{"product_id":10092,"v_id":10092,"product_name":"IBM Tivoli Security Operations Manager  4.1.1","certification_status":"Not Certified","certification_date":"2009-04-13T00:04:00Z","tech_type":"Enterprise Security Management","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Luis Caseo-Arias","vendor_phone":"512-286-2536","vendor_email":null,"assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt;\"><span style=\"mso-bidi-font-weight: bold;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Tivoli Security Operations Manager (TSOM) supports the following security functions: Audit, Identification and Authentication, User Data Protection, Security Management, Protection of the TSF, IDS.</span></span></span></p>\r\n<p class=\"MsoBodyText\" style=\"text-justify: inter-ideograph; margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoBodyText\" style=\"text-justify: inter-ideograph; margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">TSOM is a security event management software solution designed to provide a comprehensive and coherent view of enterprise security. TSOM correlates event data from disparate machines outside TSOM, called sensors. Sensors are third-party products such as firewalls, intrusion detection systems, computer systems, and routers.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Once data is correlated from sensors, TSOM analyzes the data to uncover legitimate threats to the enterprise. </span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">User activity on TSOM is audited and stored in the underlying database in the IT environment of the TSOM. Audit information may be accessed through the User Interface.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Access to audit information is restricted to authorized administrators.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoBodyText\" style=\"text-justify: inter-ideograph; margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">User identification and authentication is required to access the user interface of TSOM. The user is always prompted for user name and password credentials before accessing the system. The user login process performs authentication as well as providing system privileges that are defined on a per-user or per-role basis. Access to the User Interface is allowed through support for HTTP using Internet Explorer 5.5 or greater. Transmission security is maintained by using HTTPS (SSL) between the end user and the Web-based Console Manager (otherwise referred to as &ldquo;the system&rdquo;).<span style=\"mso-spacerun: yes;\">&nbsp; </span>TSOM includes a FIPS validated module (certificate #409) to implement SSL.</span></span></p>\r\n<p class=\"MsoBodyText\" style=\"text-justify: inter-ideograph; margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">TSOM enforces an access control policy which defines the objects that an authorized user of TSOM will have permission to manage and configure.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These objects includes security domains, rules that can be defined within TSOM, hosts, networks, events, tickets, and firewall rules.</span></span></p>\r\n<p class=\"MsoBodyText\" style=\"text-justify: inter-ideograph; margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">TSOM is designed to provide threat management for security incidents, which require handling many-to-one relationships. The Central Management System (CMS) in turn correlates the data, determines the threat and presents the relevant information to the authorized user through a GUI interface.<span style=\"mso-spacerun: yes;\">&nbsp; </span>TSOM provides the user interface utilized by the authorized administrator to manage the security and network event data collection functions and attributes.</span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; tab-stops: 386.45pt;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">TSOM provides various mechanisms to ensure that the access control policy is always enforced and the data transmitted between TSOM components is protected using the cryptographic functionality from an included FIPS validated module (certificate #409) Additionally, TSOM ensures that all TSF data is made available to distributed parts of TSOM.</span></span></p>","evaluation_configuration":"<p class=\"Default\" style=\"margin: 0in 0in 0pt;\"><strong><span style=\"font-size: 10pt;\"><span style=\"font-family: Times New Roman;\">TSOM must be installed and configured according to the following guidance documents</span></span></strong></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt 0.25in; tab-stops: .25in;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt 0.25in; tab-stops: .25in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Tivoli Security Operations Manager Version 4.1.1 Installation Guide, July 2008</span></span></p>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt 0.25in; tab-stops: .25in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">Tivoli Security Operations Manager Common Criteria Guide Version 4.1.1</span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The IBM TSOM TOE is supported by hardware and software in the IT environment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The IT Environment of the TOE consists of the following:</span></span></p>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE operates in a Linux/Unix operating system environment (Redhat Enterprise Server, Windows Server 2003, Solaris, or AIX operating systems).<span style=\"mso-spacerun: yes;\">&nbsp; </span>The operating system supports the protection of TSF processes and data by providing TSF domain separation and non-bypassability.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE also relies on the operating system to provide a reliable time stamp for the audit and event records;</span></span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt 0.25in; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE relies on the use of a database (DB2 or Oracle) for storing audit and event data;<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE relies upon the use of a GeoServer and trusted DNS servers in the IT environment for its geoserver feature and upon SMTP and SNMP servers for aspects of its IDS functionality.</span></span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE relies on the use of an internet browser in the IT environment (Internet Explorer v.6 or later or Mozilla v1.3 or later) for access to the User Interface; and</span></span></li>\r\n</ul>\r\n<p class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>\r\n<ul style=\"margin-top: 0in;\" type=\"disc\">\r\n<li class=\"MsoNormal\" style=\"text-justify: inter-ideograph; margin: 0in 0in 0pt; text-align: justify; mso-list: l0 level1 lfo1; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The TOE collects data from &ldquo;sensors\" which are disparate machines in the IT environment of the TOE.</span></span></li>\r\n</ul>\r\n<p class=\"MsoBodyText\" style=\"margin: 0in 0in 6pt 0.25in; tab-stops: .25in;\"><span style=\"font-size: x-small; font-family: Times New Roman;\">&nbsp;</span></p>","security_evaluation_summary":"<p><span style=\"font-size: 10pt;\"><span style=\"font-family: times new roman,times;\"><span style=\"font-size: small;\">\r\n<p class=\"BodyText4\" style=\"margin: 0in 0in 6pt 0.5in;\"><span style=\"font-size: 10pt;\">The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that <span style=\"mso-bidi-font-style: italic;\">the<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span>TOE<em> </em></span>meets the security requirements contained in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the<span style=\"mso-spacerun: yes;\">&nbsp;&nbsp;&nbsp; </span>TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for Tivoli Security Operations Manager 4.1.1 achieved EAL3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Several validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in September 2008.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report IBM Tivoli Security Operations Manager 4.1.1<em> </em>prepared by CCEVS.</span></p>\r\n</span></span></span></p>","environmental_strengths":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt 0.5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times New Roman;\">The<strong style=\"mso-bidi-font-weight: normal;\"> </strong>IBM Tivoli Security Operations Manager<span style=\"mso-bidi-font-style: italic;\"> TOE</span> is a commercial product that supports Audit, Identification and Authentication, User Data Protection, Security Management, and Protection of the TOE security functions.<span style=\"mso-bidi-font-weight: bold;\"><span style=\"mso-spacerun: yes;\">&nbsp; </span></span>The<span style=\"mso-spacerun: yes;\">&nbsp; </span>IBM Tivoli Security Operations Manager<em><span style=\"mso-bidi-font-weight: bold;\"> </span></em><span style=\"mso-spacerun: yes;\">&nbsp;</span>TOE provides a level of protection that is appropriate for IT environments where the<em><span style=\"mso-bidi-font-weight: bold;\"> </span></em><span style=\"mso-spacerun: yes;\">&nbsp;</span>TOE and the platform upon which is installed can be appropriately protected from physical attacks.<span style=\"mso-bidi-font-weight: bold;\"><span style=\"mso-spacerun: yes;\">&nbsp;&nbsp; </span></span></span></span></p>","features":[]}