FIPS Standard

While the security requirements specified in this standard are intended to maintain the security provided by
a cryptographic module, conformance to this standard is not sufficient to ensure that a particular module is
secure. The operator of a cryptographic module is responsible for ensuring that the security provided by a
module is sufficient and acceptable to the owner of the information that is being protected and that any
residual risk is acknowledged and accepted.
Similarly, the use of a validated cryptographic module in a computer or telecommunications system does
not guarantee the security of the overall system. The responsible authority in each agency shall ensure that
the security of the system is sufficient and acceptable.
Since a standard of this nature must be flexible enough to adapt to advancements and innovations in science
and technology, this standard will be reviewed every five years in order to consider new or revised
requirements that may be needed to meet technological and economic changes.
16. Waiver Procedure. Under certain exceptional circumstances, the heads of Federal agencies, or their
delegates, may approve waivers to Federal Information Processing Standards (FIPS), for their agency. The
heads of such agencies may redelegate such authority only to a senior official designated pursuant to
Section 3506(b) of Title 44, U.S. Code. Waivers shall be granted only when compliance with a standard
would
a. adversely affect the accomplishment of the mission of an operator of Federal computer system or
b. cause a major adverse financial impact on the operator that is not offset by government-wide
savings.
Agency heads may act upon a written waiver request containing the information detailed above. Agency
heads may also act without a written waiver request when they determine which conditions for meeting the
standard cannot be met. Agency heads may approve waivers only by a written decision that explains the
basis on which the agency head made the required finding(s). A copy of each such decision, with
procurement sensitive or classified portions clearly identified, shall be sent to: National Institute of
Standards and Technology; ATTN: FIPS Waiver Decision, Information Technology Laboratory, 100
Bureau Drive, Stop 8900, Gaithersburg, MD 20899-8900.
In addition, notice of each waiver granted and each delegation of authority to approve waivers shall be sent
promptly to the Committee on Government Operations of the House of Representatives and the Committee
on Government Affairs of the Senate and shall be published promptly in the Federal Register
.
When the determination on a waiver applies to the procurement of equipment and/or services, a notice of
the waiver determination must be published in the Commerce Business Daily
as a part of the notice of
solicitation for offers of an acquisition or, if the waiver determination is made after that notice is published,
by amendment to such notice.
A copy of the waiver, any supporting documents, the document approving the waiver and any supporting
and accompanying documents, with such deletions as the agency is authorized and decides to make under
Section 552(b) of Title 5, U.S. Code, shall be part of the procurement documentation and retained by the
agency.
17. Where to obtain copies. Copies of this publication are available from the URL:
http://csrc.nist.gov/publications. Copies are available for sale by the National Technical Information
Service, U.S. Department of Commerce, Springfield, VA 22161. When ordering, refer to Federal
Information Processing Standards Publication 140-2 (FIPSPUB1402) and identify the title. When
microfiche is desired, this should be specified. Prices are published by NTIS in current catalogs and other
issuances. Payment may be made by check, money order, deposit account, or charged to a credit card
accepted by NTIS.
18. CHANGE NOTICE. See important change notice at the end of this document.
vi