Approved Security Functions
Approved security functions are the specific cryptographic and security mechanisms that an authoritative body has vetted and permitted for protecting sensitive information. Organizations are generally expected to use these approved functions rather than unvetted or proprietary alternatives when safeguarding data. The exact list of approved functions depends on the governing standard and revision that applies to a given system.
Approved security functions generally refers to the set of cryptographic algorithms, modes, and related security mechanisms that have been evaluated and sanctioned by a governing authority for use in protecting information within a defined scope, such as federal information systems handling CUI or national security systems. In practice, implementations are expected to rely on these vetted functions, rather than non-validated or proprietary alternatives, to meet applicable confidentiality and integrity requirements. The precise set of approved functions, the authority maintaining the list, and any validation obligations vary by the applicable standard and revision; readers should confirm the specific approved functions and their status against the current authoritative text governing their system, as this entry does not establish particular algorithms, control numbers, or validation program details.
Why it matters
Approved security functions establish a baseline of trust for how sensitive information is protected. When an authoritative body vets a cryptographic algorithm or security mechanism, it provides assurance that the function has been examined against recognized criteria rather than relying on the unproven claims of a vendor or an internally developed scheme. For organizations handling Controlled Unclassified Information (CUI), national security systems, or other regulated data, using approved functions rather than proprietary or non-validated alternatives is generally a precondition for meeting applicable confidentiality and integrity requirements. Deploying an unvetted algorithm can leave data exposed to weaknesses that a formal evaluation process is designed to surface.
The practical significance also lies in accountability and consistency across systems. A commonly repeated expert caution is that selecting an approved algorithm is not the same as implementing it correctly or having that implementation validated; using an approved function does not by itself guarantee security, nor does it substitute for the broader authorization and continuous monitoring obligations that govern a system. Compliance officers and system security managers should treat the approved-functions requirement as one element of a layered control set rather than as a standalone assurance.
Because the specific set of approved functions, the authority that maintains it, and any associated validation obligations vary by governing standard and revision, teams that assume a fixed or permanent list can drift out of compliance as guidance evolves. Functions can be added, deprecated, or restricted over time. This entry does not establish particular algorithms, control numbers, or validation program details, so readers must confirm the current status of any function against the authoritative text governing their system.
Who it's relevant to
Inside Approved Security Functions
Common questions
Answers to the questions practitioners most commonly ask about Approved Security Functions.