Sitemap
Press enter or click to view image in full size

Member-only story

A Bluffer’s Guide to FIPS

4 min readMar 23, 2025

--

There are two core things that have driven the Internet: RFCs (Request for Comments) and FIPS standards. Before these, we had slow and cumbersome methods of standardisation, such as with the ISO, ANSI and IEEE standards. Overall, there are many classic standards that help systems interconnect, including RFC 792 (IP), RFC 793 (TCP), RFC 1945 (HTTP), IEEE 802 (Ethernet), and X.509 (Digital Certificates).

So, if you are into cybersecurity, hopefully you will know about the FIPS (Federal Information Processing Standards) standards. These are defined by NIST and define the standards that are to be used by US federal government departments. Their scope now carries across the world, and any company that is serious about cybersecurity should be complying with them. So, let’s have a quick look at the key standards that your organisation really should be focused on.

Two of the main standards that are defined for FIPS are:

  • FIPS 140–2/FIPS 140–3 — Security Requirements for Cryptographic Modules [here]. These define the baseline methods that should be used for all the cryptographic elements used within a system. Version 2 was defined in 2002, and Version 3 was defined in 2019. Obviously, it can take a while to upgrade systems, so many vendors are still in the process of migrating towards Version 3. Within FIPS 140, there are four different levels of security…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.