{"product_id":10220,"v_id":10220,"product_name":"IBM DB2 Content Manager Enterprise Edition V8.4 Fix Pack 1a","certification_status":"Not Certified","certification_date":"2009-01-27T00:01:00Z","tech_type":"DBMS","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Pete Jacob, Jr.","vendor_phone":"408.463.2546","vendor_email":"jacobjr@us.ibm.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">Content Manager is a data management system (content management system) that provides a foundation for managing, accessing, and integrating critical business information on demand.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Content Manager is able to integrate many forms of data &mdash; document, Web, image, rich media &mdash; across diverse business processes and applications, including Siebel, PeopleSoft, and SAP, presenting the data in an integrated context for later use.</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 0in 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman';\"><span style=\"font-size: x-small;\">The components of Content Manager include a Library Server; one or more Resource Managers, the Content Manager 8.4 Connector Application Programming Interfaces (APIs); the System Administration Client; and the Client for Windows.</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 0in 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman';\"><span style=\"font-size: x-small;\">The Library Server is the key component of the Content Manager system.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Library Server resides on a DB2 Enterprise Server database environment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Library Server manages the content metadata and is responsible for identification and authentication for non-administrative users and identification for administrative users requesting services from Content Manager and access control to the resources residing on Resource Managers.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 0in 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman';\"><span style=\"font-size: x-small;\">The Resource Manager stores resources for Content Manager.<span style=\"mso-spacerun: yes;\">&nbsp; </span>It can be on the same server as the Library Server, or it can be on its own computer.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Resource Managers can be distributed across networks to provide convenient user access.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Users store and retrieve digital resources on the Resource Manager by routing requests through the Library Server.<span style=\"mso-spacerun: yes;\">&nbsp; </span></span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 0in 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman';\"><span style=\"font-size: x-small;\">The Content Manager 8.4 Connector APIs (used by WebSphere Application Server applications, the System Administration Client, and Clint for Windows) include a set of object-oriented APIs.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The APIs allow applications and users to access the Library Server and Resource Manager(s). <span style=\"mso-spacerun: yes;\">&nbsp;</span></span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 0in 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman';\"><span style=\"font-size: x-small;\">The System Administration Client oversees the entire Content Manager system.<span style=\"mso-spacerun: yes;\">&nbsp; </span>From the System Administration Client, an administrator performs various administrative functions, such as defining the data model, creating users and defining their access to the system and specific objects, and managing storage and storage objects in the system.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The System Administration Client can be installed on any workstation with the other components or on its own workstation. The Client for Windows provides an interface that enables an application to import documents into Content Manager, view them, work with them, store them, and retrieve them</span></span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the <span style=\"mso-bidi-font-family: Times;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> </span>Content Manager Enterprise Edition V8.4 Fix Pack 1A<span style=\"mso-bidi-font-weight: bold;\"> </span>TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 4 augmented with ALC_FLR.2 family of assurance requirements.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when configured as specified in the IBM DB2 Content Manager Enterprise Edition Version 8 Release 4 Planning and Installing Your Content Management System and the IBM DB2 Content Manager Enterprise Edition System Administration Guide Version 8 Release 4, satisfies all of the security functional requirements stated in the <span style=\"mso-bidi-font-family: Times;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> </span></span><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;\">Content Manager Enterprise Edition V8.4 Fix Pack 1A Security Target</span><span style=\"font-family: Times;\">, Version 1.0.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Two Validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in November 2008.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-VID10220-2009, dated 27 January 2009) prepared by CCEVS.</span></span></p>","environmental_strengths":"<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal; text-autospace: ideograph-numeric; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The TOE is a commercial product whose users require a low to moderate level of independently assured security.<span style=\"mso-spacerun: yes;\">&nbsp; </span><span style=\"mso-bidi-font-family: Times;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> </span>Content Manager Enterprise Edition V8.4 Fix Pack 1A is targeted at a relatively benign environment with good physical access security and competent administrators.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Within such environments, it is assumed that attackers will have little attack potential.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The security environment also assumes that the TOE components are physically protected. </span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal; text-autospace: ideograph-numeric; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">IBM&reg; DB2&reg; Content Manager Enterprise Edition V8.4 Fix Pack 1A </span><span style=\"font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt;\">supports the following five security functions:</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><strong><span style=\"font-size: x-small;\">Security Audit</span></strong></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal;\"><span class=\"body0\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">All security-related events within Content Manager are logged.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These are tied to the user/administrator that performed the action, the action performed, and the time it was performed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>These audit records are stored in a central location in the IT Environment.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Client for Windows provides an interface for users to view audit records of events associated with a TOE resource.</span></span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><strong><span style=\"font-size: x-small;\">User Data Protection</span></strong></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 6pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-weight: normal; font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><span style=\"font-size: x-small;\">Access to the TOE&rsquo;s resources is governed by the resource&rsquo;s Access Control List (ACL), which identifies the user and the access allowed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The TOE uses privileges to define what operations a user is allowed to perform on the resources.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The Library Server verifies that the user has the required privilege and the ACL associated to the requested object grants access.</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><strong><span style=\"font-size: x-small;\">Identification and Authentication</span></strong></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 6pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-weight: normal; font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><span style=\"font-size: x-small;\">Content Manager identifies and authenticates non-administrative users before any other actions can be performed.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The non-administrative user is required to provide a user name and password, which will be verified by the Library Server database table.<span style=\"mso-spacerun: yes;\">&nbsp; </span>If the verification is successful, access into the TOE is granted.</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><strong><span style=\"font-size: x-small;\">Security Management</span></strong></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt;\"><span style=\"mso-bidi-font-size: 12.0pt; mso-bidi-font-family: Times;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The System Administration Client provides the authorized administrator the capability to manage the security-related functions and attributes, such as the audit function, management of users and their associated data.<span style=\"mso-spacerun: yes;\">&nbsp; </span><span style=\"mso-spacerun: yes;\">&nbsp;</span></span></span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: &quot;Times&quot;,&quot;serif&quot;; mso-bidi-font-size: 12.0pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-weight: bold;\"><strong><span style=\"font-size: x-small;\">Protection of the TSF</span></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 6pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">Content Manager provides the mechanism used to enforce the access control policy ensuring that only authorized users are given access to the resources.</span></span></p>","features":[]}