U.S. Government Approved Protection Profile - U.S. Government Protection Profile for General-Purpose Operating Systems in a Networked Environment, Version 1.0

Short Name: pp_gpospp_v1.0

Technology Type: Operating System

CC Version: 3.1

Date: 30 August 2010

Preceded By: pp_os_ca_v1.d

Conformance Claim: EAL2 Augmented

 

PP OVERVIEW

The “U.S. Government Protection Profile for General-Purpose Operating Systems in a Networked Environment” specifies security requirements for commercial-off-the-shelf (COTS) general-purpose operating systems in networked environments. This profile establishes the requirements necessary to achieve the security objectives of the Target of Evaluation (TOE) and its environment.

Conformant products support Identification and Authentication, Discretionary Access Control (DAC), and an audit capability and Cryptographic Services. These systems provide adequate security services, mechanisms, and assurances to process administrative, private, and sensitive/proprietary information. When an organization’s most sensitive/proprietary information is to be sent over a publicly accessed network, the organization should apply additional protection at the network boundaries.

SECURITY EVALUATION SUMMARY

Conformant operating systems include the following security features:

  • Identification and Authentication which mandates authorized users to be uniquely identified and authenticated before accessing information stored on the system;

  • Discretionary Access Control (DAC) which restricts access to objects based on the identity of subjects and groups to which they belong, and allows authorized users to specify protection for objects that they control;

  • Cryptographic services which provide mechanisms to protect TSF code and data and also provide support to allow authorized users and applications to encrypt, decrypt, hash, and digitally sign data as it resides within the system and as it is transmitted to other systems; and

  • Audit services which allow authorized administrators to detect and analyze potential security violations.

Assigned to the following Validated Products

Please forward any questions or comments to pp-comments@niap-ccevs.org