Study. uk . com
  1. Home
  2. All questions
  3. Question 229

CISSP study material · question 229 of 500

A vendor states that its module is FIPS 140-3 compliant on the strength of its own internal testing. Why is that claim insufficient?

  1. Compliance is claimed by registration only, and the vendor has not registered.
  2. Compliance requires an attestation from the purchasing agency rather than the vendor.
  3. Testing must be performed by an independent accredited laboratory and the report reviewed before validation.
  4. Compliance requires the module to be open source so the code can be inspected.
Show the answer

Answer: C. Testing must be performed by an independent accredited laboratory and the report reviewed before validation.

Vendors use independent, accredited cryptographic and security testing laboratories, which perform conformance testing, and the validation programme reviews the report before validating the module.

Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > 3. Explanation

Challenge yourself on this topic → Study as cards