Technology Sectors

Market Sectors

NIST invites comments on latest version of FIPS 140 standard for cryptographic modules

Eleven years after the most-recent version of FIPS-140 was issued, and seven years after it announced its intention to issue a third version, the National Institute of Standards and Technology (NIST) is still wrestling with a handful of “gaps and inconsistencies” among the various comments to that third version that have been submitted by members of the public.

To try to sort out those inconsistencies, NIST has invited the public to submit further comments by October 1, 2012 on a range of issues related to security requirements for cryptographic modules. Those issues include “trusted channels, “trusted roles,” physical security, sensitive security parameters and operator authentication mechanisms, according to a Federal Register notice published by NIST on August 30.

The draft standard, known as Federal Information Processing Standard (FIPS) 140-3, is intended to replace FIPS 140-2, which was put in place in 2001 as a substitute for FIPS 140-1, which was originally issued in 1994.

“FIPS 140-2 identifies requirements for four security levels for cryptographic modules to provide for a wide spectrum of data sensitivity (e.g., low value administrative data, million dollar funds transfers, and life protecting data), and a diversity of application environments,” explains the notice.

The current FIPS 140-2 standard and the proposed draft can be seen by clicking here.

Comments about the draft FIPS 140-3 standard can be made by sending an email to FIPS140-3@nist.gov

Further information is available from Dr. Michaela Iorga, of NIST’s computer division, at 301-975-8431.

 

 

Upcoming Events

Event Details Dates of Event
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21