{"product_id":10176,"v_id":10176,"product_name":"Configuresoft Enterprise Configuration Manager 4.10","certification_status":"Not Certified","certification_date":"2008-07-31T00:07:00Z","tech_type":"Network Management","vendor_id":{"name":"Configuresoft, Inc.","website":"http://www.configuresoft.com/"},"vendor_poc":"Michael Dunbar","vendor_phone":"703-425-0098","vendor_email":"michael.dunbar@configuresoft.com","assigned_lab":{"cctl_name":"UL Verification Services"},"product_description":"<p><span style=\"font-weight: normal; font-size: 12pt\">The Configuresoft Enterprise Configuration Manager (ECM) is a network software product that allows administrators to manage configuration control over Enterprise network resources. ECM offers a scalable, cross platform solution to help customers effectively manage and control the configuration of Network resources from a centralized Administrator workstation.&nbsp;</span></p>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-weight: normal; font-size: 12pt\">ECM collects security and configuration data settings across the IT enterprise through an Agent software component. Agents are available for multiple Operating Systems including Windows, UNIX, Linux, and Active Directory Servers. The agent is in the form of a quiescent executable which wakes up when it receives a call for a desired collection or change. The data and configuration settings are collected from the targeted machines which ECM stores in a comprehensive Configuration Management Database (CMDB). Data transfer is secured through the Microsoft cryptographic API installed on the Collector and on Window&rsquo;s based agent machines that supports secure session establishment. UNIX sessions are secured through an OpenSSL object module. By leveraging the information stored in the CMDB, IT administrators can assure that the policies they develop are in effect and institute actions through ECM to support IT infrastructure policies. </span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-weight: normal; font-size: 12pt\">In the event an Agent is not available, due to a disconnected IT resource, the Agent machine is marked within ECM as &ldquo;Failed&rdquo; and logs the event. The &ldquo;Failed&rdquo; status applies to a given Collection attempt. When a new Collection request is initiated, connection attempts resume and upon successful connection, the status of the &ldquo;Failed&rdquo; machine is then reported as &ldquo;Succeeded&rdquo;.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-size: 12pt\">Configuresoft ECM&rsquo;s CMDB based approach allows IT administrators to run enterprise compliance reports and policies against the centralized CMDB, not each remote machine across the network. Traditional issues such as data gaps due to un-powered and disconnected machines and impacts to client performance are eliminated using this CMDB based approach. ECM combines the power of distributed computing with minimal resource consumption. This low impact approach provides secure data collection, remediation and continuous compliance monitoring capabilities.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt; text-autospace: ideograph-numeric\"><b>&nbsp;</b></div>","evaluation_configuration":null,"security_evaluation_summary":"<div style=\"text-justify: inter-ideograph; margin: 0pt; text-autospace: ideograph-numeric\"><span style=\"font-size: 12pt\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Configuresoft Enterprise Configuration Manager 4.10 was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.2 and International Interpretations effective on June 12, 2006. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.2. InfoGard Laboratories determined that the evaluation assurance level (EAL) for the product is the EAL 3 family of assurance requirements. The product, when configured in accordance with the guidance identified in Section 6.2 of the ST, satisfies all of the security functional requirements stated in the Configuresoft Enterprise Configuration Manager 4.10 Security Target. This IT product does not conform to a validated Protection Profile. A Validator, on behalf of the CCEVS Validation Body, monitored the evaluation carried out by InfoGard. The evaluation was completed in April 2008. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for Configuresoft Enterprise Configuration Manager 4.10, prepared by CCEVS.</span></div>","environmental_strengths":"<p>&nbsp;</p>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-size: 12pt\">The Configuresoft Enterprise Configuration Manager 4.10 supports the following security functions:</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">ECM Data Access Control:</span></b><span style=\"font-size: 12pt\"> The ECM Data Access Control security function provides role based access to data collected from Agent Machines and maintained in the CMDB.&nbsp;It includes restrictions on accessing and viewing the Collected Data as well as role based restrictions, on which subsets of data can be analyzed through the Assessment Security Function based on ECM Role. This functionality is provided primarily through the CMDB in conjunction with the Collector for access control support.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Security Audit:</span></b><span style=\"font-size: 12pt\"> The Configuresoft ECM TOE generates audit events within the Collector machine to log TSF events by creating Windows Operating System events.&nbsp;These logged events include the time of the event, success or failure of the event and the User Identification associated with the event. Audits are generated for login success/failures as well as for application configuration actions, CMDB data consolidation, analysis and remediation actions and security management activities initiated through the Administrator Console.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Identification and Authentication:</span></b><span style=\"font-size: 12pt\"> The TOE requires that all users are successfully identified and authenticated prior to gaining access to TSF resources. All authorized ECM users are Administrators holding a specific ECM administrator role. Therefore, all references to authorized users within this security target refer to ECM administrators.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Secure Communications:</span></b><span style=\"font-size: 12pt\"> The ECM TOE secures the communication from the Web Console machine to the Collector&rsquo;s Web App subsystem using the HTTPs protocol and leveraging the Microsoft Cryptographic module in the IT Environment. This assures that Administrator sessions with the ECM application are secured via SSL/TLS utilizing symmetric key cryptography. Data transfers (i.e.: during the Collection process) between the Agent Machines and the Collector Machine are secured using one of two available methods. For Windows and Active Directory based Agent Machines, DCOM may be used and when used implements the highest possible security setting of Packet Privacy (PKT_PRIVACY) in conjunction with Microsoft cryptographic module support provided in the IT Environment. Alternatively, <a name=\"OLE_LINK17\">TLS record protocol over an HTTP </a>transport may be used to secure these data transfers; also utilizing the Microsoft cryptographic module provided in the IT Environment. The Secure Communications security function is supported by the Collector subsystem working with the applicable Agent software.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Data Consolidation:</span></b><span style=\"font-size: 12pt\"> Through the Data Consolidation Security Function, the TOE utilizes filters to selectively collect data elements from: Windows, UNIX, Linux and Active Directory Agent Machines. The data may then be directly stored in the CMDB or, alternatively if a &ldquo;Delta&rdquo; Collection is selected, it compares the newly collected results to a baseline data set stored on the Agent Machine, so that it transmits only the delta information over the network to the Collector and allows the Collector to then store the delta in the CMDB. This minimizes the network traffic and the data insert time into the CMDB. This security function is supported by the Collector subsystem in conjunction with the applicable Agent. Data storage support is provided by the CMDB subsystem.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Protection of TOE Functions:</span></b><span style=\"font-size: 12pt\"> The Collector requires physical and logical protection to assure that TOE related security functions are not bypassed or altered. The Operating System Environment (TOE Environment), secure communications and access control methods described earlier provide this protection. The only Human User interface available for login is the browser based GUI session between the Web Console machine and the ECM Web App Subsystem on the Collector machine. Valid credentials must be entered through this interface in order to access the TSF. Agents installed on machines within the network do not provide any local interfaces allowing access. All communication with the Agent must occur by the Collector subsystem during Collection and Remediation activities. The agent cannot initiate sessions with the Collector or initiate communications within a session and may only respond to specified requests from the Collector.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Assessment:</span></b><span style=\"font-size: 12pt\"> The Assessment Security function provides analysis capabilities through the TSF to evaluate data collected and compare it to compliance matrices. Operational, security, and regulatory Compliance templates are available for selection to assess CMDB data and inform administrators of aspects of configuration which are not in compliance with selected criteria.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><b><span style=\"font-size: 12pt\">Remediation:</span></b><span style=\"font-size: 12pt\"> The Remediation Security Function provides the ability for the TSF to initiate changes to the specific Windows configuration through the Administrator Console: </span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 6pt 0pt 3pt 36pt; text-indent: -18pt; text-align: justify\"><span style=\"font-size: 12pt\">&Oslash;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 12pt\">Change Agent Machine Passwords</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 6pt 0pt 3pt 36pt; text-indent: -18pt; text-align: justify\"><span style=\"font-size: 12pt\">&Oslash;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 12pt\">Start/Stop Services (applies to Agent Services configured in the Automatic or Manual Startup mode)</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 6pt 0pt 3pt 36pt; text-indent: -18pt; text-align: justify\"><span style=\"font-size: 12pt\">&Oslash;<span style=\"font: 7pt 'Times New Roman'\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span style=\"font-size: 12pt\">Apply a registry change</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 6pt 0pt 3pt 36pt\">&nbsp;</div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\"><span style=\"font-size: 12pt\">This may be based on compliance analysis or evaluation of CMDB data and review of Assessment reports. In the Common Criteria certified configuration: remediation does not apply to UNIX and Linux based Agent Machines or any other Windows or Active Directory data other than those specified.</span></div>\r\n<div style=\"text-justify: inter-ideograph; margin: 0pt\">&nbsp;</div>\r\n<div style=\"margin: 0pt\"><b><span style=\"font-size: 12pt\">Security Management: </span></b><span style=\"font-size: 12pt\">The Security Management Security Function provides the Security Management functions for the Collector machine and CMDB resources. Security Management functions are provided by the Web App component of the Collector Machine working through the Windows Internet Explorer Browser component of the Web Console Machine. Various management functions are available to allow Administrators to collect data from Agent Machines, evaluate data within the CMDB and initiate Remediation measures as required. The Collector and Web App subsystems within the Collector machine provide the prime support for the Security Management security function.</span></div>","features":[]}