FIPS 140-3 Security Requirements for Cryptographic Modules
Federal standard for cryptographic module validation derived from ISO/IEC 19790:2012. Defines four increasing security levels covering cryptographic module specification, interfaces, roles and authentication, software/firmware security, operational environment, physical security, non-invasive attack resistance, sensitive security parameter management, self-tests, and life-cycle assurance. Validated through the NIST Cryptographic Module Validation Program (CMVP) with NVLAP-accredited testing laboratories.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| FIPS 140-3 §7.2 | Cryptographic Module Specification | |
| FIPS 140-3 §7.3 | Cryptographic Module Interfaces | |
| FIPS 140-3 §7.4 | Roles, Services, and Authentication | |
| FIPS 140-3 §7.5 | Software/Firmware Security | |
| FIPS 140-3 §7.6 | Operational Environment | |
| FIPS 140-3 §7.7 | Physical Security | |
| FIPS 140-3 §7.8 | Non-Invasive Security | |
| FIPS 140-3 §7.9 | Sensitive Security Parameter Management | |
| FIPS 140-3 §7.10 | Self-Tests | |
| FIPS 140-3 §7.11 | Life-Cycle Assurance | |
| FIPS 140-3 §7.12 | Mitigation of Other Attacks |