{"product_id":10147,"v_id":10147,"product_name":"ImageNow v5.42 SP3 and WebNow v3.42","certification_status":"Not Certified","certification_date":"2007-01-10T00:01:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"Perceptive Software, Inc.","website":"http://www.imagenow.com"},"vendor_poc":"Jesse Armstrong, Amanda Bucholz","vendor_phone":"913.422.7525","vendor_email":"info@imagenow.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The Target of Evaluation (TOE) is ImageNow v5.42 SP3 and WebNow v3.42</p>\r\n<p>The TOE is a document imaging, management and workflow solution based on a client/server architecture that provides a user the ability to scan, file, retrieve, print, fax or distribute electronic objects. Because the TOE can support widespread imaging within an entire network, it provides security auditing, thorough security management functionality, and secure data transfer when accessing stored images via WebNow or the ImageNow Client.</p>\r\n<p>The TOE offers users the flexibility of deployment options and configurations that allow choices for distributed document capture, indexing, storage and management capabilities. ImageNow can simultaneously manage scanning along with the importing of object data from multiple sources, such as fax servers, mail servers, or a network location.</p>\r\n<p>The TOE allows images to be indexed and tracked by 20 different data elements and six user-defined index values. An unlimited number of keywords can be assigned to a document, enabling the user to retrieve specific information. ImageNow also has a LearnMode to &lsquo;learn&rsquo; the host application screen. From the host application screen, a user retrieves the desired transaction. The user presses the ImageNow icon from the windows system tray and ImageNow retrieves all associated documents linked to the current displayed transaction. The toolbars in ImageNow provide the user with the ability to annotate key points on the document without altering original integrity, distribute the document via print, fax, or e-mail, and view multiple documents that are linked to the current displayed document. </p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the ImageNow v5.42 SP3 and WebNow v3.42 TOE was judged is described in the Common Criteria for Information Technology Security Evaluation, Version 2.3, August 2005 and International Interpretations effective on 5 January 2006. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Evaluation Methodology, Version 2.3, August 2005. Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 2 augmented with ALC_FLR.2 and AVA_MSU.1 family of assurance requirements. The product, when configured as specified in the Perceptive Software, Inc., ImageNow Installation Guide for ImageNow 5.42x and Perceptive Software, Inc., WebNow Installation Guide for WebNow 3.4, satisfies all of the security functional requirements stated in the Perceptive Software, Inc., ImageNow v5.42 SP3 and WebNow v3.42 Security Target, Version 1.0. One Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in October 2006. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-06-0056, dated 10 January 2007) prepared by CCEVS.</p>","environmental_strengths":"<p>The TOE is a document imaging, management and workflow solution based on a client/server architecture that provides a user the ability to scan, file, retrieve, print, fax or distribute electronic objects. Because the TOE can support widespread imaging within an entire network, it provides security auditing, thorough security management functionality, and secure data transfer when accessing stored images via WebNow or the ImageNow Client. ImageNow v5.42 SP3 and WebNow v3.42 TOE supports the following four security functions:</p>\r\n<p><strong>Security audit</strong> &mdash; ImageNow generates an audit record for audit mechanism start-up and shutdown events, as well as viewing, deleting, and re-indexing images. Each audit record includes the date and time of the event, type of event, subject identity, the IP and MAC addresses where the event occurred, and the outcome of the event. An Owner can review the audited records and can select the auditable events. In addition, ImageNow provides audit selection capabilities for reviewing audit data. The audit events are stored on the underlying operating system. The Information Technology (IT) environment provides a reliable timestamp for audit use and the protection of the audit records.</p>\r\n<p><strong>User data protection</strong> &mdash; ImageNow enforces rules-based access control on users and groups. The Owner or Manager has the ability to grant access on the drawer objects that contain document pages.</p>\r\n<p><strong>Identification and authentication</strong> &mdash;ImageNow maintains a list of security attributes for users and requires users to be authorized prior to granted access to protected functions as security attributes are associated to users. The TOE relies on the IT environment to authenticate users using user and password mechanisms provided by directory services.</p>\r\n<p><strong>Security management</strong> &mdash; ImageNow restricts the ability to manage user security policy rules. ImageNow provides the functions necessary for effective management of the security functions and all actions are accomplished on the Client with the exception of auditing, as that is accomplished via the ISA console. </p>\r\n<!-- InstanceEndEditable -->","features":[]}