{"product_id":10530,"v_id":10530,"product_name":"CA Layer 7 SecureSpan SOA Gateway v8.0","certification_status":"Certified","certification_date":"2014-05-30T00:00:00Z","tech_type":"Enterprise Security Management","vendor_id":{"name":"CA Technologies","website":"www.ca.com"},"vendor_poc":"Aaron Flint","vendor_phone":"604-235-8301","vendor_email":"aaron.flint@ca.com","assigned_lab":{"cctl_name":"DXC.technology"},"product_description":"<p>The TOE is an enterprise security management solution that provides centralized management and access control over web services and related resources. The TOE controls how web services are exposed to and accessed by external client applications. The Gateway is designed to protect web services and mediate communications between Service Oriented Architecture (SOA) clients and endpoints residing in different identity, security, or middleware domains.</p>","evaluation_configuration":"","security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the product meets the security requirements contained in the Security Target. The criteria against which the CA Layer 7 SecureSpan SOA Gateway v8.0 was judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1, Revision 3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1, Revision 3. Computer Sciences Corporation determined that the product is conformant to requirements for ESM Protection Profiles; Standard Protection Profile for Enterprise Security Management Policy Management, v1.4 and Standard Protection Profile for Enterprise Security Management Access Control, v2.0.&nbsp; The product satisfies all of the security functional requirements stated in the Security Target. Two validators, on behalf of the CCEVS Validation Body, monitored the evaluation carried out by Computer Sciences Corporation. The evaluation was completed on 30 May 2014. Results of the evaluation can be found in the Evaluation Technical Report for CA Layer 7 SecureSpan SOA Gateway v8.0 prepared by Computer Sciences Corporation.</p>","environmental_strengths":"<p>Communication between the Policy Manager and the Gateway is protected from disclosure and modification. A trusted channel is established to identify and authenticate each end point.</p>\r\n<p>The Gateway validates the integrity of the policy data it receives and rejects any invalid or replayed data. The Gateway generates evidence of receipt of policies.</p>\r\n<p>The TOE provides the ability to keep an audit/log trail to provide administrative insight into system management and operation, including identifying what policies are being defined and enforced.&nbsp; The TOE is capable of sending audit/log information to an external trusted entity.&nbsp;</p>\r\n<p>Administrative access to the TOE requires authentication and is governed by role based access control. The TOE protects against attacker attempts to illicitly authenticate using repeated guesses and enforces an administrator define password policy. The TOE displays a banner a login.</p>","features":[]}