Warning: The magic method WPML_Absolute_Url_Persisted::__wakeup() must have public visibility in /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php on line 30

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":6446,"date":"2013-11-27T23:18:25","date_gmt":"2013-11-27T23:18:25","guid":{"rendered":"http:\/\/corsec.com\/?p=6446"},"modified":"2018-08-02T16:49:08","modified_gmt":"2018-08-02T20:49:08","slug":"fips-validation-steps","status":"publish","type":"post","link":"https:\/\/www.corsec.com\/fips-validation-steps\/","title":{"rendered":"Decisions In A FIPS 140-2 Validation"},"content":{"rendered":"

Trying to decide whether to perform a FIPS 140-2 validation on your product? It can actually be a pretty black and white decision. If you want to sell any product containing cryptography to any U.S. government agency or department, then the answer is clear cut: you need a FIPS 140-2 validation.<\/p>\n

What is a FIPS 140-2 Validation?<\/strong><\/h2>\n

FIPS 140-2 validation is required for products that contain cryptography and will be used with systems that process sensitive but unclassified information. The National Institute of Standards for Technology (NIST) and the Communications Security Establishment Canada (CSEC) developed FIPS 140-2 in 2001 specifically to protect sensitive information in computer and telecommunication systems.<\/p>\n

The FIPS 140-2 process can be lengthy and expensive, which can be taxing on a company\u2019s internal systems \u2014 it\u2019s a huge undertaking. But for many, the end result is worth it: Once your cryptographic module is validated, you can sell it to any<\/i> agency or department within the U.S. government.<\/p>\n

The first five steps in the FIPS 140-2 Process:<\/strong><\/h4>\n

1. Prepare\/make a good plan for your validation<\/p>\n

The time-consuming and potentially costly FIPS 140-2 process will run much more smoothly if you have a good game plan from the beginning. First, figure out how validation will affect other projects and how you can get a strong return on investment. Then decide who will be on your FIPS 140-2 team, which should include members from your marketing, sales, executive management, and quality assurance divisions. Involving team members from across the company will ensure that key members stay are aware of and stay focused on achieving the validation, and remain mindful that a validation can be a drain on other resources in the company, as well. Finally, determine whether your internal staff can provide the appropriate and ample documentation required for certification. Appointing staff members to a documentation team can help streamline this FIPS 140-2 process.<\/p>\n

2. Assess your product<\/p>\n

Assessing your product in the beginning will help prevent roadblocks along the way. Many products undergoing validation require functionality and code changes before they can be validated against the FIPS 140-2 standard. Since it\u2019s much easier to change a product in the initial stages of the development cycle, it\u2019s important to conduct proper assessments before<\/i> beginning the FIPS 140-2 process. Consider analyzing your designs against the FIPS 140-2 requirements and making adjustments if needed to meet the FIPS standards.<\/p>\n

3. Prepare a budget<\/p>\n

Knowing what costs to expect and when will help avoid budget overruns. Prepare a budget in the beginning that includes items such as the fee for your FIPS 140-2 certificate and the testing lab fees. But make sure to take into account both the hard costs and the soft costs associated with the FIPS 140-2 process. For example, choosing a lab with lower testing fees may look like a wise decision early on. But if your team doesn\u2019t have experience preparing documentation for a particular lab, this could end up being a costly setback. This is an area where a consultant can sometimes be a great asset. A consultant will have extensive FIPS 140-2 validation experience with many testing labs in both the U.S. and in other countries\u2014and will know how each lab wants its documentation prepared and will be willing to handle all of the communication with the lab for you (see No. 5).<\/p>\n

4.\u00a0Choose a lab<\/p>\n

There are many factors to consider when choosing the right FIPS 140-2 testing lab that go beyond cost alone. First, can you negotiate a fixed price for testing, reports, and the site visit? Doing so can prevent overtime costs if your project takes longer to complete. A lab that has more people assigned to your project can mean a more efficient FIPS 140-2 process. You should also select a lab that can show you that they will provide frequent and detailed communication throughout the entire FIPS 140-2 process so you feel informed during the project. Also find out about the lab\u2019s track record for project completion. They may or may not be equipped to circumvent delays that can occur if you miss milestones or if your documentation is lacking. We recommend getting price quotes from a few labs before making a final decision.<\/p>\n

5. Consider a\u00a0Third Party Vendor<\/p>\n

A consultant will prepare and revise all of the documentation and algorithm testing required for validation and communicate with the lab throughout the entire FIPS 140-2 process. This frees up your staff to focus on product development. And, because consultants are familiar with FIPS, they are able to quickly address common problems that may arise during the FIPS 140-2 process, preventing costly and time-consuming delays. That means you\u2019ll be able realize the ROI on your validation and your product even faster.<\/p>\n","protected":false},"excerpt":{"rendered":"

Trying to decide whether to perform a FIPS 140-2 validation on your product? It can actually be a pretty black and white decision. If you want to sell any product containing cryptography to any U.S. government agency or department, then the answer is clear cut: you need a FIPS validation. FIPS 140-2 validation is required for products that contain…<\/p>\n","protected":false},"author":2,"featured_media":6403,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,5],"tags":[82,4,39],"class_list":["post-6446","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-fips-140-2","tag-certification-process","tag-fips-140-2","tag-security-certifications","infinite-scroll-item","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","no-featured-image-padding"],"yoast_head":"\nFIPS 140-2 Process - What are The Step To Getting Validated<\/title>\n<meta name=\"description\" content=\"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.corsec.com\/fips-validation-steps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FIPS 140-2 Process - What are The Step To Getting Validated\" \/>\n<meta property=\"og:description\" content=\"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.corsec.com\/fips-validation-steps\/\" \/>\n<meta property=\"og:site_name\" content=\"Corsec Security, Inc.\u00ae\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/CorsecInc\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/sitdev.facebook.com\/pages\/Corsec\/158518584300710\" \/>\n<meta property=\"article:published_time\" content=\"2013-11-27T23:18:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-08-02T20:49:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"792\" \/>\n\t<meta property=\"og:image:height\" content=\"612\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jake Nelson\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/corsecsecurity\" \/>\n<meta name=\"twitter:site\" content=\"@CorsecSecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jake Nelson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/\",\"url\":\"https:\/\/www.corsec.com\/fips-validation-steps\/\",\"name\":\"FIPS 140-2 Process - What are The Step To Getting Validated\",\"isPartOf\":{\"@id\":\"https:\/\/www.corsec.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg\",\"datePublished\":\"2013-11-27T23:18:25+00:00\",\"dateModified\":\"2018-08-02T20:49:08+00:00\",\"author\":{\"@id\":\"https:\/\/www.corsec.com\/#\/schema\/person\/2249eea128c62c76370cf0ea198ef599\"},\"description\":\"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.corsec.com\/fips-validation-steps\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage\",\"url\":\"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg\",\"contentUrl\":\"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg\",\"width\":792,\"height\":612,\"caption\":\"FIPS 140-2, FIPS 140-2 validation, FIPS Validation, FIPS 140-2 process, FIPS Inside, FIPS Compliant\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.corsec.com\/fips-validation-steps\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.corsec.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Decisions In A FIPS 140-2 Validation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.corsec.com\/#website\",\"url\":\"https:\/\/www.corsec.com\/\",\"name\":\"Corsec Security, Inc.\",\"description\":\"Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL \/ UC APL.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.corsec.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.corsec.com\/#\/schema\/person\/2249eea128c62c76370cf0ea198ef599\",\"name\":\"Jake Nelson\",\"description\":\"Jake Nelson leads Corsec's strategic direction for marketing and communication. He has nearly a decade of experience in corporate branding, content marketing, social media, marketing strategy and federal sales. Prior to Corsec, Jake helped start a sales and marketing consulting firm in the Washington DC area. He has also held various positions as head of sales, including the Director of federal civilian sales for an IT government contractor. Jake received his bachelor of business administration with a focus in Business to Business Marketing from James Madison University.\",\"sameAs\":[\"http:\/\/www.corsec.com\",\"https:\/\/sitdev.facebook.com\/pages\/Corsec\/158518584300710\",\"https:\/\/sitdev.linkedin.com\/pub\/jake-nelson\/b\/1b\/636\",\"https:\/\/x.com\/https:\/\/twitter.com\/corsecsecurity\"],\"url\":\"https:\/\/www.corsec.com\/author\/marketing\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FIPS 140-2 Process - What are The Step To Getting Validated","description":"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.corsec.com\/fips-validation-steps\/","og_locale":"en_US","og_type":"article","og_title":"FIPS 140-2 Process - What are The Step To Getting Validated","og_description":"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.","og_url":"https:\/\/www.corsec.com\/fips-validation-steps\/","og_site_name":"Corsec Security, Inc.\u00ae","article_publisher":"https:\/\/www.facebook.com\/CorsecInc\/","article_author":"https:\/\/sitdev.facebook.com\/pages\/Corsec\/158518584300710","article_published_time":"2013-11-27T23:18:25+00:00","article_modified_time":"2018-08-02T20:49:08+00:00","og_image":[{"width":792,"height":612,"url":"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg","type":"image\/jpeg"}],"author":"Jake Nelson","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/corsecsecurity","twitter_site":"@CorsecSecurity","twitter_misc":{"Written by":"Jake Nelson","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.corsec.com\/fips-validation-steps\/","url":"https:\/\/www.corsec.com\/fips-validation-steps\/","name":"FIPS 140-2 Process - What are The Step To Getting Validated","isPartOf":{"@id":"https:\/\/www.corsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage"},"image":{"@id":"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage"},"thumbnailUrl":"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg","datePublished":"2013-11-27T23:18:25+00:00","dateModified":"2018-08-02T20:49:08+00:00","author":{"@id":"https:\/\/www.corsec.com\/#\/schema\/person\/2249eea128c62c76370cf0ea198ef599"},"description":"Corsec defines each component of the FIPS 140-2 process. These steps help companies understand the validation process and next steps.","breadcrumb":{"@id":"https:\/\/www.corsec.com\/fips-validation-steps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.corsec.com\/fips-validation-steps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.corsec.com\/fips-validation-steps\/#primaryimage","url":"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg","contentUrl":"https:\/\/www.corsec.com\/wp-content\/uploads\/Corsec-FIPS-140-2-Brand_03.jpg","width":792,"height":612,"caption":"FIPS 140-2, FIPS 140-2 validation, FIPS Validation, FIPS 140-2 process, FIPS Inside, FIPS Compliant"},{"@type":"BreadcrumbList","@id":"https:\/\/www.corsec.com\/fips-validation-steps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.corsec.com\/"},{"@type":"ListItem","position":2,"name":"Decisions In A FIPS 140-2 Validation"}]},{"@type":"WebSite","@id":"https:\/\/www.corsec.com\/#website","url":"https:\/\/www.corsec.com\/","name":"Corsec Security, Inc.","description":"Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL \/ UC APL.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.corsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.corsec.com\/#\/schema\/person\/2249eea128c62c76370cf0ea198ef599","name":"Jake Nelson","description":"Jake Nelson leads Corsec's strategic direction for marketing and communication. He has nearly a decade of experience in corporate branding, content marketing, social media, marketing strategy and federal sales. Prior to Corsec, Jake helped start a sales and marketing consulting firm in the Washington DC area. He has also held various positions as head of sales, including the Director of federal civilian sales for an IT government contractor. Jake received his bachelor of business administration with a focus in Business to Business Marketing from James Madison University.","sameAs":["http:\/\/www.corsec.com","https:\/\/sitdev.facebook.com\/pages\/Corsec\/158518584300710","https:\/\/sitdev.linkedin.com\/pub\/jake-nelson\/b\/1b\/636","https:\/\/x.com\/https:\/\/twitter.com\/corsecsecurity"],"url":"https:\/\/www.corsec.com\/author\/marketing\/"}]}},"_links":{"self":[{"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/posts\/6446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/comments?post=6446"}],"version-history":[{"count":0,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/posts\/6446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/media\/6403"}],"wp:attachment":[{"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/media?parent=6446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/categories?post=6446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.corsec.com\/wp-json\/wp\/v2\/tags?post=6446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}