NIST SP 800-140: Important Supplemental Docs (cont'd)
11
What happens to the "duct tape"?
12
New Terms: SSPS, CSPs and PSPs
13
New Terms: New Output Types Defined
14
New Terms: Vendor Testing, Low-Level Testing & EOL
15
The Diff: Dash-2 vs. Dash-3 Snapshot
16
The Diff: Those Dang Self-tests (continued)
17
The Diff: Roles, Services and Authentication
18
The Diff: Let's get physical (Physical Security)
19
The Diff: Software/Firmware and OS Security
20
The Diff: Actual Non-Invasive Security Requirements
21
The Diff: It's "Zeroisation", Not "Zeroization"!
22
FIPS 140-3 transition: Important dates
23
Apply: Can I achieve BOTH FIPS 140-2 and FIPS 140-3?
24
Apply: In closing, points to remember ...
25
Apply: How to stay in the loop?
Description:
Explore the key changes and implications of the new FIPS 140-3 cryptographic module validation standard in this 46-minute conference talk from RSA Conference. Delve into the differences between FIPS 140-2 and FIPS 140-3, examining new terminology, testing requirements, and security considerations. Learn about the transition timeline, the fate of existing FIPS 140-2 certificates, and how to navigate the validation process under the new standard. Gain insights into the challenges faced by labs and the Cryptographic Module Validation Program (CMVP) in adapting to evolving security needs. Discover practical advice for staying informed and preparing for the FIPS 140-3 transition, with a focus on its impact on cryptographic module development and certification.
You, Me and FIPS 140-3 - A Guide to the New Standard and Transition