{"product_id":11050,"v_id":11050,"product_name":"Apple iOS 13 and iPadOS 13: Contacts","certification_status":"Certified","certification_date":"2020-06-05T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Apple Inc.","website":"https://support.apple.com/guide/certifications/welcome/web"},"vendor_poc":"Fiona Pattinson","vendor_phone":"+1 669 227 3579","vendor_email":"Security-certifications@Apple.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p style=\"margin-bottom: .0001pt;\"><span style=\"font-size: 12pt;\"><span style=\"font-family: 'times new roman',times,serif;\">The TOE is the Apple iOS and iPadOS 13 Contacts application which runs on iPhones and iPads. The product provides access and management of user contact information within the devices. </span><span style=\"line-height: 107%; font-family: 'Calibri',sans-serif;\"><span style=\"font-family: 'times new roman',times,serif;\">Note: The TOE is the application software only.</span> </span></span><u></u></p>","evaluation_configuration":"<p style=\"margin-bottom: .0001pt;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE is an application on a mobile OS. The TOE is the Contacts application only. The mobile operating system and hardware platforms are part of the TOE environment. The evaluated version of the TOE is version 13.4.1.</span></p>","security_evaluation_summary":"<p style=\"margin-bottom: .0001pt; line-height: normal;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Apple iOS and iPadOS 13 Contacts was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered configured as identified in the Apple iOS and iPadOS 13 Contacts Common Criteria Guide, satisfies all of the security functional requirements stated in the Apple iOS and iPadOS 13 Contacts Security Target. The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in June, 2020.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.&nbsp;</span></p>","environmental_strengths":"<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE provides the security functionality required by [SWAPP].</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Cryptographic Support</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE platform provides HTTPS/TLS functionality to securely communicate with trusted entities. The TOE does not directly perform any cryptographic functions.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">User Data Protection</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE requests no hardware or software resources during the use of the application. The TOE requires network access.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Security Management</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE is installed completely pre-configured. No security related configuration is required for operation.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Privacy</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE does not request any PII with the intent to transmit the data over the network. However, the TOE will transmit contact information at the request of the user. In these cases, the TOE provides a notification when sharing this information.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Protection of the TSF</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE platform performs cryptographic self-tests at startup which ensures the TOE ability to properly operate. The TOE platform also verifies all software updates via digital signature.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Trusted Path/Channels</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE is a software application. The TOE has the ability to establish protected communications using platform provided TLS/HTTPS.</span></p>","features":[]}