Page 171 - Cyber Defense eMagazine August 2024
P. 171

Unlocking the Right Encryption


            A Guide to Government System Protection

            By Ben Warner, VP of Strategic Accounts, CRU Data Security Group


            The ever-evolving landscape of data security demands constant vigilance, especially for those handling
            Controlled Unclassified Information (CUI). A presentation by Greg Cooper, Cybersecurity SME & Security
            Engineer, at the USAF Cyber Monthly meeting shed light on common misconceptions  surrounding data
            encryption and the critical role of obtaining the correct certifications for your specific data classification.

            While encryption is widely understood as a crucial security measure, misconceptions abound.  A common
            fallacy  is that  focusing  solely on encrypting  data-in-transit  offers sufficient  protection.  The reality is far
            more  nuanced.  Technical  data,  for  example,  can  also  qualify  as  CUI,  requiring  robust  encryption
            strategies.

            Perhaps  the  most  critical  takeaway  concerns  the  limitations  of  FIPS  140-3  compliance.  While  this
            standard  offers  a  baseline  for  cryptographic  modules,  it  doesn't  guarantee  CUI  protection.  For  CUI







            Cyber Defense eMagazine – August 2024 Edition                                                                                                                                                                                                          171
            Copyright © 2024, Cyber Defense Magazine. All rights reserved worldwide.
   166   167   168   169   170   171   172   173   174   175   176