{"product_id":10561,"v_id":10561,"product_name":"Cisco Optical Networking Solution 9.8.1.2","certification_status":"Certified","certification_date":"2014-09-12T00:00:00Z","tech_type":"Network Device","vendor_id":{"name":"Cisco Systems, Inc.","website":"https://www.cisco.com"},"vendor_poc":"Cert Team","vendor_phone":"+1 410-309-4862","vendor_email":"certeam@cisco.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>The TOE is the Cisco Optical Networking Solution (ONS). The Cisco Optical Networking Solution (ONS) TOE is the Multiservice Transport Platform (MSTP) that provides dense wavelength-division multiplexing (DWDM) and time-division multiplexing (TDM) solutions.</p>","evaluation_configuration":"<p>A hardware and software solution that makes up the ONS models as follows:</p>\r\n<ul>\r\n<li>Chassis (one or more):\r\n<ul>\r\n<li>15454-M2-SA</li>\r\n<li>15454-M6-SA</li>\r\n</ul>\r\n</li>\r\n<li>Controller (Management) Cards (one or more):\r\n<ul>\r\n<li>15454-M-TNC-K9</li>\r\n<li>15454-M-TSC-K9</li>\r\n<li>15454-M-TNCE-K9</li>\r\n<li>15454-M-TSCE-K9</li>\r\n</ul>\r\n</li>\r\n<li>Encryption (Traffic Data) Card:\r\n<ul>\r\n<li>15454-M-WSE-K9</li>\r\n</ul>\r\n</li>\r\n<li>Software\r\n<ul>\r\n<li>ONS 9.8.1.2&nbsp;</li>\r\n</ul>\r\n</li>\r\n</ul>\r\n<p>The software comes pre-installed and is comprised of the Universal Cisco&nbsp;ONS software image Release 9.8.1.2.&nbsp;</p>","security_evaluation_summary":"<p class=\"Default\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and procedures. The criteria against which the Cisco Optical Networking Solution (ONS) were judged are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp;The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 4.&nbsp;Leidos (formerly SAIC) determined that the product, when delivered configured as identified in the Cisco Optical Networking Solution Common Criteria Configuration Guide document, satisfies all of the security functional requirements stated in the&nbsp;Cisco Optical Networking Solution Security Target, 1.0, August 11, 2014. The project underwent CCEVS Validator review.&nbsp;The evaluation was completed in August 2014.&nbsp; Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.</p>","environmental_strengths":"<p><strong><em>Security Audit</em></strong></p>\r\n<p>The TOE can audit events related to cryptographic functionality, identification and authentication, and administrative actions. The Cisco Optical Networking Solution generates an audit record for each auditable event. Each security relevant audit event has the date, timestamp, event description, and subject identity. Auditing is always on to audit all events and therefore the administrator is only coupled with the management of the audit data storage and archive of the log files. The TOE provides the administrator with a circular audit trail or a configurable audit trail threshold to track the storage capacity of the audit trail. Audit logs are manually archived over secure HTTPS/TLS connection to an external audit server.</p>\r\n<p><strong><em>Cryptographic Support</em></strong></p>\r\n<p>ONS is a FIPS validated product. The FIPS certificate numbers are provided in the ST.</p>\r\n<p>The TOE also provides cryptography in support of other Cisco ONS security functionality. This cryptography has been validated for conformance to the requirements of FIPS 140-2 Level. The TOE provides HTTPS, as specified in RFC 2818, to provide a secure interactive interface for remote administrative functions, and to support secure exchange of user authentication parameters during login. HTTPS uses TLS to securely establish the encrypted remote session. The TOE provides TLS 1.0, conformant to RFC 2246. The TOE only supports standard extensions, methods, and characteristics.</p>\r\n<p><strong><em>Full Residual Data Protection</em></strong></p>\r\n<p>The TOE ensures that all information flows from the TOE do not contain residual information from previous traffic.&nbsp; Packets are padded with zeros. Residual data is never transmitted from the TOE.</p>\r\n<p><strong><em>Identification and Authentication</em></strong></p>\r\n<p>The TOE provides authentication services for administrative users to connect to the TOEs GUI administrator interface. The TOE requires Authorized Administrators to be successfully identified and authenticated prior to being granted access to any of the management functionality. The TOE can be configured to require a minimum password length of 15 characters, password expiration as well as mandatory password complexity rules. The TOE provides administrator authentication against a local user database using the GUI interface accessed via secure HTTPS connection.&nbsp;</p>\r\n<p><strong><em>Security Management</em></strong></p>\r\n<p>The TOE provides secure administrative services for management of general TOE configuration and the security functionality provided by the TOE. All TOE administration occurs through a secure HTTPS session. The TOE provides the ability to securely manage:</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; All TOE administrative users;</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; All identification and authentication;</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; All audit functionality of the TOE;</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; All TOE cryptographic functionality;</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The timestamps maintained by the TOE; and</p>\r\n<p>&bull;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Updates to the TOE.&nbsp;</p>\r\n<p><strong><em>Protection of the TSF</em></strong></p>\r\n<p>The TOE protects against interference and tampering by untrusted subjects by implementing identification, authentication, and access controls to limit configuration to Authorized Administrators. The TOE prevents reading of cryptographic keys and passwords. Additionally Cisco ONS is not a general-purpose operating system and access to Cisco ONS memory space is restricted to only Cisco ONS functions.</p>\r\n<p>The TOE internally maintains the date and time. This date and time is used as the timestamp that is applied to audit records generated by the TOE.&nbsp;</p>\r\n<p>The TOE performs testing to verify correct operation of the system itself and that of the cryptographic module.</p>\r\n<p>Finally, the TOE is able to verify any software updates prior to the software updates being installed on the TOE to avoid the installation of unauthorized software.</p>\r\n<p><strong><em>TOE Access</em></strong></p>\r\n<p>The TOE can terminate inactive sessions after an Authorized Administrator configurable time-period. Once a session has been terminated the TOE requires the user to re-authenticate to establish a new session. The TOE can also be configured to display an Authorized Administrator specified banner on the GUI management interface prior to accessing the TOE.</p>\r\n<p><strong><em>Trusted Path/Channels</em></strong></p>\r\n<p>The TOE allows trusted paths to be established to itself from remote administrators over HTTPS for remote administration and manual archiving of audit messages.&nbsp;&nbsp;&nbsp;</p>","features":[]}