2.3 - Relate how national bodies such as NCSC, GCHQ, NIST and FIPS provide guidance and information to public and private sector organisations Flashcards
What is Federal Information Processing Standard 140-2?
It is the benchmark for validating the effectiveness of cryptographic hardware
Who issued FIPS 140-2?
National Institute of Standards and Technology (NIST)
How many FIPS security levels are there?
4
What is FIPS Level 1?
Level 1: Provides the lowest level of security. Basic security requirements are at least one Approved algorithm or Approved security function and production-grade component are required.
What is FIPS Level 2?
Level 2: Adds requirements for physical tamper-evidence and role-based authentication.
What is FIPS Level 3?
Level 3: Adds requirements for physical tamper-resistance and identity-based authentication.
What is FIPS Level 4?
Level 4: Makes the physical security requirements more stringent, requiring the ability to be tamper-active.
What is a security policy?
A security policy is a formal statement of the rules by which employees who use technology within the company.
What is NIST SP 500?
Computer Systems Technology - includes conference and meeting proceedings; best practice recommendations; and reports on test methods, specifications, and data formats from the Information Technology Laboratory (ITL)
What is NIST SP 800?
Computer Security Series - Publications in the SP800 series present information of interest to the computer security community
What is NIST SP 1800?
NIST Cybersecurity Practice Guides - target specific cybersecurity challenges in the public and private sectors.
What is NIAP?
National Information Assurance Partnership - US CC Certifies protection profiles, approves test labs, evaluate security targets
What are Certificate consuming members?
They recognise CC certifications
What is the CCRA
Common Criteria Recognition Arrangement - Defines the list of members that test CC
What is FIPs used?
In computer systems by non-military American government agencies and government contractors
What is FIPS 197?
Standard for ADVANCED ENCRYPTION STANDARD (AES)
What is FIPS 46-3?
Data Encryption Standard (DES)
What is FIPS 140?
Security requirements for cryptography modules
What is FIPS 137?
Federal Standard for Linear Predictive Coding
What is FIPS 199?
Standards for Security Categorization of Federal Information and Information Systems
What is FIPS FIPS 201?
Personal Identity Verification for Federal Employees and Contractors
What is FISMA?
Federal Information Security Modernization Act of 2014
What does Federal Information Security Modernization Act of 2014 emphasize?
risk-based policy for cost-effective security.
What does FISMA require executive agencies within the federal government to do?
- Plan for security
- Ensure that appropriate officials are assigned security responsibility
- Periodically review the security controls in their systems
- Authorize system processing prior to operations and, periodically, thereafter