3 ms·
FedRAMP actually has a bunch of workarounds for the problems of FIPS. In the "FedRAMP Policy for Cryptographic Module Selection and Use" (https://www.fedramp.g
by dlgeek 2mo ago
FedRAMP actually has a bunch of workarounds for the problems of FIPS.
In the "FedRAMP Policy for Cryptographic Module Selection and Use" (https://www.fedramp.gov/resources/documents/FedRAMP_Policy_for_Cryptographic_Module_Selection_v1.1.0.pdf https://www.fedramp.gov/resources/documents/FedRAMP_Policy_f...), there are a ton of gems that make it clear that the FedRAMP folks are fed up with the CMVP process backlog. The most explicit is:
"FRR9: CSPs shall determine if updating to a newer version of the software, whether or not its cryptographic modules are FIPS validated, would eliminate the vulnerabilities; if it would, CSPs shall promptly update if that is feasible."
- tw04 2mo agoHow is that “a problem with FIPS?” In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later. You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.
- rileymat2 2mo agoIf our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.
- beardedwizard 2mo ago+1, been all the way to fed ramp high and this is a huge part of the security theater that is fedramp. The second best part is either getting really good at patching every single thing, or playing the POA&M game.
- pseudohadamard 2mo agoSo your choice inevitably boils down to running some ancient vulnerability-riddled version that's FIPS certified or running a recent less vulnerability-riddled version that's not certified. Most orgs that I've worked with keep running the vulnerable version because they have to be able to check the box that says "FIPS certified".