home.social

#niap — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #niap, aggregated by home.social.

fetched live
  1. wonna know something?
    so there's a company called cellcrypt which (was) actually NSA certified. they're trying to get certified again, it's expected to come out of testing soon.
    but they wrote this artical which is now archived web.archive.org/web/2025012602 for those that can't parse hyperlinks. they basically argue against public infrastructure (reasonible) yet they now have an offering which uses public infrastructure.
    are you for it, or are you against it? com e on, make up your mind!
    @kkarhan #infosec #cybersecurity #security #encryption #cellcrypt #niap #nsa

  2. wonna know something?
    so there's a company called cellcrypt which (was) actually NSA certified. they're trying to get certified again, it's expected to come out of testing soon.
    but they wrote this artical which is now archived web.archive.org/web/2025012602 for those that can't parse hyperlinks. they basically argue against public infrastructure (reasonible) yet they now have an offering which uses public infrastructure.
    are you for it, or are you against it? com e on, make up your mind!
    @kkarhan #infosec #cybersecurity #security #encryption #cellcrypt #niap #nsa

  3. It would be a great accelerator for #sbom adoption if there was a way to leverage them to accelerate #NIAP / #FIPS / #FedRAMP

    If one was able to digitally attest to known approved versions of software libraries in their SBOM, you would think it could reduce their certification burden.

    The current NIAP/CC/FedRAMP process is endlessly broken and this could be a great way to start to modernize it.

  4. It would be a great accelerator for #sbom adoption if there was a way to leverage them to accelerate #NIAP / #FIPS / #FedRAMP

    If one was able to digitally attest to known approved versions of software libraries in their SBOM, you would think it could reduce their certification burden.

    The current NIAP/CC/FedRAMP process is endlessly broken and this could be a great way to start to modernize it.