
I-2 FIPS 140-2 Standard
LX Series Configuration Guide
FIPS 140-2 Standard
FIPS 140-1 and its successor FIPS 140-2 are U.S. Government
standards that provide a benchmark for implementing
cryptographic software and hardware. They specify best
practices for implementing cryptographic algorithms, handling
key material and data buffers, and working with the operating
system. This standard was published by the National Institute
of Standards and Technology (NIST), and was adopted by the
Canadian government’s Communications Security Establishment
(CSE), and by the financial community through the American
National Standards Institute (ANSI).
Required FIPS 140-2 Validation
FIPS 140-2 validation is required for sale of products
implementing cryptography to the Federal Government.
Although not all agencies are aware of this, more and more
RFPs, contracts, and specifications are requiring FIPS 140-2
certification as a pre-requisite to bid proposals. While it was
once possible to get a waiver signed, thus making a product
exempt from these requirements for a limited amount of time,
that practice was limited by FISMA. Therefore, obtaining a
waiver is now rare.
The financial community increasingly specifies FIPS 140-2 as a
procurement requirement and is beginning to embrace it, wholly
or in part, in its own standards. Finally, the security community
values products that have completed this evaluation, as it
carries the sanction of an independent third party.
The FIPS 140-2 certification approval is tailored specifically for
platforms containing both a Hardware and Software
component. The LX-Series software and ppciboot in conjunction
with the LX-Series Hardware platforms are the first series to be
FIPS 140-2 validated, with other LX-Series platforms to follow.
Comentarios a estos manuales