CAVS does not support, with two clarifications:</p>
<ol>
<li>If a CAVS submission would require special processing, e.g., a request from the vendor/lab that failing test results be ignored because the implementation under test does not support certain input parameter lengths, but the ACVTS handles the case natively, ACVTS must be used.</li>
<li>If a FIPS 140-2 IG indicates that vendor affirmation is applicable for a particular Approved algorithm (and the IG transition end date has not passed), the vendor may choose either to test using ACVTS or vendor affirm.</li>
</ol>
<p><strong>Notes:</strong></p>
<ul>
<li>CAVS testing will remain free until it is retired</li>
<li>ACVTS will be free up until the CAVS retirement date</li>
</ul>
<p><strong>Key Dates:</strong></p>
<ul>
<li>1/20/20: CAVS submissions will only be accepted from a NVLAP-accredited CTS Lab that has obtained ACVTS credentials</li>
<li>6/30/20: Last day to submit CAVS test results</li>
<li>7/1/20: ACVTS is the only path for obtaining algorithm validations</li>
</ul>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p class="p2" style="text-align: left;"><strong><span class="s2">About Algorithm Testing and FIPS 140-2</span></strong></p>
<p><span class="s1"><a href="https://sitdev.corsec.com/fips-140-2/"><span style="color: #008000;">FIPS 140-2</span></a> is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2. Product vendors are required to complete validation testing of FIPS-approved and NIST-recommended cryptographic algorithms and their individual components.</span></p>
<p><span class="s1">FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency. </span><span class="s1">FIPS is mandated by law in the U.S. and very strictly enforced in Canada, it is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>About Corsec Security, Inc.</strong></p>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span></strong>, <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS 140-3 APPROVED</title>
		<link>https://sitdev.corsec.com/fips-140-3-approved/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 01 May 2019 15:52:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17777</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>A <a id="" href="https://www.federalregister.gov/documents/2019/05/01/2019-08817/announcing-issuance-of-federal-information-processing-standard-fips-140-3-security-requirements-for" target="_blank" rel="noopener noreferrer">Federal Register Notice</a> has been issued for the &#8220;Federal Information Processing Standard (<span style="color: #008000;"><a id="" style="color: #008000;" title="FIPS 140" href="https://csrc.nist.gov/publications/detail/fips/140/3/final" target="_blank" rel="noopener noreferrer">FIPS</a></span>) 140-3, Security Requirements for Cryptographic Modules&#8221;.</p>
<p>Having now been signed by the U.S. Commerce Secretary, it is official, FIPS 140-3 has been approved!</p>
<p style="padding-left: 40px;"><em>&#8220;This notice announces the Secretary of Commerce&#8217;s issuance of Federal Information Processing Standard (FIPS) 140-3, Security Requirements for Cryptographic Modules. <span style="color: #008000;">FIPS 140-3</span> includes references to two existing international standards: International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 19790:2012(E) Information technology — Security techniques — Security requirements for cryptographic modules, and ISO/IEC 24759:2017(E) Information technology — Security techniques — Test requirements for cryptographic modules. As permitted by those standards, NIST Special Publication (SP) series 800-140 will specify updates, replacements, or additions to the currently-cited ISO/IEC standard, as necessary. Those new SP 800-140 documents (currently under development) will consolidate implementation guidance and administrative guidance, and will be made available for public review and comment.&#8221;</em></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Key Dates:</strong></p>
<p>Companies actively working on or planning a FIPS validation will inevitably face decisions around which standard to work towards. The following dates will be critical for those projects:</p>
<ul>
<li><span style="color: #339966;">Draft For Comments: Complete</span></li>
<li><span style="color: #339966;">Effective Date: Complete</span></li>
<li><span style="color: #339966;">Publication of the Standard: Complete</span></li>
<li><span style="color: #339966;">Supporting Documents for FIPS 140-2 &amp; the CMVP Released: Complete</span></li>
<li>New Testing Begins: 9/22/20</li>
<li>140-3 Mandated &amp; The Last Day for 140-2 Submissions: 9/22/21 (This means Labs must submit their Lab reports to CMVP by this date)</li>
</ul>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Documentation:</b></p>
<p>CMVP wants to minimize the content in the series of NIST SP 800-140 documents because they hope to be as close to the international standard as possible. These are the documents that we believe will replace the existing FIPS 140-2 DTR, Appendices, and Annexes:</p>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140/final">NIST SP 800-140</a></span> – <em>FIPS 140-3 Derived Test Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140a/final">NIST SP 800-140A</a></span> – <em>CMVP Documentation Requirements</em></li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-140b/final"><span style="color: #3366ff;">NIST SP 800-140B</span></a> – <em>CMVP Security Policy Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140c/final">NIST SP 800-140C</a> </span>– <em>CMVP Approved Security Functions</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140d/final">NIST SP 800-140D</a> </span>– <em>CMVP Approved Sensitive Security Parameter Generation and Establishment Methods</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140e/final">NIST SP 800-140E</a></span> – <em>CMVP Approved Authentication Mechanisms</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140f/final">NIST SP 800-140F</a></span> – <em>CMVP Approved Non-Invasive Attack Mitigation Test Metrics</em></li>
</ul>
<p>A notable omission from the new SP 800-140 series is any reference document for Approved Protection Profiles from Common Criteria (a CC-certified operating system was required for software validations at level 2 and above).</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Early Review and Analysis:</b></p>
<p>This release has been a long time coming. We still expect additional updates and changes to come, but Corsec has reviewed the public documents and found the following areas to be of interest:</p>
<ul>
<li>Rather than encompassing the module requirements directly, FIPS 140-3 references ISO/IEC 19790:2012. The testing for these requirements will be in accordance with ISO/IEC 24759:2017</li>
<li>This version of FIPS 140-3 retains the 4 levels of validation</li>
<li>The sections in FIPS 140-3 are now as follows:
<ol>
<li>Cryptographic Module Specification</li>
<li>Cryptographic Module Interfaces</li>
<li>Roles, Services, And Authentication</li>
<li>Software/Firmware Security</li>
<li>Operating Environment</li>
<li>Physical Security</li>
<li>Non-Invasive Security</li>
<li>Sensitive Security Parameter Management*</li>
<li>Self-Tests</li>
<li>Life-Cycle Assurance</li>
<li>Mitigation of Other Attacks</li>
</ol>
</li>
</ul>
<p style="padding-left: 80px;"><strong>*</strong>Sensitive Security Parameters is a new category &#8211; SSPs include both CSPs and PSPs (Public Security Parameters)</p>
<p style="padding-left: 80px;"><strong>**</strong>Finite State Model was removed but may have been absorbed into section 11</p>
<p style="padding-left: 80px;"><strong>***</strong>EMI/EMC was removed. There was no mention of EMI/EMC in the draft ISO 24759 either</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Moving Forward:</strong></p>
<ol>
<li>Get Ahead: Be the first to complete the new standard (<span style="color: #008000;"><a style="color: #008000;" href="https://csrc.nist.gov/publications/detail/fips/140/3/final">FIPS 140-3</a></span>)</li>
<li>Revalidate Early: Avoid the new requirements prior to the mandated transition date and add 5 years to your current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> validation</li>
<li>Plan Accordingly &#8211; Products being evaluated against FIPS 140-2 during testing transition may face problems completing their certification under old requirements.</li>
</ol>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec participates in numerous committees, technical working groups, certification leadership positions, and industry events. As more information develops, we will deliver updates. Stay informed on all the program details, requirements, and timelines associated with FIPS 140-3 – <a href="https://ww3.corsec.com/subscribe">Subscribe</a></p>
<p>For more information on the current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> program, requirements, and process &#8211; <a href="https://sitdev.corsec.com/fips-140-2/">visit here</a>.</p>
<p>For any questions on how this will affect current or future FIPS projects, <a href="https://sitdev.corsec.com/contact-us/">contact Corsec</a>!</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Certes CFNC Achieves Common Criteria</title>
		<link>https://sitdev.corsec.com/certes-cnfc-cc/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 15 Apr 2019 16:06:59 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Customers]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17790</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>Corsec would like to congratulate our partner, Certes Networks, Inc. (Certes), for completing the <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) certification process on their CryptoFlow Net Creator (CFNC) with CEP.</p>
<p>To achieve this milestone, Certes partnered with Corsec, completing the certification under the Italian scheme at an EAL4+. For more information on the validation and to find additional details on the CFNC certification, visit the <a href="https://www.commoncriteriaportal.org/products/">CC Certified Products List</a>.</p>
<p>Their completion of the <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> certification process demonstrates their commitment to strong levels of security, including a government backed product offering and a dedication to providing customers and end users with the most scrutinized and highly tested security solutions.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong><span class="s3">About Common Criteria</span></strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p class="p1"><span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) is an internationally recognized set of guidelines (ISO 15408), which define a common framework for evaluating security features and capabilities of Information Technology security products. The standard consists of several predetermined evaluation assurance levels, each one more stringent than the last. Common Criteria allows vendors to have their products tested against a chosen level by an independent third-party testing laboratory. The Common Criteria Mutual Recognition Agreement (CCRA) is a pact, which was designed to allow all evaluations up to an evaluation assurance level (EAL) 2, to be recognized by all participating countries, regardless of where the evaluation was completed. There are currently 30 countries involved in the CCRA, including the United States and Canada, with others that follow unofficially such as the EU.</p>
<p class="p1">The U.S. government mandates Common Criteria certification of security products for federal purchases. The National Information Assurance Acquisition Policy, NSTISSP No. 11, requires agencies to purchase only those commercial security products that have met specified third-party assurance requirements and have been tested by an accredited national laboratory.</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper"></div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>About the Certes CFNC and CEP</strong></h5>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>CryptoFlow Net Solutions enable you to set automatic traffic protection policies on any standards-based network, including LAN, WAN, WiFi, Internet, SDN/NFV and others.</p>
<p>CryptoFlow Net Creator is the management solution providing centralized policy definition and control over all CryptoFlow Net Enforcers. CryptoFlow Net Creator enables all keys for all network protection to be generated and managed from one central point of control. It is a web-based GUI that configures and monitors the Certes Enforcement Points (CEP) encryption appliances, stores and deploys policies (or rules), and provides key management and auditing capabilities. CEPs are purpose-built encryption appliances that provide multi-layer data protection and application segmentation.</p>
<h5><strong>About Corsec Security, Inc.</strong></h5>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <a href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5><strong>Connect With Us</strong></h5>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HPE Smart Array Gen10 P-Class RAID Controllers</title>
		<link>https://sitdev.corsec.com/hpe-raid-fips/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 14 Mar 2019 20:49:29 +0000</pubDate>
				<category><![CDATA[Customers]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17811</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec would like to congratulate the entire HPE Smart Array team on completing the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process. The completion of the certification process not only opens the doors to new and exciting markets for HPE, but also demonstrates their fervent commitment to product security.</p>
<p>To achieve this milestone, HPE partnered with Corsec, completing the validation at a Level 1 as seen in certificate #<span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3397">3397</a></span>. For more information on the validation and to find additional details on the security policy, visit <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3397">NIST’s validated modules site</a></span>.</p>
<p>Their completion of the <span style="color: #339966;"><span class="s1"><a style="color: #339966;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> </span>validation process demonstrates their commitment to strong levels of security, including a government backed product offering and a dedication to providing customers and end users with the most scrutinized and highly tested security solutions.</p>
<p>For more information on engineering your product to meet Federal and regulated industry security requirements, <a href="https://sitdev.corsec.com/contact-us/">schedule time to speak to a Corsec engineer</a>.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p class="p2" style="text-align: left;"><strong><span class="s2">About FIPS 140-2</span></strong></p>
<p><span class="s1"><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> is a joint effort by the National Institute of Standards and Technology (NIST) in the United States, and the Communications Security Establishment Canada (CSEC), under the Canadian government. The Cryptographic Module Validation Program (CMVP), headed by NIST, provides module and algorithm testing for FIPS 140-2, which applies to Federal agencies using validated cryptographic modules to protect sensitive government data in computer and telecommunication systems. FIPS 140-2 provides stringent third-party assurance of security claims on any product containing cryptography that may be purchased by a government agency.</span></p>
<p><span class="s1">FIPS, which is mandated by law in the U.S. and very strictly enforced in Canada, is also currently being reviewed by ISO to become an international standard. FIPS 140-2 is gaining worldwide recognition as an important benchmark for third party validations of encryption products of all kinds. A FIPS 140-2 validation of a product provides end users with a high degree of product security, assurance, and dependability.</span></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>About Corsec Security, Inc.</strong></p>
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <strong><span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span></strong>, <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://sitdev.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC) and the <span style="color: #000080;"><a style="color: #000080;" href="https://sitdev.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a></span>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
<div class="wpb_text_column wpb_content_element "></div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h4><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h4>
</div>
</div>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED ROUNDUP: FEBRUARY 2019</title>
		<link>https://sitdev.corsec.com/fed-feb19/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 26 Feb 2019 16:09:41 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16953</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 style="text-align: left;"><span style="color: #000000;"><strong><a style="color: #000000;" href="http://sitdev.disa.mil/newsandevents">DISA’s February News</a></strong></span></h5>
<ul>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/Adobe_data_impact_level_4"><span style="color: #0000ff;">DISA grants Provisional Authorization (PA) with conditions to the Adobe Experience Manager for Managed Services (AEMMS) at data Impact Level 4</span></a></li>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/Cloud_Services_data_impact_level_5"><span style="color: #0000ff;">DISA grants Provisional Authorization (PA) with conditions to PTC Cloud Services at data Impact Level 5</span></a></li>
<li><a href="https://sitdev.disa.mil/NewsandEvents/2019/5_JRSS_concerns_addressed"><span style="color: #0000ff;">DISA addresses 5 mission partner concerns regarding Joint Regional Security Stacks (JRSS)</span></a></li>
</ul>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST’s February News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #0000ff;"><span style="color: #0000ff;">None</span></span></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2019/stateful-hbs-request-for-public-comments"><span style="color: #0000ff;"><span style="color: #0000ff;">Requests for Public Comments on &#8220;Stateful Hash-Based Signatures (HBS)&#8221;</span></span></a></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2019/draft-nist-sp-800-205-available-for-comment">Draft NIST Special Publication 800-205, &#8220;Attribute Considerations for Access Control Systems&#8221;</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/News/2019/NIST-Updates-SP-800-162">Updates to Special Publication 800-162, &#8220;Guide to Attribute Based Access Control (ABAC) Definition and Considerations&#8221;</a></span></li>
<li><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://csrc.nist.gov/publications/detail/sp/800-177/rev-1/final">Special Publication 800-177, Rev. 1, &#8220;Trustworthy Email&#8221;</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s February News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><span style="color: #0000ff;">None</span></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<p><a href="https://sitdev.niap-ccevs.org/Announcements/Announcements.cfm"><span style="color: #0000ff;">The Full Drive Encryption (FDE) international Technical Community (iTC) has published the following:</span></a></p>
<ul>
<li><span style="color: #0000ff;">FDE Encryption Engine (EE) Collaborative Protection Profile (cPP) v2.0</span></li>
<li><span style="color: #0000ff;">FDE EE Supporting Document (SD) v2.0</span></li>
<li><span style="color: #0000ff;">FDE Authorization Acquisition (AA) cPP v2.0</span></li>
<li><span style="color: #0000ff;">FDE AA SD v2.0</span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CDM: The Old and The New</title>
		<link>https://sitdev.corsec.com/cdm-the-old-and-the-new/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 13 Feb 2019 14:45:13 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CDM]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16809</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>The Continuous Diagnostics and Mitigation Program</strong></h5>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">The Continuous Diagnostics and Mitigation (CDM) Program was originally a multiple award IDIQ released under the GSA Schedule 7o Blanket Purchase Agreement (BPA). It was</span> created to establish &#8220;a dynamic approach to fortifying the cybersecurity of government networks and systems.&#8221;</p>
<p>The program was<span style="font-style: inherit !important; font-weight: inherit !important;"> designed to provide the Department of Homeland Security and other federal agencies with the capabilities, resources, and tools to</span> 1.) Identify cybersecurity risks on an ongoing basis, 2.) Prioritize these risks based upon potential impacts, and 3.) Enable cybersecurity personnel to mitigate the most significant problems first.</p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">As threats changed, the CDM program offered federal agencies COTS tools to support technical modernization efforts. Additionally, CDM provided a structured methodology to allow for risk prioritization based on perceived impact, with the goal of mitigating the most significant risks, flaws, and bugs first. To do this, CDM used a four-phase process with an end goal of collecting and analyzing vulnerabilities data to make “strategic decisions regarding systematic cyber security risks across the entire Federal civilian enterprise.” </span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">Ultimately, CDM provided a means to address and react to threats as they occurred, which decreased vulnerabilities and mitigated the risk of network exploitation.</span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">Since its inception, the acquisition strategy for the CDM program changed. As stated, it originally was a DHS issued Blanket Purchase Agreements (BPA) under the GSA IT Schedule 70 contract, known and referred to as the CDM Tools/Continuous Monitoring as a Service (CMaaS) BPAs. These BPAs expired in August of 2018. </span></p>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">To continue the mission and goals of the program, t</span><span style="font-style: inherit !important; font-weight: inherit !important;">he following two acquisition strategies were developed to allow Vendors to compete on projects that address the mission of CDM:</span></p>
<ul>
<li><span style="font-style: inherit !important; font-weight: inherit !important;"><strong>For Products </strong>(SW &amp; HW) – Issuance of a CDM Tools SIN (132-44) under the GSA IT Schedule 70</span></li>
<li><span style="font-style: inherit !important; font-weight: inherit !important;"><strong>For Services</strong> &#8211; Task Orders referred to as CDM Dynamic and Evolving Federal Enterprise Network Defense (DEFEND) under the GSA GWAC Alliant</span></li>
</ul>
<p><span style="font-style: inherit !important; font-weight: inherit !important;">The programs are still consistent with NIST and OMB guidance as well as fulfillment of the Federal Information Security Management Act (FISMA).</span></p>
<h5><strong>CDM Tools SIN (132-44)</strong></h5>
<p>The new SIN is organized into five subcategories based on CDM capabilities:</p>
<ol>
<li>Manage “What is on the network?”</li>
<li>Manage “Who is on the network?”</li>
<li>Manage “How is the network protected?”</li>
<li>Manage “What is happening on the network?”</li>
<li>Emerging Tools and Technology</li>
</ol>
<p>To be added to the CDM Tools SIN, Vendors must submit their product for qualification review. Prior to applying, vendors must first have their product listed on the DHS Approved Products List (APL), and second, be a current holder of the GSA Schedule 70 GWAC. Acceptance onto the APL is reviewed on a monthly basic &#8211; the process to being added can be found <a href="https://sitdev.gsa.gov/technology/technology-products-services/it-security/continuous-diagnostics-mitigation-cdm/continuous-diagnostics-mitigation-cdm-tools-special-item-number-sin-information-for-vendors">here</a>.</p>
<p>A current list of all vendors and products currently available for procurement under the CDM Tools SIN can be found <a href="https://sitdev.gsaelibrary.gsa.gov/ElibMain/sinDetails.do?executeQuery=YES&amp;scheduleNumber=70&amp;flag=&amp;filter=&amp;specialItemNumber=132+44">here</a>.</p>
<p>For help with requirements or other certification related concerns, please reach out and discuss with a Corsec expert &#8211; <a href="https://sitdev.corsec.com/contact-us/">Connect</a></p>
<p>&nbsp;</p>
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;">Stay Up to Date:</strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://ww3.corsec.com/subscribe">Subscribe</a></span></p>
<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<h5 class="wpb_text_column wpb_content_element "><strong><a href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>
</div>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<div class="wpb_text_column wpb_content_element "><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>
</div>
</div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED IT Spending: Reviewing 2018 &#038; Gauging 2019</title>
		<link>https://sitdev.corsec.com/2018-review/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 12 Oct 2018 17:48:11 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[federal spending]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[IT spending]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=16659</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>2018 FEDERAL YEAR IN REVIEW</strong></h4>
<p>2018 was a stellar year for companies doing business with U.S. Federal Agencies. Over <strong>$95.6 billion dollars</strong> were allocated towards the procurement of secured IT products and solutions across Civilian, DoD, and the IC agencies.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>2018 DoD IT Spend |</b> $35.7 billion</h5>
<p>$42.5 billion originally allocated &#8211; not all spending has been recorded*</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>2018 Civilian IT Spend |</b> $45.5 billion</h5>
<p>$53.1 billion originally allocated &#8211; not all spending has been recorded*</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Top 5 Agencies</b>: Predicted % of Total Spend*</h5>
<p>DoD: ~44.4%<br />
HHS: ~14.5%<br />
DHS: ~7.1%<br />
Treasury: ~4.5%<br />
VA: ~4.3%</p>
<p>*Data based on 2018 White House and OMB projected and released findings.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Modernization</b>: Improving the U.S. Critical Infrastructure</h5>
<p>According to the President and OMB&#8217;s release on Information Technology, &#8220;The Administration will work to modernize and improve government operations and service delivery by building modern citizen-facing digital services, buying more like a business, improving cybersecurity, investing in improved data analytics, and generating greater cost efficiencies.&#8221;</p>
<p>This further emphasizes the President&#8217;s focus on improving the homeland&#8217;s IT support system. In May of 2017, he signed an <a href="https://sitdev.corsec.com/cybersecurity-executive-order/">Executive Order</a> to modernize and strengthen our technology infrastructure.</p>
<p>Additional information on the current status of the modernization effort can be found <a href="https://sitdev.corsec.com/federal-modernization/">here</a>.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>2019 FEDERAL OUTLOOK</strong></h4>
<p>The President of the U.S. recently signed the Department of Defense Appropriations Bill that provides over <strong>$674 billion dollars</strong> to fund military operations in 2019.</p>
<p>This is a $19.8-billion increase from the FY 2018.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Estimated 2019 DoD IT Spend |</b> $46.4 billion</h5>
<p>According to the Physical 2019 request, $36.4 billion will be allocated towards unclassified IT, $10 billion to classified, and $8.6 billion to cyberspace activities</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><b>Estimated 2019 Civilian IT Spend |</b> $45.8 billion**</h5>
<p>This is a decrease from previous years, although the previous IT budget included grants made by Federal agencies to state and local governments for IT systems used to administer Federal benefits.</p>
<p>The FY 2019 budget includes funding and investments to support 3 main functions: 1.) mission delivery; 2.) IT infrastructure, IT security, and IT management; and 3.) administrative services and support systems.</p>
<p>**Data based on 2019 White House and OMB projected release.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h4 style="text-align: left;"><strong>Connect With Us</strong></h4>
<div class="wpb_text_column wpb_content_element ">
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></p>
</div>
<p style="text-align: center;">###</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.linkedin.com/in/jake-nelson-63601bb">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><a href="https://sitdev.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://sitdev.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 21:44:28 by W3 Total Cache
-->