FIPS 140 Cryptographic Hardware Validation for Overall Security, v1.0

Approved cryptography hardware devices must be used to ensure overall system security. Systems should be validated for FIPS 140 compliance level.

Assessment Step

1
FIPS 140 Overall (FIPS140Overall)
Does the cryptographic hardware for overall security meet the FIPS 140 requirements at level 1, level2, or level 3? Please include the specific FIPS level as the parameter.
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support the technical details of FIPS 140 Level under which cryptographic hardware was validated.
Parameter
FIPS 140 Levelrequired
NUMBER : This field should be populated with the highest FIPS 140 level that the organization operates at.

Conformance Criteria (1)

C1
Cryptographic authenticators used at AAL2 SHALL use approved cryptography. Authenticators procured by government agencies SHALL be validated to meet the requirements of FIPS 140 Level 1. Multi-factor authenticators used at AAL3 SHALL be hardware cryptographic modules validated at FIPS 140 Level 2 or higher overall with at least FIPS 140 Level 3 physical security. Single-factor cryptographic devices used at AAL3 SHALL be validated at FIPS 140 Level 1 or higher overall with at least FIPS 140 Level 3 physical security.
Citation
NIST SP 800-63B
Sections 4.2.2 and 4.3.2