Showing posts with label NIST. Show all posts
Showing posts with label NIST. Show all posts

Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Sunday, October 27, 2019

Fortanix gets FIPS 140-2 Level 3 certification enabling businesses to update to a more modern encryption platform

Fortanix Inc. announced that the Fortanix Self-Defending Key Management Service (SDKMS) has earned the Federal Information Processing Standard (FIPS) 140-2 Level 3 certification from the National Institute of Standards and Technology (NIST), which is part of the U.S. Department of Commerce. 


This achievement enables businesses to replace legacy encryption technologies, including Hardware Security Modules (HSMs), with the Fortanix SDKMS encryption platform for protecting the most sensitive data in the U.S. Government, technology, financial services and healthcare industries.




SDKMS has been built on HSM-grade security, secures any KMS use case including TDE, storage multi-cloud and blockchain. SDKMS also delivers tokenization, secrets management and HSM; central management, audit and control. It also comes secured with Intel SGX, built for cloud scale/resiliency, SDKMS reduces threats and consolidates costs.​


As part of the certification, Fortanix passed strict government requirements for Level 3 certifications, validating the Fortanix SDKMS cryptographic protections and ability to maintain the confidentiality and integrity of protected information. Customers in the U.S. Government, financial services, healthcare and other regulated industries have specific private data such as passwords and PIN numbers that must be encrypted using FIPS 140-2 Level 3 certified cryptographic modules.



For decades, businesses in highly regulated industries have been locked into HSM appliances that are costly to operate, difficult to scale, and lack the modern RESTful programming interfaces required by application developers to bring new applications to market and migrate them to the public cloud. 


With Fortanix SDKMS, businesses can lower their operating costs up to 70 percent, scale across multi-site and multi-cloud environments, and accelerate application development through modern cryptographic services.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...