{"product_id":10017,"v_id":10017,"product_name":"Marimba Desktop/Mobile Management and Server Change Management (including Marimba Infrastructure 6.0.2.1, Marimba Policy Manager 6.0.2, and Marimba Deployment Manager 6.0.2)","certification_status":"Not Certified","certification_date":"2005-06-10T00:06:00Z","tech_type":"Secure Messaging","vendor_id":{"name":"BMC Software, Inc.","website":"http://www.bmc.com"},"vendor_poc":"Bryant Macy","vendor_phone":"(650)-930-5307","vendor_email":"bryant_macy@bmc.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The Desktop/Mobile Management (DMM) and Server Change Management (SCM) products are software change management packages produced by BMC Software, Inc., 440 Clyde Ave., Mt. View, CA 94043, herein called simply DMM/SCM. The SCM software is designed for use with groups of servers, while the DMM software is designed for use with groups of desktop machines. Both products rely primarily on a pair of applications called the Tuner and the Transmitter, which serves channels (applications or files) over a network. </p>\r\n<p>The majority of software components are identical between the DMM and SCM products and include the following security-relevant applications that comprise the TOE: Marimba Infrastructure 6.0.2.1, Marimba Policy Manager 6.0.2, and Marimba Deployment Manager 6.0.2. </p>\r\n<p>The DMM/SCM allows administrators to perform change management of software packages across an enterprise. For example, they can package applications and application updates to automate their distribution. DMM/SCM also allows administrators to perform OS migration and perform hardware and software inventories of connected machines. </p>\r\n<p>DMM/SCM products are capable of managing these packages from a single location in a heterogeneous environment, including Windows and Solaris platforms. </p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the Marimba TOE meets the security requirements contained in the Security Target - Marimba Desktop/Mobile Management and Server Change Management Security Target, Version 2.0, 26 May 2005. </p>\r\n<p>The criteria against which the Marimba TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 1.0. Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the Marimba TOE is EAL 3. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target. </p>\r\n<p>A Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in March 2005. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report. </p>","environmental_strengths":"<p>The Marimba TOE provides security audit, user data protection, identification and authentication, and security management features as they relate to the distribution and management of enterprise applications. </p>\r\n<p><strong>Security Audit: </strong>DMM/SCM audits the actions that occur on the Transmitter. The log files contain information about events such as starting the Transmitter and modifying access control attributes associated to channels, as well as any problems associated with those events. </p>\r\n<p><strong>User Data Protection: </strong>DMM/SCM access privileges for the user, hence, access to the various channels and other named objects are controlled by the combination of user and group identification and the access control attributes associated to the named objects. </p>\r\n<p><strong>Identification and Authentication: </strong>The DMM/SCM requires users to be identified and authenticated before they can access the TOE and the TOE security-relevant data. </p>\r\n<strong>Security Management: </strong>The TOE provides a number of interfaces to manage the configuration and implementation of the policy enforced by the TOE. Security management includes managing the following items: access control of channels and configuring termination of inactive sessions. <!-- InstanceEndEditable -->","features":[]}