OWASP / ASVS

Application Security Verification Standard
Creative Commons Attribution Share Alike 4.0 International
2.72k stars 665 forks source link

FIPS 140-2 is superseded by FIPS 140-3 #1344

Closed AtlasHackert closed 2 years ago

AtlasHackert commented 2 years ago

In V6's references, FIPS 140-2 is mentioned. However, FIPS 140-2 is superseded by FIPS 140-3. See for example: https://www.federalregister.gov/documents/2019/05/01/2019-08817/announcing-issuance-of-federal-information-processing-standard-fips-140-3-security-requirements-for

FIPS 140-3 supercedes FIPS 140-2.

However, FIPS 140-3 is vastly different in set-up than FIPS 140-2, so I'm not sure there's a "quick fix", and I'm not a FIPS-expert.

tghosth commented 2 years ago

So I don't think we rely on FIPS, we just mention it so I have just updated how we refer to it in #1373

elarlang commented 2 years ago

changes merged, closing. reopen if needed.