- Home
- All questions
- Question 229
CISSP study material · question 229 of 500
A vendor states that its module is FIPS 140-3 compliant on the strength of its own internal testing. Why is that claim insufficient?
Show the answer
Answer: C. Testing must be performed by an independent accredited laboratory and the report reviewed before validation.
Vendors use independent, accredited cryptographic and security testing laboratories, which perform conformance testing, and the validation programme reviews the report before validating the module.
Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > 3. Explanation