Here is a simplified, accessible summary of the FIPS (Federal Information Processing Standards) regime, and a sketch of other U.S. security / communications rules you should know — plus caveats. (If you like, I can also show how these compare with UK/EU equivalents.)
FIPS are a set of standards published by NIST (the U.S. National Institute of Standards and Technology) for use by U.S. federal agencies — and often by their contractors and vendors — especially when handling sensitive information. ([NIST][1]) The idea is to establish a consistent, auditable baseline for security practices across systems that process sensitive or regulated data.
Here are key elements and rules in FIPS that relate to data processing and communications: