FIPS 140-1 and FIPS 140-2 are
standards developed by the US Government that codify the implementation, algorithms and other aspects of cryptographic modules (hardware and/or software modules or components). These standards
are intended to ensure that computer products provided to the Federal Government meet minimum levels of data security. Note that these standards only address data encryption and security, not
other aspects of computer security such a password security are covered.
Vendors who desire to provide computer hardware and software to non-military government agencies may be required to only use FIPS certified cryptographic modules in their
products. Vendors can satisfy this requirement by using certified modules (the software itself is compliant) from third parties and incorporating those modules in their product in a compliant
manor (the process in which the software is created is compliant).
For more information: