Tag: NIST

Home » NIST
  • Yubico submits YubiKey 5 FIPS Series for FIPS 140-3 validationWe’re excited to share that the YubiKey 5 FIPS Series latest 5.7 firmware has completed testing by our NIST accredited testing lab, and has been submitted to the Cryptographic Module Validation Program (CMVP) for FIPS 140-3 validation, Overall Level 2 and Physical Level 3. This marks a significant milestone in our ongoing commitment to providing […]Read moreFIPSNISTYubiKey 5.7YubiKey FIPS Series
  • Adapting to new cybersecurity regulations and addressing evolving threats within financial servicesIn late 2023, the U.S. subsidiary of the Industrial and Commercial Bank of China was hit with ransomware, creating a ripple effect across the U.S. Treasury market. In February 2024, Bank of America reported a breach impacting 57,000 account holders related to a compromise with a third-party software provider. And as recently as June, a […]Read morefinancial servicesNISTPCI DSSphishing-resistant MFA
  • New NIST guidance on passkeys: Key takeaways for enterprisesNIST recently released an update to SP800-63B to provide guidance on syncable authenticators. As FIDO passkeys continue becoming more adopted and available at a large scale, NIST guidance helps organizations properly position and plan so they can successfully implement synced passkeys both internally and externally.  Within the guidance, it’s important to understand the nuance of […]Read moregovernmentNISTpasskeysphishing-resistant MFA
  • What CISA and NSA’s ESF guidance means for critical infrastructure cybersecurityThe Cybersecurity Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently collaborated to produce an important new document, “Identity and Access Management: Recommended Best Practices for Administrators.” Part of the Enduring Security Framework (ESF), it presents a distillation of identity access management (IAM) and cybersecurity guidance put forth by CISA to date, based […]Read moreCISAcritical infrastructureESFgovernmentNIST
  • A new era for Federal identity with Joe Scalone – YubicoThis is part two of a two-part series on the latest NIST guidelines. To read part one, check out our blog post here. Over the past six months, three National Institute of Standards and Technology (NIST) draft guidelines were released that will change how federal agencies manage digital identity services, the authentication of users and […]Read moreFIDO2NISTNIST SP 800-63-4
  • NIST SP 800-63-4: What the new phishing-resistant definition means for federal agenciesThe recent drafts from National Institute of Standards and Technology (NIST) around cybersecurity highlight important updates on where the government is moving on technology and the focus on increasing security against cyber threats. This is because NIST’s primary goal is to develop and disseminate the standards that allow technology to work seamlessly and businesses to […]Read morefederal governmentNISTNIST SP 800-63-4passkey
  • Compliant PINs and MFA: Modern direction for staying secureEntities within the US Federal Government are in the midst of a drastic change regarding how they approach the services they are using—moving away from traditional on-prem and proprietary systems to cloud services based on private platforms, like Azure and Amazon Web Services. However, the requirements for security remain the same regardless of the platform […]Read moreNISTphishing-resistant MFAPINssmart cardYubiKey
  • Yubico LogoYubiKey FIPS SeriesFIPS 140-2 validated security keys Meets stringent compliance requirements for highly security-conscious organizations Superior authentication FIPS 140-2 validated (Overall Level 1 and Level 2, Physical Security Level 3) Meets the highest authenticator assurance level 3 (AAL3) of NIST SP800-63B guidance. Easy, fast, reliable Hardware authenticator, offering one-touch strong authentication. Does not require a battery or […]Read moreauthenticationFIPS 140-2NISTYubiKey FIPS Series
  • Yubico LogoWhat is authentication assurance?What is authentication assurance level 3? The NIST is on version 3 of the Authentication Assurance levels, called Authentication Assurance Level 3 (AAL3). Authentication Assurance relies on examination of the cryptographic modules of an authenticator. Level 3 requirements (AAL3) means that the code is within a tamper-proof container so that keys used in the cryptography are destroyed […]Read moreauthenticationFIDO U2FNISTPIVYubiKey
  • Lessons from the SolarWinds incidentLast week, a large and expertly run espionage operation was made public — one that began no later than October 2019, and which had been actively exploiting victims since at least early 2020. This incident is particularly interesting for several reasons: for the breadth of sensitive global government and industry targets, for misuse of a […]Read moreidentity and access managementNISTsecurityWebAuthn