Turn on more accessible mode
Skip to main content
Turn off more accessible mode
Open Smart Grid - OpenSG
Login
|
Join
|
Home
SG Systems
SG Conformity
SG Security
SG Communications
SG Simulations
SG EIM
Meetings
Other UCAIug Sites
Member Corporations
Join UCAIug
OpenHAN
OpenAMI-Ent
OpenADE
OpenADR
Open Spatial TF
Use Case Team
SRS Team
Service Definitions Team
Interoperability Testing Team
Edge Conformity
Security Conformity
ENT Conformity
Conformity Artifacts
AMI-SEC TF
SG-NET
Network Interop
Upcoming Meetings
Past Meetings
CIGRE 2014
DTECH 2014
DTECH 2013
UCAIug Summit 2012
Cincinnati 2012
Knoxville 2012
UCAIug Summit 2011
Vancouver 2011
South San Francisco 2011
Fort Lauderdale 2010
Detroit 2010
Washington, DC 2010
San Francisco 2010
Knoxville 2009
UCA International
CIMug
IEC61850ug
UCA SharePoint Training
This Site: Help Desk
Search UCAI
Search CIM
Search IEC61850
Search OSG
Search IECTC57
Search Across All Sites
Advanced Search
Open Smart Grid - OpenSG
>
Help Desk
>
Service Requests
>
Remove FIPS 140-2 Encryption Compliance as a requirement for Data Custodian and Third Party Connect My Data Certification
Service Requests
: Remove FIPS 140-2 Encryption Compliance as a requirement for Data Custodian and Third Party Connect My Data Certification
Version History
Service Request
Remove FIPS 140-2 Encryption Compliance as a requirement for Data Custodian and Third Party Connect My Data Certification
Details
The current published version of the NAESB Energy Service Provider Interface does not require implementers to meet FIPS 140-2 encryption requirements. Furthermore, experience indicates UCAIug ITCA CMD Certification Applicants are not able to provide reliable evidence their computer infrastructures meet the FIPS 140-2 encryption compliance requirement, which is creating a liability issue for the UCAIug ITCA test laboratory without including a full FIPS 140-2 test suite as part of the CMD testing process. Such an inclusion will be cost prohibitive for CMD Certification applicants and would only apply to the infrastructure currently being tested. Any changes to their infrastructure system, would void the issued certification and require a full FIPS 140-2 certification test of their new infrastructure. Therefore, it is recommended, since the UCAIug ITCA is NOT a recognized NIST FIPS 140-2 testing organization, that the requirement for Data Custodian and Third Party Connect My Data certification applicants meet the NIST FIPS 140-2 encryption certification requirement be removed.
Customer
donald.coffin
Priority
(2) Normal
Service Representative
Assigned To
Keywords
GreenButton
;
ESPI
Comments
No existing entries.
Status
Initiated
Resolution Type
Resolution Date
Mark for Knowledge Base
Related Articles
Resolution Time
0
Attachments
Version: 1.0
Created at 4/30/2017 7:04 PM by donald.coffin
Last modified at 4/30/2017 7:04 PM by donald.coffin
Use this page to add attachments to an item.
Name
© OpenSG Users Group 2009-2016. All Rights Reserved.