{"product_id":10224,"v_id":10224,"product_name":"Microsoft Windows Rights Management Services (RMS) 1.0 SP2","certification_status":"Not Certified","certification_date":"2007-08-08T00:08:00Z","tech_type":"Sensitive Data Protection","vendor_id":{"name":"Microsoft Corporation","website":"https://www.microsoft.com"},"vendor_poc":"Tim Myers","vendor_phone":"425-707-9422","vendor_email":"timmyers@microsoft.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>Microsoft Windows Rights Management Services (RMS) 1.0 SP2 is an information protection technology that works with RMS-enabled applications to help safeguard digital information from unauthorized use&mdash;both online and offline, inside and outside a firewall. However, the TOE is restricted to use within a closed network environment that is not connected to the Internet.</p>\r\n<p>RMS uses Windows Server 2003 features and security technologies, including encryption, certificates and authentication, to help organizations create information protection solutions. RMS provides protection of information through persistent usage policies, which remain with the information, no matter where it goes.</p>\r\n<p>RMS is a set of web and operating system services designed to facilitate the management of rights-protected content. While the TOE doesn&rsquo;t actually store any protected content, it generates certificates and licenses that can be used to encrypt content and enable access to those authorized to use the content. RMS provides the setup steps that enable trusted entities to use rights-protected information.<span> It also handles administration functions.</span></p>\r\n<p>The TOE issues XML-based licenses that define usage rights and conditions to control access to encrypted data. The TOE is supported on Windows Server 2003 as its IT environment. Encrypted data usage rights and conditions that are defined within licenses identify individual authorized users who can view the information and how that information can be used and shared.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Microsoft Windows Rights Management Services (RMS) 1.0 SP2 TOE was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the Evaluation Team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3. Science Applications International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the product is the EAL4 family of assurance requirements, augmented with ALC_FLR.3 (Systematic flaw remediation). The product, when configured as specified in &ldquo;Windows Rights Management Services (RMS) 1.0 with SP2 Security Configuration Guide&rdquo;, satisfies all of the security functional requirements stated in the Microsoft Windows Rights Management Services (RMS) Security Target. A validation team on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC. The evaluation was completed in May 2007. Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report, (report number CCEVS-VR-07-0057) prepared by CCEVS.</p>","environmental_strengths":"<p>The evaluated configuration of the TOE comprises a Root Certification Server and, optionally, one or more Licensing Servers. The Microsoft-hosted RMS Enrollment Service is also included in the evaluated configuration.</p>\r\n<p>Microsoft Windows Rights Management Services (RMS) 1.0 SP2 supports the following security functions:</p>\r\n<ul>\r\n    <li><strong>Security Audit</strong> &ndash; The TOE has the ability to log successful and failed Use License requests.<span> When logging is enabled, all attempts to acquire Use Licenses are logged by forwarding them to the local SQL server configured in the IT environment of the TOE.</span></li>\r\n    <li><strong>User Data Protection</strong> &ndash; The TOE ensures that certificates are generated with appropriate contents. The TOE also restricts the issuance of Use Licenses to content users who have been granted rights that would be reflected in a license issued by the TOE.</li>\r\n    <li><strong>Identification and Authentication</strong> &ndash; While the TOE depends upon the IT environment to properly authenticate user identities, the TOE requires the identity of requesting users before it processing requests for Client Licensor Certificates and Use Licenses.</li>\r\n    <li><strong>Security Management</strong> &ndash; The TOE provides the administrator with functions to manage the audit function, Use License issuance controls and exclusion list, the decommissioning service, and dictating the applicable content of certificates and licenses.</li>\r\n</ul>","features":[]}