{"product_id":10500,"v_id":10500,"product_name":"McAfee MOVE AV 2.5 and ePolicy Orchestrator 4.6","certification_status":"Not Certified","certification_date":"2012-09-14T00:09:00Z","tech_type":"AntiVirus","vendor_id":{"name":"McAfee, LLC","website":"www.mcafee.com"},"vendor_poc":"James Reardon","vendor_phone":"651-628-5346","vendor_email":"james_reardon@mcafee.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p>McAfee MOVE Antivirus is an anti-virus solution for virtual environments that removes the need to install an anti-virus application on every virtual machine (VM).</p>\r\n<p>A traditional security solution for virtual environments uses an anti-virus application running on every VM on a hypervisor. This requirement reduces VM density per hypervisor and causes high disk, CPU, and memory usage. McAfee MOVE Antivirus solves this issue by offloading all on-access scanning to a dedicated VM that runs an offload scan server to improve performance related to anti-virus scanning. This results in increased VM density per hypervisor.</p>\r\n<p>The management capabilities for MOVE are provided by ePO through the MOVE ePO Extension and McAfee Agent&nbsp;&nbsp;&nbsp; ePO manages McAfee Agents and MOVE Software that reside on client systems.&nbsp; By using ePO you can manage a large enterprise network from a centralized system. ePO through the McAfee Agent provides capabilities to distribute updated MOVE Security policies, DAT files to the Offload Scan Server. ePO also centrally manages Event and Log records.</p>\r\n<p>Communication between the distributed components of the TOE is protected from disclosure and modification by cryptographic functionality provided by the FIPS approved components of the McAfee ePO and the McAfee Agent.&nbsp;&nbsp;&nbsp; It is assumed that the IT environment will provide a secure line of communications between the TOE and remote administrators.</p>\r\n<p>The TOE includes these components:</p>\r\n<ul>\r\n<li>McAfee MOVE Antivirus Agent for Windows &mdash; Allows virtual desktops and servers to communicate with ePolicy Orchestrator. </li>\r\n<li>McAfee MOVE Antivirus Offload Server &mdash; Provides offloaded scanning support for virtual servers, minimizing the impact on virtual desktops. </li>\r\n<li>McAfee MOVE Antivirus ePolicy Orchestrator extension &mdash; Provides policies and controls for configuring McAfee MOVE Antivirus behavior. </li>\r\n<li>ePolicy Orchestrator &ndash; provides management capabilities for the TOE. </li>\r\n<li>McAfee Agent &ndash; provides common communication functionality between ePO and all of McAfee&rsquo;s product-specific software (such as MOVE).</li>\r\n</ul>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that Security Target McAfee MOVE 2.5 and ePolicy Orchestrator 4.6, Document Version 1.4, August 14, 2012 meets the security requirements contained in the Security Target.</p>\r\n<p>The criteria against which Security Target McAfee MOVE 2.5 and ePolicy Orchestrator 4.6, Document Version 1.4, August 14, 2012 was judged is described in the Common Criteria for Information Technology Security Evaluation, Version 3.1. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1. The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for Security Target McAfee MOVE 2.5 and ePolicy Orchestrator 4.6, Document Version 1.4, August 14, 2012 is EAL 2 + ALC_FLR.2. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p>A Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by the COACT, Inc. CAFE Lab. The evaluation was completed in August 2012. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p><strong>Virus Scanning and Alerts&nbsp;&nbsp; </strong></p>\r\n<p>The TOE provides for scanning and detection of file-based viruses. Users are alerted of actions on both the managed systems (via pop-up dialog) and the management system (via log). This functionality is supported in the VSE component of the Offload Scan Server.</p>\r\n<p><strong>Audit&nbsp; </strong></p>\r\n<p>Event information is concurrently generated for transmission to the ePO management databases. Event records for all clients can be reviewed from the ePO console.</p>\r\n<p><strong>Management&nbsp; </strong></p>\r\n<p>ePO enables the Global Administrator to centrally manage virus scan settings on workstations, configure and manage the actions the virus scan component takes when detection of an infection occurs, and manage the Event and Log records.</p>\r\n<p><strong>Cryptographic Operation&nbsp;&nbsp;&nbsp;&nbsp; </strong></p>\r\n<p>Anti-virus packages are distributed to the workstation with a SHA-1 hash value used to verify the integrity of the package.&nbsp; Communications between ePO and the McAfee Agent are encrypted using AES implemented by FIPS 140-2 validated modules.</p>","features":[]}