{"product_id":10221,"v_id":10221,"product_name":"IBM DB2 Document Manager V8.4 Fix Pack 1","certification_status":"Not Certified","certification_date":"2009-01-30T00:01:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Pete Jacob Jr.","vendor_phone":"408-463-2546","vendor_email":"jacobjr@us.ibm.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: \">The TOE, IBM DB2 Document Manager provides the capability to manage controlled documents, such as standard operating procedures, engineering drawings, work instructions, and material safety data sheets, throughout the lifecycle of the documents. It enforces a role-based policy that controls what operations users can perform on documents, based on the user&rsquo;s role. Document Manager relies on </span><span style=\"font-family: Times New Roman;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> </span><span style=\"font-family: \">Content Manager Enterprise Edition V8.4 Fix Pack 1 to act as a content repository for Document Manager documents.</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-size: x-small;\"><span style=\"font-family: \">Document Manager works with </span><span style=\"font-family: Times New Roman;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> </span><span style=\"font-family: \">Content Manager Enterprise Edition V8.4 Fix Pack 1 (also referred to simply as &lsquo;Content Manager&rsquo; or &lsquo;CM&rsquo;) to manage controlled documents throughout their lifecycle.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Document Manager provides relationship management of related documents and manages the various states and transitions that occur throughout a document&rsquo;s lifecycle, from creation to disposition or destruction.</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt; text-indent: 0in; text-align: justify; mso-list: none; tab-stops: list .5in;\"><span style=\"font-family: \"><span style=\"font-size: x-small;\">The Document Manager system is built on a three-tiered computing model comprising</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt 0.5in; text-indent: -0.25in; text-align: justify; mso-list: l1 level1 lfo2; tab-stops: .5in;\"><span style=\"font-family: \"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">(1)</span><span style=\"font: 7pt \">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: \"><span style=\"font-size: x-small;\">a Content Repository Tier, which provides an information management function built on the supporting Content Management system;</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt 0.5in; text-indent: -0.25in; text-align: justify; mso-list: l1 level1 lfo2; tab-stops: .5in;\"><span style=\"font-family: \"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">(2)</span><span style=\"font: 7pt \">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: \"><span style=\"font-size: x-small;\">a Document Manager Server and Services tier, which provides a DM server function to control communication with the content repository, a group of specialized services (i.e., lifecycle, notification, rendition, print/plot, and automation services, alarm manager, and cache manager), and a client software delivery component; and</span></span></p>\r\n<p class=\"BulletList\" style=\"margin: 3pt 0in 6pt 0.5in; text-indent: -0.25in; text-align: justify; mso-list: l1 level1 lfo2; tab-stops: .5in;\"><span style=\"font-family: \"><span style=\"mso-list: Ignore;\"><span style=\"font-size: x-small;\">(3)</span><span style=\"font: 7pt \">&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><span style=\"font-family: \"><span style=\"font-size: x-small;\">a Document Manager Clients tier, which provides a configurable desktop client application, functions to support the integration of Microsoft Office and other viewing applications, the Designer system administration client application, a batch item loader, and a client application programming interface (API).</span></span></p>","evaluation_configuration":null,"security_evaluation_summary":"<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The criteria against which the IBM DB2&reg; Document Manager V8.4 Fix Pack 1<span style=\"mso-bidi-font-weight: bold;\"> </span>TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is EAL 3 augmented with ALC_FLR.2 family of assurance requirements.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when configured as specified in the IBM DB2 Document Manager Version 8 Release 4 Planning and Installing Your Document Management System and the IBM DB2 Document Manager System Administration Guide Version 8 Release 4, satisfies all of the security functional requirements stated in the </span><span style=\"font-family: \">IBM DB2<sup>&reg;</sup> Document Manager V8.4 Fix Pack 1 Security Target</span><span style=\"font-family: Times;\">, Version 1.0.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Two Validators on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in November 2008.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-VID10221-2009, dated 30 January 2009 and prepared by CCEVS.</span></span></p>","environmental_strengths":"<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal; text-autospace: ideograph-numeric; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The TOE is a commercial product whose users require a low to moderate level of independently assured security.<span style=\"mso-spacerun: yes;\">&nbsp; </span>IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> Document Manager V8.4 Fix Pack 1 is targeted at a relatively benign environment with good physical access security and competent administrators.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Within such environments, it is assumed that attackers will have little attack potential.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The security environment also assumes that the TOE components are physically protected. </span></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal; text-autospace: ideograph-numeric; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">IBM<sup>&reg;</sup> DB2<sup>&reg;</sup> Document Manager V8.4 Fix Pack 1 </span><span style=\"font-family: \">supports the following four security functions:</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: \"><strong><span style=\"font-size: x-small;\">Security Audit</span></strong></span></p>\r\n<p class=\"Body\" style=\"margin: 0in 0in 6pt; line-height: normal;\"><span class=\"body0\"><span style=\"font-size: x-small;\"><span style=\"font-family: Times;\">The components of the Server and Services tier generate logs of actions performed on a document throughout the document&rsquo;s lifecycle. The Desktop provides the user with the interface to review the logs.</span></span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: \"><strong><span style=\"font-size: x-small;\">User Data Protection</span></strong></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 6pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-weight: normal; font-family: \"><span style=\"font-size: x-small;\">The TOE enforces a role-based access control policy that controls the actions users can perform on documents, based on the roles the user is associated with and the life cycle stage of the document.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Users of the TOE are identified and authenticated by the IT environment before any access to the TOE is granted. The TOE defines document management roles, and associates those roles with users and groups that are defined in the IT environment. The roles a user is associated with determine what commands a user can perform. Roles are also associated with the various states in which a document type can exist. The document life cycle defines how the document transitions through its various states. A document life cycle stage is the current state of the document and the transitions that apply to the document in its current state. The TOE ensures the user has an appropriate document management role and that the requested operation is valid for the current life cycle stage of the document before allowing a requested operation to be performed. The Desktop tier and the Server and Services tier work together to implement the role-based access control policy.</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: \"><strong><span style=\"font-size: x-small;\">Identification and Authentication</span></strong></span></p>\r\n<p class=\"System\" style=\"margin: 6pt 0in; text-align: justify;\"><span style=\"font-weight: normal; font-family: \"><span style=\"font-size: x-small;\">The TOE presents a login screen to users of both the Desktop and the Designer when these client applications are first started. The user identity and password are passed through to the IT environment for identification and authentication prior to granting any further access to the TOE. The TOE enforces the identification and authentication decision received from the IT environment and ensures the user does not gain access to the TOE if identification and authentication fail. The TOE associates the user identity with the current active session and uses this identity and the user&rsquo;s document management roles to enforce the access control policy on documents.</span></span></p>\r\n<p class=\"System\" style=\"margin: 6pt 0in; text-align: justify;\"><span style=\"font-weight: normal; font-family: \"><span style=\"font-size: x-small;\">The Desktop client can be configured by the administrator to lock out the Desktop client login screen after a set number of failed attempts, for an administrator-defined interval. The Desktop client can also be configured to require the end user to re-login if idle for longer than a configurable interval.</span></span></p>\r\n<p class=\"System\" style=\"margin: 0in 0in 0pt; text-autospace: ideograph-numeric; text-align: justify; mso-layout-grid-align: auto; punctuation-wrap: hanging; mso-vertical-align-alt: auto;\"><span style=\"font-family: \"><strong><span style=\"font-size: x-small;\">Security Management</span></strong></span></p>\r\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 6pt; text-align: justify;\"><span style=\"mso-bidi-font-family: Times;\"><span style=\"font-size: x-small; font-family: Times;\">The TOE requires an authorized administrator role to perform the security functions of creating and modifying document management roles, document states, and document classes and defining document life cycle stages. The TOE&rsquo;s authorized administrator security management role is defined in the IT environment.</span></span></p>","features":[]}