Skip to content

Commit b916ee3

Browse files
authored
State that HSMs are validated as meeting FIPS requirements (#281)
...not just that they meet them. Fixes #269
1 parent 104deee commit b916ee3

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

CP-CPS.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -607,7 +607,7 @@ ISRG prohibits any media that contains or has contained sensitive data from leav
607607

608608
### 5.1.8 Off-site backup
609609

610-
ISRG maintains multiple backups of ISRG CA Private Keys at multiple Secure PKI Facilities. All backups are stored on devices meeting FIPS 140-2 Level 3 (or higher) criteria.
610+
ISRG maintains multiple backups of ISRG CA Private Keys at multiple Secure PKI Facilities. All backups are stored on devices validated as meeting FIPS 140-2 Level 3 (or higher) criteria.
611611

612612
## 5.2 Procedural controls
613613

@@ -859,7 +859,7 @@ See Section 7, Certificate Profiles.
859859

860860
### 6.2.1 Cryptographic module standards and controls
861861

862-
ISRG uses HSMs meeting FIPS 140-2 Level 3 (or higher) requirements.
862+
ISRG uses HSMs validated as meeting FIPS 140-2 Level 3 (or higher) requirements.
863863

864864
### 6.2.2 Private key (n out of m) multi-person control
865865

0 commit comments

Comments
 (0)