• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Process Compliance and Governance

TCG unveils guidance to safeguard sensitive data from cyber threats

FutureCISO Editors by FutureCISO Editors
September 27, 2024
TCG unveils guidance to safeguard sensitive data from cyber threats

Photo by Tara Winstead: https://www.pexels.com/photo/a-diagnosis-form-on-a-chemistry-laboratory-safety-rules-guidelines-7723533/

Share on FacebookShare on Twitter

The Trusted Computing Group (TCG) has released new guidance aimed at bolstering the security of sensitive data within federal systems against cyber attackers. The document, titled "TCG FIPS 140-3 Guidance for TPM 2.0," is designed to facilitate the availability of FIPS 140-3 certified cryptographic solutions, enabling government bodies to enhance their data protection measures.

At the core of this initiative is the Trusted Platform Module (TPM), which verifies that attached devices operate in a trusted manner. Olivier Collart, chair of the Security Evaluation Work Group at TCG, emphasised the urgency of this transition: “TPM 2.0 devices need to be compliant with the latest Federal Information Processing Standard (FIPS) to protect the sensitive data held by the government and regulated organisations. Vendors are now racing to become compliant to FIPS 140-3 before 2026.”

FIPS 140-3, established by the National Institute of Standards and Technology (NIST), outlines the mandatory criteria for cryptographic modules used by U.S. and Canadian government entities. By September 2026, all cryptographic modules must achieve FIPS 140-3 compliance to remain in use within government operations. TCG’s new guidance aims to streamline the transition from the previous FIPS 140-2 standard, offering vendors a roadmap to compliance.

The guidance details implementation recommendations and extensions for TPM 2.0, emphasising the new requirements for FIPS 140-3 'Level 1,' which focuses on basic encryption and key management capabilities. TCG president Joe Pennisi remarked, “The guidance provided by the Security Evaluation Work Group is essential, especially with the deadline for FIPS 140-3 looming over vendors. By making it easier to attain certification, government bodies—and critical sectors like healthcare—will gain access to a range of FIPS-certified solutions to address growing security concerns.”

Related:  Data strategies in the hybrid, multi-cloud normal

With the publication of this guidance, an increase in adoption across the computing industry is anticipated, significantly enhancing data security measures for sensitive federal information.

Tags: FIPSTrusted Platform Module
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl