- Home
- All questions
- Question 230
CISSP study material · question 230 of 500
An architect specifies FIPS 140-3 Level 4 for every module in a low-impact internal application, arguing that higher is always safer. What does the standard advise?
Show the answer
Answer: B. The level should be chosen to match the security the application and environment actually require.
FIPS 140-3 says the level to which a module is validated must be chosen to provide security appropriate for the requirements of the application and environment and the services provided.
Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > 7. Applications