Browse Definitions :
Definition

Federal Information Processing Standardization 140

Federal Information Processing Standardization 140 is a standard that specifies security requirements for cryptographic modules used by the U.S. government. Federal Information Processing Standardization 140-2 accreditation is required for any cryptography product sold by a private sector company to the U.S. government.

The United States National Institute of Standards and Technology (NIST) develops and issues Federal Information Processing Standardizations (FIPSs) when adequate industry standards do not already exist to ensure that products conform to security requirements. Publication series 140 specifically applies to cryptography modules. The current version of the 140 series is FIPS 140-2.

FIPS 140-2, issued by NIST in 2001, qualitatively specifies security requirements for cryptographic modules in four increasingly severe levels intended to cover the wide range of potential applications and environments in which cryptographic modules might be employed by the government:

Level 1 – The lowest level of security. Requires at least one approved algorithm but no physical security

Level 2 – Requires role-based authentication and some physical security

Level 3 – Requires identity-based authentication and tighter physical security

Level 4 – Highest level of physical security, intended to provide a “complete envelope of protection” around the module

The FIPS 140 requirement is applicable to all U.S. government departments and agencies that use cryptographic-based security systems to protect sensitive but unclassified information, including any organizations selling products to U.S. and Canadian government agencies.

Learn more:

How to verify 140-2 (FIPS 140-2) compliance

USB thumb drive security best practices spelled out by NIST.

This was last updated in June 2010

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

SearchCompliance

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

  • data governance policy

    A data governance policy is a documented set of guidelines for ensuring that an organization's data and information assets are ...

SearchSecurity

  • asymmetric cryptography (public key cryptography)

    Asymmetric cryptography, also known as public-key cryptography, is a process that uses a pair of related keys -- one public key ...

  • Evil Corp

    Evil Corp is an international cybercrime network that uses malicious software to steal money from its victims' bank accounts.

  • Plundervolt

    Plundervolt is a method of hacking that involves depriving an Intel chip of power so that processing errors occur.

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

SearchStorage

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification written for internally mounted storage...

  • RAID (redundant array of independent disks)

    RAID (redundant array of independent disks) is a way of storing the same data in different places on multiple hard disks or ...

  • cache memory

    Cache memory, also called CPU memory, is high-speed static random access memory (SRAM) that a computer microprocessor can access ...

Close