Close

HPE Aruba Networking Blogs

FIPS 140-2 certification for HPE Aruba Networking Central On-Premises

By Ishani Chakraborty, Product Marketing Manager for HPE Comware Switches, Central and Client Insights

In today's complex network environment, security threats are on the rise. With networks continually evolving and the proliferation of diverse devices, organizations recognize the need for a simple and secure network management solution. With a commitment to keeping data on-premises, catering to strict regulatory requirements, and addressing the concerns of cloud-averse customers, Central On-premises also known as CoP has always been a trusted ally in ensuring that data stays locally and not on the cloud.  Now, bolstering its security credentials, CoP is FIPS 140-2 validated. In this blog, we'll explore why it’s important.

What is FIPS?

The FIPS protocol crafted by National Institute of Standards and Technology (NIST) is a cryptographic-based security standard to protect sensitive U.S government data from increasingly sophisticated cyberattacks and threats. These standards are applicable to applications, databases as well as telecommunication networks. Simply put, it is like a suit of armour for data. Its job is to keep the most sensitive information safe from cyber adversaries. All software in use by U.S. government agencies, contractors, and third parties working for federal agencies must be FIPS validated.

Customers should be aware that if a cryptographic module is not on this list, then the U.S. government will treat that module as plaintext and therefore unprotected. A cryptographic module is a secure software that encrypts and decrypts data and implements security functions such as key generation and management.

Process

Only after NIST validates the module which includes the entire documentation and algorithms used in the code, a CMVP certificate for the validated module is issued and a vendor can truthfully claim that they are using FIPS 140-2 validated cryptographic methods and algorithms. To know more about the process, please visit the NIST website. Network devices and management solutions use cryptography to ensure data security and protect management connections. Thus, CoP as a network management solution needs to be FIPS 140 validated. Using a FIPS validated module ensures that the product meets the highest standards of data protection.

Why should you consider Central On-Premises?

For those navigating strict regulations, managing legacy IT, or reluctant to embrace the cloud, Central On-Premises network management is the ideal choice. It offers a unified management, single pane of glass visibility and control of Aruba wired, wireless infrastructure across campus and branch locations. Cloud-like scale and efficiency on-prem with built-in redundancy and programmability that allows automated workflows with third party integration are other benefits of CoP. Our recent FIPS 140-2 validation is not only beneficial for US. Government agencies, Govt. funded organizations, defence contractors dealing with classified data but even for private enterprises handling personal data (financial, healthcare, retail details etc..) because they are now assured of our commitment to secure their network infrastructure. Quick tip - When considering a vendor's FIPS 140-2 certification, simply check the NIST website for confirmation. If they're listed in NIST's Cryptographic Module Validation Program (CMVP), you can trust their technology. To explore all that CoP has to offer, refer to our ordering guide.