Study. uk . com
  1. Home
  2. All questions
  3. Question 31

CISSP study material · question 31 of 500

A vendor tells a procurement team that its hardware security module is "FIPS validated" because its AES implementation passed algorithm testing. The security engineer reviewing the claim explains that cryptographic module validation under FIPS 140-3 examines considerably more than algorithm correctness. Which areas does that validation cover? Choose two.

  1. The risk register entries recorded for the system that deploys the module
  2. The physical security of the module's enclosure and tamper response
  3. The identity proofing performed before operator credentials are issued
  4. The module's handling and zeroisation of sensitive security parameters
Show the answer

Answer: B. The physical security of the module's enclosure and tamper response
D. The module's handling and zeroisation of sensitive security parameters

Module validation covers physical security, the operating environment, non-invasive attack resistance and sensitive security parameter handling; operator identity proofing and organisational risk registers sit outside the module boundary.

Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > Abstract

Challenge yourself on this topic → Study as cards