Skip to content

Add SOG-IS and FIPS/NIST compliance #32

Open
@sander

Description

@sander

For some use cases it is important to know if the core functions and interfaces are secured using approved cryptography standards. Common lists are the SOG-IS Agreed Cryptographic Mechanisms for the EU and the FIPS-Approved and NIST-Recommended lists for the USA.

For example, trust frameworks under public governance require this to enable standardisation, evaluation, and certification. This enables more efficient public tendering and supervision.

I suggest to add fields:

  • ID:
    • cryptoComplianceSogIs13: All core functions and interface cryptography is on SOG-IS list 1.3
    • cryptoComplianceNist140cr2: All core functions and interface cryptography is on SP 800-140Cr2
    • maybe more
  • Type: Yes | No

Metadata

Metadata

Assignees

No one assigned

    Labels

    TBDwe can not solve this right now, but maybe in the future

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions