{"product_id":10415,"v_id":10415,"product_name":"CA Top Secret r14 SP1 for z/OS","certification_status":"Not Certified","certification_date":"2011-04-04T00:04:00Z","tech_type":"Enterprise Security Management","vendor_id":{"name":"CA Technologies","website":"www.ca.com"},"vendor_poc":"William Clark","vendor_phone":"703-708-3501","vendor_email":"william.clark@ca.com","assigned_lab":{"cctl_name":"Booz Allen Hamilton Common Criteria Testing Laboratory"},"product_description":"<p>The Security Target (ST) defines the Information Technology (IT) security requirements for CA Top Secret for z/OS (CA Top Secret). CA Top Secret delivers access control capabilities for z/OS systems and includes interfaces for CICS, TSO, and IMS. CA Top Secret allows administrators to control user access to protected mainframe resources such as datasets and volumes. CA Top Secret controls access to the system and its own data through the use of policies and privileges that limit how and when a user or administrator can access the system and what they can do once they are authenticated. Administrators can be given authority over various segments of the system through the use of privileges.</p>","evaluation_configuration":"<p>Several different models were used in the evaluated configuration. All contained the same security functionality and the only differences were in throughput. They are enumerated as follows:</p>\r\n<p>The following requirements are defined for the evaluated configuration:</p>\r\n<ul>\r\n<li>CA Top Secret running in FAIL mode</li>\r\n<li>z/OS 1.11</li>\r\n<li>CICS CTS 3.2</li>\r\n<li>IMS 10</li>\r\n<li>CA LDAP Server r14</li>\r\n</ul>\r\n<p>The following system characteristics represent the tested configuration:</p>\r\n<ul>\r\n<li>IBM Model 2097</li>\r\n<li>384MB virtual memory</li>\r\n<li>~15,000 cylinders of Direct Access Storage Devices (DASD)</li>\r\n</ul>","security_evaluation_summary":"<p>The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) processes and procedures. CA Top Secret r14 SP1 for z/OS was evaluated against the criteria contained in the Common Criteria for Information Technology Security Evaluation, Version 3.1 Revision 3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 Revision 3. It has been determined that the product meets the security criteria in the Security Target, which specifies an assurance level of EAL4 augmented with ALC_FLR.1 and ASE_TSS.2. Validators, on behalf of the CCEVS Validation Body, monitored the evaluation. The evaluation was completed in March 2011.</p>","environmental_strengths":"<p><strong><em>Security Audit</em></strong><strong><em></em></strong></p>\r\n<p>CA Top Secret uses the System Management Facility (SMF) or CA Top Secret Audit and Tracking File to record all security-relevant events. These records are secured from accidental disclosure or destruction by the standard Discretionary Access Control (DAC) and Mandatory Access Control (MAC) protection mechanisms.&nbsp; CA Top Secret may enforce the MAC policy to objects based on users, resources, and Access Level, Type, Object Security Label, and Subject Security label. CA Top Secret enforces the DAC policy to objects based on users, entity, security relevant attributes control option auth, resource class name, entity name, secrec, ownership, facility, time of day, day of week, sysid, Limited Command Facility (LCF), calendar, program, and library.</p>\r\n<p>&nbsp;</p>\r\n<p>CA Top Secret provides report utilities to produce reports. For example, the TSSUTIL utility report provides an audit trail of security events. A variety of parameters can be set to customize the reports.</p>\r\n<p><strong><em>Identification and Authentication</em></strong><strong><em></em></strong></p>\r\n<p>CA Top Secret controls how, when, and which resources a user or administrator can access.&nbsp; CA Top Secret requires that each user and administrator have a valid User ID and authenticate utilizing the necessary mechanism (i.e. password verification, passphrase verification, digital certificate verification, passticket verification, Kerberos authentication) before entering the system.&nbsp; CA Top Secret also tracks failed authentication attempts. If the threshold for failed authentication attempts is exceeded, CA Top Secret will suspend the user or administrator account from being able to authenticate.</p>\r\n<p>&nbsp;</p>\r\n<p>By default, CA Top Secret requires that all User IDs are password protected. The security administrator which created the user or administrator assigns the first password. The user or administrator associated with the User ID will then change the password immediately or later when it expires.&nbsp; CA Top Secret will also enforce the requirement that the user or administrator create a password which is consistent with a password policy (e.g., minimum length, complexity).&nbsp; The additional authentication mechanisms are set to &ldquo;none&rdquo; by default and require an administrator to configure the authentication applications to utilize these mechanisms.&nbsp; CA Top Secret will enforce the use of these authentication mechanisms when a user or administrator has been configured to use one of the additional mechanisms.&nbsp; In addition to the enforcement of a password policy, when passphrases are used, the Top Secret requires a user or administrator to create a passphrase which meets a passphrase policy.</p>\r\n<p><strong><em>Security Management</em></strong><strong><em></em></strong></p>\r\n<p>CA Top Secret maintains three roles: security administrators, scoped security administrators and users.&nbsp; Administrators manage CA Top Secret and its users; whereas a user&rsquo;s primary function is to perform work.&nbsp; Any administrator with ACID (CREATE) administrative authority can establish users. Although a user can be assigned most types of administrative authority, the user's scope is always limited to itself.</p>\r\n<p>&nbsp;</p>\r\n<p>Security administrators can display and change fields of ACIDs based on their scope. Scoped administrators can perform administrative operations that are defined within their scope.</p>\r\n<p><strong><em>User Data Protection</em></strong><strong><em></em></strong></p>\r\n<p>CA Top Secret determines whether an individual user should be permitted access to a resource and must be able to associate a user&rsquo;s identity with each job or time-sharing session. No job can run on a CA Top Secret-controlled system unless it can first be identified with a valid, predefined user. Thus, CA Top Secret is also protecting the resources of the computer system itself. No one can use processing time on a system unless they are running under an ACID previously defined to CA Top Secret.</p>\r\n<p>&nbsp;</p>\r\n<p>CA Top Secret performs two main methods of access control, one being mandatory access control (MAC) and the other being discretionary access control (DAC).</p>\r\n<p>&nbsp;</p>\r\n<p>MAC imposes a security policy based on security labels. Security labels classify users, data, and resources.&nbsp; Standard permissions still apply, but only after MAC label dominance checks determine that a user can access data and resources based on their security label and the security label of the data or resources the user wants to access.</p>\r\n<p>&nbsp;</p>\r\n<p>DAC security policy manages the controlled sharing of data and resources using rules. Depending on an implementation option, a security administrator or data owner can write security controls to permit sharing. If a user tries to access data without permission, the system creates a violation record and denies access.</p>\r\n<p><strong><em>TOE Access</em></strong><strong><em></em></strong></p>\r\n<p>CA Top Secret is capable of denying access to\\users who have a suspended/canceled account or have failed to enter a correct password within the threshold limit set by an administrator. A user&rsquo;s access can also be denied when a policy exists which restricts their ability to access the system. These policies can be based on time/date of entry, source of entry, and/or APPLID used for entry.</p>","features":[]}