﻿<?xml version="1.0" encoding="utf-8"?>
<etgov:EmergingTechnology xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:etgov="www.cio.gov/AIC/ETgov/">
  <etgov:ComponentDetails>
    <etgov:ComponentName>FIPS 140-2</etgov:ComponentName>
    <etgov:XMLGenerationDate>2006-08-29</etgov:XMLGenerationDate>
    <etgov:ComponentType>Data</etgov:ComponentType>
    <etgov:ComponentDescription>Federal Information Processing Standards Publication 140-2 documents a standard to be used by Federal organizations in cryptographic-based security systems used to provide protection for sensitive or valuable data.</etgov:ComponentDescription>
    <etgov:GovernmentBenefits>The selective application of technological and related procedural safeguards is an important responsibility of every Federal organization in providing adequate security in its computer and telecommunication systems.  Protection of a cryptographic module within a security system is necessary to maintain the confidentiality and integrity of the information protected by the module. This standard specifies the security requirements that will be satisfied by a cryptographic module. The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments. The security requirements cover areas related to the secure design and implementation of a cryptographic module. These areas include cryptographic module specification; cryptographic module ports and interfaces; roles, services, and authentication; finite state model; physical security; operational environment; cryptographic key management; electromagnetic interference/electromagnetic compatibility (EMI/EMC); self-tests; design assurance; and mitigation of other attacks.

For additional information see http://csrc.nist.gov/cryptval/140-2.htm</etgov:GovernmentBenefits>
    <etgov:Categorizations>
      <etgov:Categorization etgov:categorizationScheme="FEA">
        <etgov:ServiceReferenceModelInformation>
          <etgov:ServiceType>Records Management</etgov:ServiceType>
        </etgov:ServiceReferenceModelInformation>
        <etgov:TechnicalReferenceModelInformation>
          <etgov:ServiceArea>Component Framework</etgov:ServiceArea>
          <etgov:ServiceCategory>Security</etgov:ServiceCategory>
          <etgov:ServiceStandard>Supporting Security Services</etgov:ServiceStandard>
          <etgov:ProposedSpecification>FIPS 140-2</etgov:ProposedSpecification>
        </etgov:TechnicalReferenceModelInformation>
      </etgov:Categorization>
    </etgov:Categorizations>
  </etgov:ComponentDetails>
</etgov:EmergingTechnology>