FIPS 140-2 for Newbies

Here is a collection of links to information about FIPS 140-2:

A software engineer’s guide to encryption: How not to fail (written by Luther Martin of HPE) provides a good overview of the importance of FIPS 140-2.

The FIPS 140-2 Publication has some good introductory material.

It is easy to get bogged down attempting to read start-to-finish. I suggest that you begin by quickly reading the following sections:

  • Section 1 – Overview
  • Section 1.1 – Security Level 1
  • Section 3 – Functional Security Objectives

The CMVP landing page addresses the following topics:

  • What is the purpose of the CMVP?
  • What is the applicability of CMVP to the US government?
  • Use of Unvalidated Cryptographic Modules by Federal Agencies and Departments

We are happy to be a resource to you. Please contact [email protected]

KeyPair Consulting – expert guidance to meet your FIPS 140-2 goals