Uk Defence Standard Ambiguity?
by sctmedk
I’m currently reviewing some compliance against the UK Defence Standard for suppliers, and I’ve got a bit hung up on one in particular; ‘The Supplier shall employ appropriate nationally or departmentally approved cryptography when used to protect all Data (e.g. FIPS 140-2 or comparable standards)’ The only thing I’ve been able to reference so far is NCSC and it doesn’t seem to be too specific, I’m in particular interested around VPN’s, since we currently use Wireguard/Tailscale, but available info seems to advice against due to its encryption method, and advices to use something like OpenVPN instead since it uses AES. Am I being really dense about this? Or reading it the wrong way completely? I think I’ve got myself into a bit of a research spiral and have convinced myself of things that aren’t the case. I’ve also looked into Cloudflare’s meshing ZTNA but I’m concerned how info is processed at their edge before going to other nodes. submitted by /u/sctmedk [link] [comments]