What Is FIPS Mode? (2024)

In a prior article, we explained what the Federal Information Processing Standards (FIPS) are and how to determine FIPS compliance. In this article, we’ll explain what FIPS mode is and how enabling FIPS mode on networks and/or devices can make systems FIPS compliant.

What Are the Federal Information Processing Standards?

The Federal Information Processing Standards (FIPS) are a set of federal security standards designed for protecting sensitive data and systems leveraged by U.S. government agencies and the contractors and vendors they work with. They’re specifically meant to inform the operation of cryptographic modules—algorithms that encrypt data stored within the system or device.

Encryption modules for information technology and computer security programs that are running in FIPS mode will perform Federal Information Processing Standards-compliant functions such as key generation, encryption, and decryption.

What Is NIST?

The National Institute of Standards and Technology (NIST) is a U.S. government laboratory that works to promote the economic security of the country by developing security standards that counter digital theft and cybersecurity threats.

Security standards issued by the laboratory are considered excellent default security measures, even for non-federal agencies not required to operate in FIPS mode for compliance.

Overview of FIPS and Its History

Federal Information Processing Standards were first created by NIST in 1974. FIPS compliance provides rigorous standards for IT and computer security. Specifically, it’s concerned with the compliance of an application or product’s encryption modules, designed to protect data in transit or at rest. The standards were designed by NIST to improve data security of sensitive data.

Learn more about FIPS compliance and how it’s determined.

What Is FIPS Mode?

FIPS mode is a configuration option for systems (e.g., software, operating systems, SIEM solutions) and hardware (e.g., routers, data storage). When these specific FIPS security features are being implemented, the device or system is running in FIPS mode and is typically considered to be Federal Information Processing Standards compliant. (For Federal Information Processing Standards 140-2, additional parameters may be required for compliance).

What Happens in FIPS Mode?

When a device or system and its components are running in FIPS mode, they’re only using Federal Information Processing Standards-compliant algorithms and libraries for cryptography. In some cases, they may also run additional data protection features. It also may mean that, while in FIPS mode, certain non-Federal Information Processing Standards compliant functions may be disabled or restricted.

Learn more about Pure’s government data center solutions!

U.S. Federal Standards for Security Controls

Can FIPS Mode Be Disabled?

Yes, FIPS mode can be disabled. When Federal Information Processing Standards mode is disabled, non-Federal Information Processing Standards compliant functions are no longer restricted.

What Technology Can Be Put in FIPS Mode?

Any technology or system that can run Federal Information Processing Standards-compliant encryption algorithms or operations can be put into Federal Information Processing Standards mode.

Hardware That Can Be Put in Federal Information Processing Standards Mode

The types of hardware that can be put into Federal Information Processing Standards mode include hardware that performs cryptographic functions, such as:

  • Data storage arrays (e.g., self-encrypting drives)
  • Network devices, such as routers, firewalls, and network switches
  • Security devices

Software That Can Have Federal Information Processing Standards Mode Enabled

The types of software that can have Federal Information Processing Standards mode enabled include systems or software that run encryption modules, such as:

  • Operating systems
  • Encryption software
  • Virtual private networks (VPNs)
  • SIEM software or network intrusion detection systems

What Networks and Industries Need FIPS Mode?

The networks or industries that need FIPS mode are contractually obligated to and are typically those networks within the United States handling classified information for the U.S. government. These can include:

  • Federal and government networks
  • Law enforcement, national security, and national defense networks
  • Healthcare networks
  • Military networks
  • Critical infrastructure, including the utilities sector, energy, power, and power grid networks

FIPS Mode vs. Being FIPS Validated

FIPS mode is a specific configuration or setting that is enabled, while being Federal Information Processing Standards validated means a system or device has undergone the formal Federal Information Processing Standards validation testing process. For example, a device can be Federal Information Processing Standards validated but not necessarily running in FIPS mode.

Conclusion

FIPS mode is a very specific configuration for devices and systems that must be Federal Information Processing Standards compliant, but it’s important to note that it is not a catchall nor will it be appropriate for every device or system.

Not all data storage devices are able to be Federal Information Processing Standards compliant or run in FIPS mode. If you need a Federal Information Processing Standards-compliant data storage device, look for a storage array that explicitly notes Federal Information Processing Standards compliance in its system documentation (e.g., technical specs and user manuals) or check a vendor’s documentation or reach out to technical support.

What Is FIPS Mode? (1)

BUYER’S GUIDE, 14 PAGES

A Buyer’s Guide to Modern Virtualization

What Is FIPS Mode? (2)
What Is FIPS Mode? (2024)
Top Articles
Passive Income Archives
What Is a Second Mortgage? - NerdWallet
Craigslist Home Health Care Jobs
How To Fix Epson Printer Error Code 0x9e
Pet For Sale Craigslist
Elleypoint
Erika Kullberg Wikipedia
Richard Sambade Obituary
Gunshots, panic and then fury - BBC correspondent's account of Trump shooting
Palace Pizza Joplin
Prices Way Too High Crossword Clue
R Tiktoksweets
Unit 1 Lesson 5 Practice Problems Answer Key
Miami Valley Hospital Central Scheduling
Conduent Connect Feps Login
Edible Arrangements Keller
Amelia Bissoon Wedding
What to do if your rotary tiller won't start – Oleomac
Marion County Wv Tax Maps
Craigslist Motorcycles Orange County Ca
Bowlero (BOWL) Earnings Date and Reports 2024
Les Rainwater Auto Sales
De beste uitvaartdiensten die goede rituele diensten aanbieden voor de laatste rituelen
623-250-6295
Amih Stocktwits
Craigslist Roseburg Oregon Free Stuff
Marquette Gas Prices
Belledelphine Telegram
Craigslist Comes Clean: No More 'Adult Services,' Ever
Srjc.book Store
Homewatch Caregivers Salary
Spy School Secrets - Canada's History
Plato's Closet Mansfield Ohio
Tyler Sis 360 Boonville Mo
October 31St Weather
Msnl Seeds
The Transformation Of Vanessa Ray From Childhood To Blue Bloods - Looper
Craigslist Pa Altoona
Thelemagick Library - The New Comment to Liber AL vel Legis
Dogs Craiglist
How to Quickly Detect GI Stasis in Rabbits (and what to do about it) | The Bunny Lady
Craigs List Hartford
11 Best Hotels in Cologne (Köln), Germany in 2024 - My Germany Vacation
Lucifer Morningstar Wiki
Citymd West 146Th Urgent Care - Nyc Photos
Hanco*ck County Ms Busted Newspaper
Food and Water Safety During Power Outages and Floods
Germany’s intensely private and immensely wealthy Reimann family
Google Flights Missoula
Sam's Club Fountain Valley Gas Prices
Latest Posts
Article information

Author: Roderick King

Last Updated:

Views: 5306

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Roderick King

Birthday: 1997-10-09

Address: 3782 Madge Knoll, East Dudley, MA 63913

Phone: +2521695290067

Job: Customer Sales Coordinator

Hobby: Gunsmithing, Embroidery, Parkour, Kitesurfing, Rock climbing, Sand art, Beekeeping

Introduction: My name is Roderick King, I am a cute, splendid, excited, perfect, gentle, funny, vivacious person who loves writing and wants to share my knowledge and understanding with you.