Page 171 - Cyber Defense eMagazine August 2024
P. 171
Unlocking the Right Encryption
A Guide to Government System Protection
By Ben Warner, VP of Strategic Accounts, CRU Data Security Group
The ever-evolving landscape of data security demands constant vigilance, especially for those handling
Controlled Unclassified Information (CUI). A presentation by Greg Cooper, Cybersecurity SME & Security
Engineer, at the USAF Cyber Monthly meeting shed light on common misconceptions surrounding data
encryption and the critical role of obtaining the correct certifications for your specific data classification.
While encryption is widely understood as a crucial security measure, misconceptions abound. A common
fallacy is that focusing solely on encrypting data-in-transit offers sufficient protection. The reality is far
more nuanced. Technical data, for example, can also qualify as CUI, requiring robust encryption
strategies.
Perhaps the most critical takeaway concerns the limitations of FIPS 140-3 compliance. While this
standard offers a baseline for cryptographic modules, it doesn't guarantee CUI protection. For CUI
Cyber Defense eMagazine – August 2024 Edition 171
Copyright © 2024, Cyber Defense Magazine. All rights reserved worldwide.