Skip to content

Changelog

Updates to the SL5 Standard, newest first. Each entry records a change to a control or to the standard's guidance, with a link to the affected control.

Release 0.1.2

Release 0.1.2 removes the FIPS 140-3 Level 3 validation requirement for inter-facility encryptors while retaining equivalent non-algorithm protections, requires post-quantum cryptography, adds cryptographic diversity to the Rule of Two, and completes the control selection's structural dependencies. It distinguishes SenL personnel-vetting designations from formal physical-access authorization and aligns the SA-4 shielded-rack requirement with the NSA 94-106 Figure 1 attenuation curves. The selection grows from 43 controls in 10 families to 60 controls in 12 families. The 17 added dependency controls are selection-only additions with no new SL5 supplemental guidance or parameter assignments. SR-13 now resolves from a separate SP 800-161 Rev. 1 Update 1 catalog without introducing new SL5 requirements.

PE-2(3)Revision

Restrict Unescorted Access

Replaced the SenL-5 "clearance" terminology with two distinct conditions for unescorted Red Zone access: formal physical-access authorization and the SenL-5 Custodial designation. SenL is an industry-adapted personnel-vetting model, not a government security clearance or adjudication. The parameter now selects formal access authorization rather than a SenL clearance.

View control
SA-4Revision

Acquisition Process

Corrected the shielded-rack requirement to reference the NSA 94-106 Figure 1 attenuation requirements at each of its test frequencies (1 kHz through 10 GHz), or an equivalent verified design. The flat 100 dB figure previously quoted is NSA 94-106's power-line filter specification, not its shielding performance curve, which is graduated by frequency.

View control
SC-8(1)Revision

Cryptographic Protection

Removed the FIPS 140-3 Level 3 module validation requirement while retaining equivalent non-algorithm Level 3 protections for physical security, operator authentication, self-tests, and sensitive security parameter management. Added explicit key management requirements for secure provisioning, synchronization where applicable, rotation, recovery, revocation, zeroization, trusted-channel entry and output, and split knowledge. Inline network encryptors must implement post-quantum (quantum-resistant) algorithms, with specific algorithm selection deferred to current guidance from a recognized national cryptographic authority (e.g., NIST post-quantum standards or NSA CNSA 2.0) rather than mandated by the standard. Updated Fig. 1 (SL5 Network Architecture) to remove the "FIPS 140-3 L3" specification labels and explicitly depict the two serial, supplier-diverse encryptor layers at each endpoint.

View control
SC-13Revision

Cryptographic Protection

Revised the supplemental guidance to require post-quantum cryptographic algorithms for inter-facility encryptors, in line with SC-8(1), with the specific algorithms left to current national cryptographic guidance rather than fixed by the standard. Removed the stated preference for NSA Type 1 certified encryptors. Corrected the frameworks example: CNSSI 1253 requires NIST FIPS-compliant key-management processes for unclassified NSS, and CNSS Policy 15 requires NSA-approved cryptography to protect national security systems. The prior text attributed a FIPS-validated requirement to CNSSI 1253 that the instruction does not contain.

View control
SC-29Revision

Heterogeneity

Extended the Rule of Two for inline network encryptors: supplier diversity alone does not provide cryptographic diversity. The two layers must not share a cryptographic hardness assumption, so each encryptor implements quantum-resistant protection from a different algorithm family (e.g., a lattice-based KEM in one layer and a symmetric pre-shared-key construction or code-based KEM in the other), ensuring a single cryptanalytic breakthrough cannot defeat both layers.

View control
Security ArchitectureRevision

Cryptographic Protection

Updated the Security Architecture overview to replace "FIPS 140-3 Level 3 minimum validation for network encryptors" with "Post-quantum (quantum-resistant) cryptographic algorithms for network encryptors", aligning the narrative section with the SC-8(1) and SC-13 control revisions.

Open QuestionsRevision

Cryptographic Protection

Narrowed the cryptographic-sufficiency open question. The SC-8(1) and SC-13 revisions settle whether post-quantum algorithms are required (they are), so the remaining open item is the selection of specific post-quantum algorithms as the standards mature.

Open QuestionsRevision

Physical Security

Resolved the shielded-rack attenuation open question. The SA-4 revision specifies the NSA 94-106 Figure 1 attenuation requirements at each of its test frequencies, or an equivalent verified design, settling the full-versus-reduced-spec question.

SelectionAddition

Base and related controls added

Added 17 controls, growing the selection from 43 controls in 10 families to 60 in 12. Twelve are base controls required when their enhancements are selected: AC-2, AC-3, CM-7, PE-2, PE-3, PE-19, SC-8, SC-15, SC-28, SI-7, SR-3, and SR-5. Five are related controls already invoked by SL5 guidance: AC-2(13), IR-4, RA-3, SC-12, and SI-4. IR-4 and RA-3 add the Incident Response and Risk Assessment families. These 17 controls are selection-only additions; this release adds no SL5 supplemental guidance or parameter assignments to them.

SR-13Revision

Supplier Inventory

Corrected OSCAL source resolution by importing SR-13 from a separately published local catalog based on NIST SP 800-161 Rev. 1 Update 1. The catalog contains the official control statement and Supplemental C-SCRM Guidance. The existing short SL5 guidance is unchanged, and no SL5 parameter assignments were added.

View control

Release 0.1.1

Revises two controls in response to external review. PS-3 removes the "Private SF-86" construct and reframes high-tier personnel vetting as an active area of research with two paths: a formal government partnership or the industry-adapted Sensitivity Levels (SenL) Framework. PE-19(1) extends emanations security to adversary-controlled active signals and defines energy-flow policies at Red Zone boundaries.

PS-3Revision

Personnel Screening

Removed the "Private SF-86" construct, which assumed a private vetting process equivalent to a government background investigation that does not yet exist. PS-3 now frames high-tier personnel vetting as an active area of research with two paths: (1) a formal government partnership using existing government clearance authorities, or (2) the Sensitivity Levels (SenL) Framework, an industry-adapted vetting model that labs can deploy without government participation, though it would benefit from government information-sharing. Fig. 3 (Personnel Security Program) updated to remove the "Private SF-86" stage from the vetting pipeline, aligning the figure with this revision.

View control
PE-19(1)Revision

National Emissions Policies and Procedures

Extended emanations security from passive egress prevention to adversary-controlled active signals, covering inbound signal injection used to influence system behavior. Emissions policies now define the permitted energy flows across each Red Zone boundary in both directions. The extension is stated as this standard's own requirement: TEMPEST/1-92 is cited for the emanations countermeasures it actually covers, since that document addresses laboratory testing of signals leaving equipment and does not apply to facilities or inbound signals.

View control