The Installed Operating System Is FIPS 140-2 Certified
An XCCDF Rule
Description
To enable processing of sensitive information the operating system must provide certified cryptographic modules compliant with FIPS 140-2 standard.
warning alert: Warning
warning alert: Regulatory Warning
Rationale
The Federal Information Processing Standard (FIPS) Publication 140-2, (FIPS PUB 140-2) is a computer security standard. The standard specifies security requirements for cryptographic modules used to protect sensitive unclassified information. Refer to the full FIPS 140-2 standard at http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf for further details on the requirements. FIPS 140-2 validation is required by U.S. law when information systems use cryptography to protect sensitive government information. In order to achieve FIPS 140-2 certification, cryptographic modules are subject to extensive testing by independent laboratories, accredited by National Institute of Standards and Technology (NIST).
- ID
- xccdf_org.ssgproject.content_rule_installed_OS_is_FIPS_certified
- Severity
- High
- References
- Updated