fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.9k stars 402 forks source link

Support FIPS-140-3 encryption standard #18851

Open dherder opened 3 months ago

dherder commented 3 months ago

Problem

Complete implementation documented / sized in the following proposal: https://github.com/fleetdm/fleet/blob/main/proposals/fips/fleet-server-fips.md

noahtalerman commented 3 months ago

Support FIPS-140-3 encryption standard

@dherder why? What's the business case here?

dherder commented 3 months ago

@noahtalerman it is a requirement for the prospects on this issue. @KAB703 can add more context I believe.

KAB703 commented 3 months ago

All US Federal agencies require FIPS 140-3 and SCAP 1.3. DOD requires the STIG.

noahtalerman commented 3 months ago

Zach: Low upfront cost. High maintenance cost.

ireedy commented 2 months ago

Bringing this back to feature fest. We are currently going through the process to become CDM compliant. To qualify, Fleet must meet the following:

Being recognized as CDM compliant is important as most federal government contracts, particularly in the cybersecurity and IT space, require it. We risk not being considered for federal opportunities if we are not compliant.

noahtalerman commented 2 months ago

We risk not being considered for federal opportunities if we are not compliant.

Thanks @ireedy!

Hey @alexmitchelliii do we have any order forms out to federal prospects?

alexmitchelliii commented 2 months ago

@noahtalerman I think we are going to have to bypass the order form out requirement to prioritize this issue because we won't be able to start any federal sales cycles without having it. So the priority call is whether we want to build any federal pipeline now vs other priorities.

noahtalerman commented 2 months ago

@alexmitchelliii: the big opportunities are to replace BigFix, not Jamf.

@noahtalerman: Got it. Not completing the work/testing yet while we're focused on Jamf parity.

cc @ireedy

noahtalerman commented 2 months ago

VA page on Jamf compliance: https://www.oit.va.gov/Services/TRM/ToolPage.aspx?tid=10822&tab=2&minYear=2022