ConceptioArchiveNIST
NISTpublic full text

NIST FIPS 140-3: Security Requirements for Cryptographic Modules

National Institute of Standards and Technology · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
federalstandardfipsnist
federal standard, cryptography, FIPS, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications FIPS 140-3 Security Requirements for Cryptographic Modules Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: March 22, 2019 Supersedes: FIPS 140-2 (12/03/2002) Planning Note ( 05/01/2019 ): See the FIPS 140-3 Transition project for the following information: FIPS 140-3 Transition Schedule Supporting SP 800-140x documents that modify requirements of ISO/IEC 19790:2012 and ISO/IEC 24759:2017 Author(s) National Institute of Standards and Technology Abstract The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems.   This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347. This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract.  The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments.  The security requirements cover areas related to the secure design, implementation and operation of a cryptographic module.  These areas include cryptographic module specification; cryptographic module interfaces; roles, services, and authentication; software/firmware security; operating environment; physical security; non-invasive security; sensitive security parameter management; self-tests; life-cycle assurance; and mitigation of other attacks. The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems.   This standard is applicable to all federal agencies that use cryptographic-based... See full abstract The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems.   This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347. This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract.  The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments.  The security requirements cover areas related to the secure design, implementation and operation of a cryptographic module.  These areas include cryptographic module specification; cryptographic module interfaces; roles, services, and authentication; software/firmware security; operating environment; physical security; non-invasive security; sensitive security parameter management; self-tests; life-cycle assurance; and mitigation of other attacks. Hide full abstract Keywords computer security ; telecommunication security ; physical security ; software security ; cryptography ; cryptographic modules ; Federal Information Processing Standard (FIPS) ; ISO/IEC 19790:2012 ; ISO/IEC 24759:2014 Control Families None selected Documentation Publication: https://doi.org/10.6028/NIST.FIPS.140-3 Download URL Supplemental Material: Cryptographic Module Validation Program (CMVP) NIST News Article Related NIST Publications: ITL Bulletin SP 800-140 Document History: 07/13/07: FIPS 140-3 (Draft) 12/11/09: FIPS 140-3 (Draft) 03/22/19: FIPS 140-3 (Final) Topics Security and Privacy cryptography , testing & validation Laws and Regulations E-Government Act , Federal Information Security Modernization Act HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2808 · SHA-256 40841e6c3ce79d7e
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.