Validated Product - Computer Associates eTrust Admin Version 8.0 with CAM v1.11 patchCertificate Date: 03 February 2006 Validation Report Number: CCEVS-VR-06-0008 Product Type: System Access Control Conformance Claim: EAL2 PP Identifiers: None PRODUCT DESCRIPTIONThe eTrust Admin product consists of an eTrust Admin Server, Administrator Interface, Web-based Interface, and eTrust Directory. Briefly, the TOE includes the eTrust Admin Server software, the Administrator Interface, and the Web-based Interface. The eTrust Directory and the Windows 2000 OS, upon which the eTrust Admin Server runs, are included in the IT Environment. The TOE is a software-only TOE which consists of:
The TOE includes eTrust Admin Options (part of eTrust Admin Server) to communicate with managed systems. Only the Windows OS option was tested during the evaluation. eTrust Admin provides the following security features:
SECURITY EVALUATION SUMMARYThe evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. The TOE was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL 2. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in November 2005. Test Configuration for Evaluation
ENVIRONMENTAL STRENGTHSThe TOE provides the following security functionality: security audit, identification and authentication, secure management, and partial protection of the TOE security functions. The main security service provided by eTrust Admin is enablement of user life-cycle management across disparate systems, applications, physical resources, and Web services. Based on user roles, eTrust Admin automatically creates, modifies, and deletes user accounts on multiple, heterogeneous systems or applications. It integrates with human resources systems to achieve completely automated user account management. Vendor: CA, Inc. Contact: William F. Clark Phone: 703-708-3501 Fax: 703-708-3683 Web: http://www.ca.com Email: william.clark@ca.com CC Testing Lab: CygnaCom Solutions, Inc |