{"product_id":10042,"v_id":10042,"product_name":"SecureInfo Risk Management System 3.2.06.12","certification_status":"Not Certified","certification_date":"2006-06-26T00:06:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"SecureInfo Corporation","website":"http://www.secureinfo.com"},"vendor_poc":"Roberto Garcia","vendor_phone":"210.403.5600","vendor_email":"roberto.garcia@secureinfo.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p>SecureInfo Risk Management System (RMS) Version 3.2.06.12 is a web based software application that is marketed as a tool that generates security Certification and Accreditation (C&amp;A) document templates that a customer can tailor for government and other regulatory mandates. It provides a formal network C&amp;A process to determine the level-of-risk and maintain overall security posture of an organization&acirc;&euro;&trade;s enterprise information infrastructure. Using RMS, a user can develop required security documentation necessary to perform C&amp;A.</p>\r\n<p>Due to the potential sensitivity of the information contained in the documents managed by RMS, RMS provides mechanisms to limit accessibility to those with a need-to-know. Therefore, RMS supports identification and authentication, access control, and role management features. These features limit access to RMS, RMS data elements, and support three roles: RMS system administrator, domain manager, and user. These security features were the focus of this CC evaluation. The validity of vendor claims regarding suitability for use in C&amp;A activities was not part of this evaluation.</p>\r\n<p>Access to RMS is a simple client/server relationship using the Internet Explorer web browser on the client system. An RMS client application provides a GUI interface to the RMS server application. The client is not part of the TOE and is outside the scope of this evaluation. Similarly, the underlying hardware, operating system, and standard support applications for the web service application on the server were treated as part of the IT Environment. </p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The valuation demonstrated that the SecureInfo RMS TOE meets the security requirements contained in the Security Target.</p>\r\n<p>The criteria against which the SecureInfo RMS TOE were judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for the SecureInfo RMS TOE is EAL 2. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p>A Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by the COACT, Inc. CAFE Lab. The evaluation was completed in June 2006. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p>The TOE&acirc;&euro;&trade;s Security Functions are:</p>\r\n<p><strong>Identification and Authentication (I&amp;A) </strong>- The TOE requires users to identify and authenticate themselves before accessing the TOE, and therefore, by default, before viewing any TSF data or configuring any portion of the TOE. No action can be initiated before proper identification and authentication. Each TOE user has security attributes associated with their account that defines the functionality the user is allowed to perform. </p>\r\n<p><strong>Access Control</strong> - The TOE uses access control to address security attribute usage and characteristics of policies and may have the ability to explicitly authorize or deny access to an object based upon security attributes. Specifically, security attribute-based access control allows the TOE to enforce access based upon security attributes and named groups of attributes. </p>\r\n<p><strong>Role Management </strong>- The TOE supports three security roles: Authorized RMS System Administrator, Domain Manager, and Authorized User. These roles are defined within the TOE. An authorized RMS System Administrator has the ability to define groups and other roles to assist in the management of access rights and privileges. A Domain Manager has full access to and has the ability to create user accounts in his or her domain. Authorized Users are users that are authorized to use some TOE resources.</p>","features":[]}