My company is gearing up to get 800-171 compliant. We're not a gov agency, but according to 800-171 controls, we must be using FIPS compliant algorithms for encryption, hashing, and signing. Is this correct or am I misreading the control? Thanks in advance for your help.
[link] [comments]