NIAP: Assurance Continuity
  NIAP  »»  Product Compliant List  »»  Product Entry  »»  Assurance Continuity  
Assurance Continuity - Maintenance Update of Cisco Web Security Appliance

Date of Maintenance Completion:  2018.01.30

Product Type:    Network Device

Conformance Claim:  Protection Profile Compliant

PP Identifier:    collaborative Protection Profile for Network Devices Version 1.0

Original Evaluated TOE:  2017.08.08 - Cisco Web Security Appliance 10.5

CC Certificate [PDF] Validation Report [PDF] Assurance Activity [PDF]

Administrative Guide [PDF]

Please note:  The above files are for the Original Evaluated TOE.  Consequently, they do not refer to this maintained version, although they apply to the maintained version. 

Security Target [PDF] * Assurance Continuity Maintenance Report [PDF]

Please note:  This serves as an addendum to the VR for the Original Evaluated TOE. 

* This is the Security Target (ST) associated with this latest Maintenance Release.  To view previous STs for this TOE, click here.

Readers are reminded that the certification of this product (TOE) is the result of maintenance, rather than an actual re-evaluation of the product.  Maintenance only considers the affect of TOE changes on the assurance baseline (i.e. the original evaluated TOE); maintenance is not intended to provide assurance in regard to the resistance of the TOE to new vulnerabilities or attack methods discovered since the date of the initial certificate.  Such assurance can only be gained through re-evaluation. 

Using a security impact analysis of the changes made to the TOE, which was provided by the developer, the CCEVS has determined that the impact of changes on the TOE are considered minor and that independent evaluator analysis was not necessary.  A summary of the results can be found in the Maintenance Report, which is written in relation to the product's original validation report and Security Target.  Readers are therefore reminded to read the Security Target, Validation Report, and the Assurance Maintenance Report to fully understand the meaning of what a maintained certificate represents. 

Product Description

Changes to Evaluation Documents:

·         ST: Updated FCS_TLSS_EXT.1.1 to add the following ciphersuites:

·         TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA as defined in RFC 4492

·         TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA as defined in RFC 4492

·         TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289

·         TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289 

Regression Testing:

Testing was completed with TLS prior to the product being certified in August 2017. That testing included the four TLS ciphersuites that have been added to the ST. However, additional tests of the four additional ciphersuites was performed with the evaluated version of the TOE, and demonstrated to work correctly with no observable consequences. That additional testing was performed as part of this Assurance Continuity activity. 

Vulnerability Analysis:

No additional vulnerability analysis was performed since there were no changes made to the TOE, either in hardware or software.

Vendor Information

Cisco Systems, Inc.
Lisa Rogers
Site Map              Contact Us              Home