Warning: The magic method WPML_Absolute_Url_Persisted::__wakeup() must have public visibility in /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php on line 30

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /usr/home/corsec/public_html/corsec.com/wp-content/plugins/sitepress-multilingual-cms/classes/url-handling/resolver/wpml-absolute-url-persisted.php:30) in /usr/home/corsec/public_html/corsec.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":7005,"date":"2016-02-17T15:16:43","date_gmt":"2016-02-17T15:16:43","guid":{"rendered":"http:\/\/corsec.com\/?p=7005"},"modified":"2017-07-21T16:26:38","modified_gmt":"2017-07-21T20:26:38","slug":"dod-selling","status":"publish","type":"post","link":"https:\/\/www.corsec.com\/dod-selling\/","title":{"rendered":"Targeting the DoD? The Different Paths to Military Sales"},"content":{"rendered":"

With the military\u2019s love of acronyms and the many and varied requirement definitions, understanding how to break into Department of Defense (DoD) sales can be a daunting proposition. How do these DoD and international requirements relate to one another and what does your product need?<\/p>\n

A few of the requirements we are hearing questions on are Suite B cryptography, Commercial National Security Algorithm (CNSA), Commercial Solutions for Classified (CSfC), and FedRamp. Let\u2019s take a look at each of these and how they relate to Corsec\u2019s core offerings of DoDIN APL, Common Criteria, and FIPS 140-2.<\/p>\n

First, let\u2019s start with differentiating between DoD purchasing for unclassified systems and National Security Systems (NSS).  Many DoD networks are unclassified and use commercial off-the-shelf (COTS) product for these networks. Common Criteria, FIPS 140-2, and DoDIN APL were designed to provide assurance for these types of products.  NSS includes systems used or operated by an agency or organization that us involved in intelligence activities, cryptologic activities related to national security, command and control of military forces, or is an integral part of a weapons system.  All classified government networks are included in the NSS definition. So, in general NSS deals with classified networks, but some sensitive networks may also be designated NSS.  There is a Committee on National Security Systems (CNSS) that sets policies for NSS systems. The CNSS and National Institute of Standards and Technology (NIST) collaborate to provide policies for unclassified and NSS networks.<\/p>\n

Suite B Cryptography\/CNSA Suite<\/strong><\/strong><\/span><\/p>\n

NIST manages the FIPS 140-2 standards, which the DoD relies on for assurance on any COTS product using cryptography on a DoD network.  NIST has taken the FIPS 140-2 requirements and further refined them for NSS networks. These refinements include a reduced list of allowed cryptographic algorithms and were called Suite B cryptography. In January 2016, the NSA defined the Commercial National Security Algorithm (CNSA) Suite, which is a new set of algorithms that replace the Suite B algorithm set. CNSA Suite will be in place until a new set of quantum computer resistant algorithms can be identified.  All algorithms on the CNSA Suite list are valid in FIPS 140-2, but not all FIPS 140-2 algorithms meet CNSA Suite requirements.  It is important to remember, that these requirements are only for products that are determined to be NSS.<\/p>\n

CSfC<\/strong><\/span><\/p>\n

CSfC is a list, maintained by NSA of products that are approved for use as NSS.  Products on this list must:<\/p>\n