insurancenewsnet.com
Monkton Announces Initiation of NIAP Accreditation Process - InsuranceNewsNet
https://insurancenewsnet.com/oarticle/monkton-announces-initiation-of-niap-accreditation-process
To be an INNsider. 9733; DOL Rule News. April 3, 2017. Monkton Announces Initiation of NIAP Accreditation Process. April 03, 2017. Has contracted with Acumen Security. National Information Assurance Partnership. NIAP) Assessment of two iOS mobile applications in its portfolio. The applications will operate in two modes: offline, in a disconnected state, and online, interfacing with. Impact Level 4, 5, and 6 environments. This move toward NIAP represents a strategic investment for. NSA) validation program...
csrc.nist.gov
NIST.gov - Computer Security Division - Computer Security Resource Center
http://csrc.nist.gov/groups/STM/testing_labs/index.html
NIST, Computer Security Resource Center. FISMA and Cybersecurity Initiatives. Systems and Emerging Technologies. A-Z List of Projects. NIST Special Publications (SPs). By Security Control Family. Journal Articles and Other Papers. Early Computer Security Papers (1970-1985). Federal Register Notices Archives. Cryptographic Module Validation Program (CMVP). Cryptographic Algorithm Validation Program (CAVP). And for testing of Approved security functions. Asia Pacific IT Laboratory, TÜV NORD. Lab Director: ...
blog.acumensecurity.net
OPENSSL: SEVERE UNDISCLOSED BUG
http://blog.acumensecurity.net/openssl-severe-undisclosed-bug
Welcome to the Acumen Security Blog. OPENSSL: SEVERE UNDISCLOSED BUG. July 8, 2015. A new version of OpenSSL, the open-source software widely used to encrypt internet communications using SSL/TLS, is due to be released this Thursday July 9. Patching a “high severity” vulnerability. The developers of OpenSSL posted the following announcement to their message boards at openssl.org –. So, a word of advice to all those dealing with OpenSSL projects, keep an eye on this important update on Thursday July 9.
blog.acumensecurity.net
Acumen Security – Blog
http://blog.acumensecurity.net/page/3
Welcome to the Acumen Security Blog. The Email Client EP. September 8, 2016. A number of the email client EP’s other unique SFRs have only documentation based assurance activities. Others that have testing AAs only require an evaluator to use the product’s standard functionality that should be available to any user. FDP NOT EXT.1 (S/MIME status notification) can be tested entirely by sending different and receiving different types of emails. Revisiting W X with OpenBSD 6.0. September 1, 2016. Was release...
blog.acumensecurity.net
Leveraging Government Certification to Make a Better Product
http://blog.acumensecurity.net/leveraging-government-certification-to-make-a-better-product
Welcome to the Acumen Security Blog. Leveraging Government Certification to Make a Better Product. May 14, 2015. The paper can be found here. Had the OSGP been comprised of standards-based protocols and cryptographic algorithms as required for government certification, such as, FIPS 140 and Common Criteria, these attacks would not have been possible. This is just one recent example of how leveraging government certifications could have prevented potential compromise in systems. October 12, 2016.
blog.acumensecurity.net
Time to comment on FIPS 140-NEXT
http://blog.acumensecurity.net/fips-140-next-comments
Welcome to the Acumen Security Blog. Time to comment on FIPS 140-NEXT. August 13, 2015. The time has come to provide comments on the proposed successor to FIPS 140-2. NIST has put a proposal for comment to use ISO 19790 as the next revision of FIPS 140 (we like to call it FIPS 140-NEXT but it will probably end up being called FIPS 140-3). The link to the request for comments can be found on Federal Register, here:. Will you be commenting on the proposal? Speak Your Mind Cancel reply. October 12, 2016.
blog.acumensecurity.net
Getting ready for an ISO 19790 based FIPS 140-Next
http://blog.acumensecurity.net/getting-ready-for-an-iso-19790-based-fips-140-next
Welcome to the Acumen Security Blog. Getting ready for an ISO 19790 based FIPS 140-Next. April 15, 2014. Recently, there has been a lot of talk about the next version of FIPS 140 being based on ISO 19790:2012. The CMVP has even added a section to its website. Automated Security Diagnostic Testing:. ISO 19790:2012 requires that any software/firmware in a product be run through automated testing (such as, static analysis). If you are not already performing that type of testing, now is a good time to st...
blog.acumensecurity.net
CMVP RNG Transition
http://blog.acumensecurity.net/201
Welcome to the Acumen Security Blog. March 17, 2015. The Cryptographic Technology Group at NIST has confirmed the transition schedule for RNGs (e.g., the X9.31 RNG) provided in SP 800-131A. Accordingly, when the transition takes place the CMVP will proceed as follows:. Validated modules on the CMVP validation lists:. Modules on the CMVP queue. REVIEW PENDING or IN REVIEW:. These module submissions will be handled like those in the REVIEW PENDING or IN REVIEW case. This transition is being handled in a ma...
SOCIAL ENGAGEMENT