{"product_id":10115,"v_id":10115,"product_name":"Computer Associates eTrust Security Command Center r8 SP1 with_CR2 patch","certification_status":"Not Certified","certification_date":"2007-01-26T00:01:00Z","tech_type":"Enterprise Security Management","vendor_id":{"name":"CA Technologies","website":"www.ca.com"},"vendor_poc":"William F. Clark","vendor_phone":"703-708-3501","vendor_email":"william.clark@ca.com","assigned_lab":{"cctl_name":"CygnaCom Solutions, Inc"},"product_description":"<p><em>e</em>Trust Security Command Center&trade; (SCC) is a software application that provides users the ability to manage and monitor the security of an enterprise at many different levels and offers customizable views, ranging from executive-level summaries to views specially designed for network security specialists.</p>\r\n<p><em>e</em>Trust SCC allows security event data and audit data to be collected from a diverse set of systems, applications, devices and appliances and then provides the ability to analyze data, set rules for alerts based on events or correlations of events, and perform reporting. <em>e</em>Trust SCC provides capabilities to create and manage a centralized policy regarding the retention of audit information. In addition, <em>e</em>Trust SCC provides tools to monitor the status of network resources and to manage products that reside on the network. <em>e</em>Trust SCC includes <em>e</em>Trust Audit, an audit data collector and analyzer, to further enhance the ability to analyze audited events on diverse systems throughout an enterprise. </p>","evaluation_configuration":"<p>The evaluated configuration includes the <em>e</em>Trust SCC, <em>e</em>Trust Audit Policy Manager and Audit Data Tools installed on MS Windows 2000 platforms. MS Windows XP and MS Windows 2000 environment was used to test the managed node features, i.e., nodes from which audit data was collected. </p>\r\n<div style=\"PADDING-RIGHT: 1em; FLOAT: left; WIDTH: 32%\">\r\n<table cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" border=\"1\">\r\n    <tbody>\r\n        <tr>\r\n            <th><strong><em>e</em>Trust Security Command Center</strong> </th>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"BACKGROUND: #eee\" valign=\"top\"><strong>Tested Configuration</strong> </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><em>e</em>Trust SCC Server<br />\r\n            <em>e</em>Trust Audit Policy Manager<br />\r\n            <em>e</em>Trust Audit Client<br />\r\n            Server-Side Product Integration Kits (PIKs) </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Windows 2000 Server with SP4</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Minimum Hardware Requirements</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Pentium-III, 1.4 GHz processor</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">1000 MB RAM</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">6000 MB Disk Space</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Database Requirements</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Microsoft SQL Server 2000 SP3</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Software:</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">TCP/IP <br />\r\n            Microsoft Internet Explorer 6.0 </td>\r\n        </tr>\r\n    </tbody>\r\n</table>\r\n</div>\r\n<div style=\"PADDING-RIGHT: 1em; FLOAT: left; WIDTH: 32%\">\r\n<table cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" border=\"1\">\r\n    <tbody>\r\n        <tr>\r\n            <th><strong><em>e</em>Trust Audit Data Tools Server</strong> </th>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"BACKGROUND: #eee\" valign=\"top\"><strong>Tested Configuration</strong> </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><em>e</em>Trust Audit Data Tools<br />\r\n            <em>e</em>Trust Security Command Center Agent </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Windows 2000 Server with SP4 </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Minimum Hardware Requirements</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Pentium 1 GHz</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">1000 MB RAM </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">6000 MB Disk Space</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Database Requirements</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Microsoft SQL Server 2000 SP3</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Software:</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">TCP/IP </td>\r\n        </tr>\r\n    </tbody>\r\n</table>\r\n</div>\r\n<div style=\"CLEAR: right; FLOAT: left; WIDTH: 32%\">\r\n<table cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" border=\"1\">\r\n    <tbody>\r\n        <tr>\r\n            <th><strong>Client Machine</strong> </th>\r\n        </tr>\r\n        <tr>\r\n            <td style=\"BACKGROUND: #eee\" valign=\"top\"><strong>Tested Configuration</strong> </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><em>e</em>Trust Security Command Center Agent<br />\r\n            <em>e</em>Trust Audit Client<br />\r\n            Agent-Side PIKs </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Windows XP </td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Minimum Hardware Requirements</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">Pentium 1 GHz</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">128 MB RAM</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">100 MB Disk Space</td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\"><strong>Software</strong></td>\r\n        </tr>\r\n        <tr>\r\n            <td valign=\"top\">TCP/IP <br />\r\n            Microsoft Internet Explorer 6.0 </td>\r\n        </tr>\r\n    </tbody>\r\n</table>\r\n</div>","security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. CA <em>e</em>Trust SCC was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 2.2. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. CygnaCom Solutions has determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL2. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in January 2007. </p>","environmental_strengths":"<p>The TOE provides the following security services: </p>\r\n<p><strong>Security Audit: </strong><em>e</em>Trust SCC has the following security auditing functions:</p>\r\n<ul type=\"disc\">\r\n    <ul type=\"circle\">\r\n        <li>Collects audit information from its managed resources </li>\r\n        <li>Generates audit records of its own use </li>\r\n        <li>Takes administrator defined actions when a security relevant event is detected in a resource&acirc;&euro;&trade;s audit data or when the status of a resource becomes critical. </li>\r\n        <li>Provides the administrators with rule and filter based specification of security significant events. </li>\r\n        <li>Provides users with audit record viewing capabilities </li>\r\n    </ul>\r\n</ul>\r\n<p><strong>Identification and Authentication:</strong> <em>e</em>Trust SCC provides user identification through user accounts and password-based authentication.</p>\r\n<p><strong>Security Management:</strong> <em>e</em>Trust SCC provides security management through the use of the administration capabilities of the web-based user interface. Access to management functions and data is controlled through the use of administrator roles.</p>\r\n<p><strong>Partial Protection of the TSF</strong>: <em>e</em>Trust SCC protects its security functions and data from interference and tampering through its own interfaces in conjunction with protection from the IT environment. </p>\r\n<!-- InstanceEndEditable -->","features":[]}