# FIPS 140-3 Security Requirements for Cryptographic Modules

Framework id: `fips_140`. Cryptographic Standard. Publisher: NIST / CMVP. Version: 2019. Region: USA. Mapping licence: CC BY-SA 4.0.
Source text: https://csrc.nist.gov/publications/detail/fips/140/3/final

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (11, average coverage 71%)
- FIPS 140-3 §7.2 Cryptographic Module Specification: SC-13, SA-04, SA-08, SA-17, CM-06 (82%)
- FIPS 140-3 §7.3 Cryptographic Module Interfaces: SC-13, AC-04, SC-07, SC-03 (62%)
- FIPS 140-3 §7.4 Roles, Services, and Authentication: AC-02, AC-05, AC-06, IA-02, IA-05, IA-07, AC-07 (92%)
- FIPS 140-3 §7.5 Software/Firmware Security: SI-07, CM-14, SA-10, SA-11, SC-34 (82%)
- FIPS 140-3 §7.6 Operational Environment: CM-06, CM-07, SC-39, SI-03, CM-02 (78%)
- FIPS 140-3 §7.7 Physical Security: PE-03, PE-04, PE-05, PE-06, PE-19, PE-20 (62%)
- FIPS 140-3 §7.8 Non-Invasive Security: PE-19, RA-03, SC-28 (30%)
- FIPS 140-3 §7.9 Sensitive Security Parameter Management: SC-12, SC-13, SC-17, SC-28, IA-05, MP-06 (92%)
- FIPS 140-3 §7.10 Self-Tests: SI-06, SI-07, CA-08 (52%)
- FIPS 140-3 §7.11 Life-Cycle Assurance: SA-03, SA-10, SA-11, SA-15, CM-03, CM-05, SA-04 (80%)
- FIPS 140-3 §7.12 Mitigation of Other Attacks: RA-03, RA-05, SI-02, RA-07, SA-11 (68%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=fips_140
- Control-to-clause mappings as JSON: /api/v1/frameworks/fips_140?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/fips-140.json
- Page for people: /frameworks/fips-140/
